{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:USMXHT2RA6OHUPSCYA5PZ323V4","short_pith_number":"pith:USMXHT2R","canonical_record":{"source":{"id":"2606.10217","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-06-08T22:15:20Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"4df03f98edff15274cba9f00c98b714355986bf988f5ef1607deb737386823ca","abstract_canon_sha256":"cc48749c1290f02b9d01e2e080cc549c2928e6a1cc5b8381ce90cfa873e1334e"},"schema_version":"1.0"},"canonical_sha256":"a49973cf51079c7a3e42c03afcef5baf29e034eaa862d07d7732a2047d5c8ac3","source":{"kind":"arxiv","id":"2606.10217","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.10217","created_at":"2026-06-10T01:09:00Z"},{"alias_kind":"arxiv_version","alias_value":"2606.10217v1","created_at":"2026-06-10T01:09:00Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.10217","created_at":"2026-06-10T01:09:00Z"},{"alias_kind":"pith_short_12","alias_value":"USMXHT2RA6OH","created_at":"2026-06-10T01:09:00Z"},{"alias_kind":"pith_short_16","alias_value":"USMXHT2RA6OHUPSC","created_at":"2026-06-10T01:09:00Z"},{"alias_kind":"pith_short_8","alias_value":"USMXHT2R","created_at":"2026-06-10T01:09:00Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:USMXHT2RA6OHUPSCYA5PZ323V4","target":"record","payload":{"canonical_record":{"source":{"id":"2606.10217","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-06-08T22:15:20Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"4df03f98edff15274cba9f00c98b714355986bf988f5ef1607deb737386823ca","abstract_canon_sha256":"cc48749c1290f02b9d01e2e080cc549c2928e6a1cc5b8381ce90cfa873e1334e"},"schema_version":"1.0"},"canonical_sha256":"a49973cf51079c7a3e42c03afcef5baf29e034eaa862d07d7732a2047d5c8ac3","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-10T01:09:00.147591Z","signature_b64":"VuAX51dEI96j7CItCYCItAw8uC+jnN60dcShc0IH1+pRrXXGX9Ahlm8n1kt6WJlQtFCFMYY26TtWdkwy4EimAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a49973cf51079c7a3e42c03afcef5baf29e034eaa862d07d7732a2047d5c8ac3","last_reissued_at":"2026-06-10T01:09:00.146689Z","signature_status":"signed_v1","first_computed_at":"2026-06-10T01:09:00.146689Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.10217","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-10T01:09:00Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Eaw/YUVdCnq7BZePhtsLrVjh1J0gj/xemCVKGnE//d+pdPR+P3vxDAyC3jmot+EXxzUdy8PxW6RgmJN9dnnGDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T05:19:45.625211Z"},"content_sha256":"d625d838b625a9f38447fefa4a0f292adae3cbe4ce5d436352961d8e16f6ba8f","schema_version":"1.0","event_id":"sha256:d625d838b625a9f38447fefa4a0f292adae3cbe4ce5d436352961d8e16f6ba8f"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:USMXHT2RA6OHUPSCYA5PZ323V4","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Alignment Defends LLMs from Property Inference Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Chhavi Yadav, Kamalika Chaudhuri, Pengrun Huang, Ruihan Wu","submitted_at":"2026-06-08T22:15:20Z","abstract_excerpt":"Large language models (LLMs) are increasingly fine-tuned on domain-specific datasets that may contain sensitive, dataset-level properties. Recent work has shown that such dataset-level information can be effectively extracted through property inference attacks, posing a confidentiality risk. Existing defenses against these attacks primarily operate by modifying the training data distribution and hence require access to the original data and retraining the model, limiting their applicability to settings where data is unavailable or models are already deployed. In this work, we propose alignment"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.10217","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.10217/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-10T01:09:00Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"enZm/SFLhGF9DbKzO74sDeZKXnjXESAJ7/c+Joyt3O1oxcPo1KoTUiBb8SuC9offYlb2bvfSOC4CGoqZ9mKpBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T05:19:45.625621Z"},"content_sha256":"5e9c7ce20c3478737986145daf3de9bda91523e2ae8a9f9da5fa4140c66dae6f","schema_version":"1.0","event_id":"sha256:5e9c7ce20c3478737986145daf3de9bda91523e2ae8a9f9da5fa4140c66dae6f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/USMXHT2RA6OHUPSCYA5PZ323V4/bundle.json","state_url":"https://pith.science/pith/USMXHT2RA6OHUPSCYA5PZ323V4/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/USMXHT2RA6OHUPSCYA5PZ323V4/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-30T05:19:45Z","links":{"resolver":"https://pith.science/pith/USMXHT2RA6OHUPSCYA5PZ323V4","bundle":"https://pith.science/pith/USMXHT2RA6OHUPSCYA5PZ323V4/bundle.json","state":"https://pith.science/pith/USMXHT2RA6OHUPSCYA5PZ323V4/state.json","well_known_bundle":"https://pith.science/.well-known/pith/USMXHT2RA6OHUPSCYA5PZ323V4/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:USMXHT2RA6OHUPSCYA5PZ323V4","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"cc48749c1290f02b9d01e2e080cc549c2928e6a1cc5b8381ce90cfa873e1334e","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-06-08T22:15:20Z","title_canon_sha256":"4df03f98edff15274cba9f00c98b714355986bf988f5ef1607deb737386823ca"},"schema_version":"1.0","source":{"id":"2606.10217","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.10217","created_at":"2026-06-10T01:09:00Z"},{"alias_kind":"arxiv_version","alias_value":"2606.10217v1","created_at":"2026-06-10T01:09:00Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.10217","created_at":"2026-06-10T01:09:00Z"},{"alias_kind":"pith_short_12","alias_value":"USMXHT2RA6OH","created_at":"2026-06-10T01:09:00Z"},{"alias_kind":"pith_short_16","alias_value":"USMXHT2RA6OHUPSC","created_at":"2026-06-10T01:09:00Z"},{"alias_kind":"pith_short_8","alias_value":"USMXHT2R","created_at":"2026-06-10T01:09:00Z"}],"graph_snapshots":[{"event_id":"sha256:5e9c7ce20c3478737986145daf3de9bda91523e2ae8a9f9da5fa4140c66dae6f","target":"graph","created_at":"2026-06-10T01:09:00Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.10217/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language models (LLMs) are increasingly fine-tuned on domain-specific datasets that may contain sensitive, dataset-level properties. Recent work has shown that such dataset-level information can be effectively extracted through property inference attacks, posing a confidentiality risk. Existing defenses against these attacks primarily operate by modifying the training data distribution and hence require access to the original data and retraining the model, limiting their applicability to settings where data is unavailable or models are already deployed. In this work, we propose alignment","authors_text":"Chhavi Yadav, Kamalika Chaudhuri, Pengrun Huang, Ruihan Wu","cross_cats":["cs.CR"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-06-08T22:15:20Z","title":"Alignment Defends LLMs from Property Inference Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.10217","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:d625d838b625a9f38447fefa4a0f292adae3cbe4ce5d436352961d8e16f6ba8f","target":"record","created_at":"2026-06-10T01:09:00Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"cc48749c1290f02b9d01e2e080cc549c2928e6a1cc5b8381ce90cfa873e1334e","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-06-08T22:15:20Z","title_canon_sha256":"4df03f98edff15274cba9f00c98b714355986bf988f5ef1607deb737386823ca"},"schema_version":"1.0","source":{"id":"2606.10217","kind":"arxiv","version":1}},"canonical_sha256":"a49973cf51079c7a3e42c03afcef5baf29e034eaa862d07d7732a2047d5c8ac3","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a49973cf51079c7a3e42c03afcef5baf29e034eaa862d07d7732a2047d5c8ac3","first_computed_at":"2026-06-10T01:09:00.146689Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-10T01:09:00.146689Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"VuAX51dEI96j7CItCYCItAw8uC+jnN60dcShc0IH1+pRrXXGX9Ahlm8n1kt6WJlQtFCFMYY26TtWdkwy4EimAQ==","signature_status":"signed_v1","signed_at":"2026-06-10T01:09:00.147591Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.10217","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:d625d838b625a9f38447fefa4a0f292adae3cbe4ce5d436352961d8e16f6ba8f","sha256:5e9c7ce20c3478737986145daf3de9bda91523e2ae8a9f9da5fa4140c66dae6f"],"state_sha256":"d1b232bdfd0ea36363da3333e2222171db5f39dcb622215531d4a7315080be52"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+omwIWGb8u4G2ZncGb1bHTZU2+At72wDacQLwwnXAfozrKUtZ/dJ9HuP9a0dn2kovFaCFU8uXjJ3S0N/nr3ABQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-30T05:19:45.628032Z","bundle_sha256":"16516a3018258d72c7b4cf84c297aa615957173734b919c2fbab633497c010cc"}}