{"as_of":"2026-08-09T14:07:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:93c2f623d8999df2c47246b3835cbd769901e0278369477cc256bacdd9fe5226","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":30,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":30,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-09T06:31:02.800959+00:00","state":"measured"},{"denominator":30,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":30,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-07T20:53:28.387219Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":1,"source":"arxiv_reference","source_observed_at":"2026-08-05T02:28:24.338817Z","state":"measured"}],"external_citation_measurements":[{"count":7,"observed_at":"2026-08-05T02:28:24.338817Z","source":"arxiv_reference"}],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-07T20:53:28.387219Z","title":"D., Steinke, T., Hayase, J., Cooper, A","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2502.09619","last_updated":"2025-02-13T18:59:44Z","snapshot_observed_at":"2026-08-08T23:16:00.492203Z","submitted_at":"2025-02-13T18:59:44Z","title":"Can this Model Also Recognize Dogs? Zero-Shot Model Search from Weights","version":1},"reference_index":4,"source":"arxiv_source","source_observed_at":"2026-08-07T20:53:28.387219Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2502.09619"},"observation_digest":"sha256:a8de39efbe25e7ad8ae41d86c9ceff19290da51e8ba8c49e685f2f4162ac60a4","observation_id":"95873777-caaa-4f50-8c22-974f7cd15bb1","resolution":{"observed_at":"2026-08-07T20:53:28.387219Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-07T14:34:34.779319Z","title":"Stealing part of a production language model","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2505.18471","last_updated":"2025-05-24T02:26:49Z","snapshot_observed_at":"2026-08-07T21:54:09.971572Z","submitted_at":"2025-05-24T02:26:49Z","title":"Invisible Tokens, Visible Bills: The Urgent Need to Audit Hidden Operations in Opaque LLM Services","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-07T14:34:34.779319Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2505.18471"},"observation_digest":"sha256:89c472b3dbc6734791b1f42df39e571b05834ac7f7120bee75eb032570971bde","observation_id":"1e05a6e3-11f7-41e4-af7b-2d666af5c970","resolution":{"observed_at":"2026-08-07T14:34:34.779319Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-07T14:26:34.918711Z","title":"Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, Itay Yona, Eric Wallace, David Rolnick, and Florian Tramèr","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.18893","last_updated":"2025-05-30T14:09:51Z","snapshot_observed_at":"2026-08-09T08:24:03.844078Z","submitted_at":"2025-05-24T22:35:32Z","title":"Reality Check: A New Evaluation Ecosystem Is Necessary to Understand AI's Real World Effects","version":4},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-07T14:26:34.918711Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2505.18893"},"observation_digest":"sha256:b47c097715b249bbfc59c40175344fd76ef64b7bf8ede905bc366081e1a5fd54","observation_id":"76c89e6d-1f98-451e-ba59-bb9b2433b228","resolution":{"observed_at":"2026-08-07T14:26:34.918711Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-06T23:58:58.659790Z","title":"Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, Itay Yona, Eric Wallace, David Rolnick, and Florian Tramèr","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.15553","last_updated":"2025-06-18T15:26:43Z","snapshot_observed_at":"2026-08-08T20:05:57.585673Z","submitted_at":"2025-06-18T15:26:43Z","title":"Approximating Language Model Training Data from Weights","version":1},"reference_index":8,"source":"arxiv_source","source_observed_at":"2026-08-06T23:58:58.659790Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2506.15553"},"observation_digest":"sha256:ff3197efe60e77bff6b85c4aee064d4d3bc82e06fe33de33e5fe9cb1880623f5","observation_id":"381bac5a-b44b-42a5-9686-fd745ce10bd0","resolution":{"observed_at":"2026-08-06T23:58:58.659790Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-06T23:01:43.167408Z","title":"Carlini, D","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.22492","last_updated":"2025-06-24T18:55:29Z","snapshot_observed_at":"2026-08-06T22:57:48.252370Z","submitted_at":"2025-06-24T18:55:29Z","title":"Report on NSF Workshop on Science of Safe AI","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-06T23:01:43.167408Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2506.22492"},"observation_digest":"sha256:55e4c5fdd3336985984f97f9a8a38c146e704b12c9f0357c5fbd9f756a43bf67","observation_id":"98a5c5b6-44fb-4307-84e4-ad3e27534878","resolution":{"observed_at":"2026-08-06T23:01:43.167408Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-06T22:23:07.379249Z","title":"Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, Itay Yona, Eric Wallace, David Rolnick, and Florian Tram‘er","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.22521","last_updated":"2025-06-26T22:02:01Z","snapshot_observed_at":"2026-08-07T22:00:37.560675Z","submitted_at":"2025-06-26T22:02:01Z","title":"A Survey on Model Extraction Attacks and Defenses for Large Language Models","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-06T22:23:07.379249Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2506.22521"},"observation_digest":"sha256:9bff04fd4a21159c24af11c88dfc2156aea3ec75903bf93d9326ab2605c75832","observation_id":"595b52f3-0a8b-46de-9fde-a94212a96ecb","resolution":{"observed_at":"2026-08-06T22:23:07.379249Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-06T21:45:00.538286Z","title":"D., Steinke, T., Hayase, J., Cooper, A","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2506.23706","last_updated":"2025-06-30T10:29:42Z","snapshot_observed_at":"2026-08-08T23:28:19.101327Z","submitted_at":"2025-06-30T10:29:42Z","title":"Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments","version":1},"reference_index":12,"source":"arxiv_source","source_observed_at":"2026-08-06T21:45:00.538286Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2506.23706"},"observation_digest":"sha256:545a487d83ed05b8c852a23df3050ed50ee1265618d29a6c185475b95a6258bf","observation_id":"18b7d635-0fdc-43d2-afeb-2ad65315a2bb","resolution":{"observed_at":"2026-08-06T21:45:00.538286Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2507.02850","last_updated":"2026-04-20T16:20:19Z","snapshot_observed_at":"2026-08-08T22:29:26.063319Z","submitted_at":"2025-07-03T17:55:40Z","title":"LLM Hypnosis: Exploiting User Feedback for Unauthorized Knowledge Injection to All Users","version":3},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-05-19T05:58:17.452837Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2507.02850"},"observation_digest":"sha256:d112cffbbbd40980c085e0eb75a5d5865a8eb50701e254760ae274597a59b7b1","observation_id":"e5178f43-11bb-42cb-9e4c-c56a29797357","resolution":{"observed_at":"2026-05-19T06:02:07.798930Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-06T17:21:33.552558Z","title":"arXiv:2403.06634 (2024)","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.11128","last_updated":"2025-07-15T09:28:44Z","snapshot_observed_at":"2026-08-06T17:13:26.565391Z","submitted_at":"2025-07-15T09:28:44Z","title":"What Should LLMs Forget? Quantifying Personal Data in LLMs for Right-to-Be-Forgotten Requests","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-06T17:21:33.552558Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2507.11128"},"observation_digest":"sha256:90aa9d310fec03074a7da29da58ee330a103d64134e76ce7d75e1fbe2ca7f580","observation_id":"1b0a2967-6868-4495-8b81-46222b80ce65","resolution":{"observed_at":"2026-08-06T17:21:33.552558Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-06T14:22:38.225032Z","title":"Stealing Part of a Production Language Model","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2507.19567","last_updated":"2025-07-25T16:40:17Z","snapshot_observed_at":"2026-08-06T14:22:37.279909Z","submitted_at":"2025-07-25T16:40:17Z","title":"Differentiating hype from practical applications of large language models in medicine -- a primer for healthcare professionals","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-06T14:22:38.225032Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2507.19567"},"observation_digest":"sha256:239554ba814b718cb018e9536c0d62dd97503c55bf5d33fa92cfd15c1f26c0a5","observation_id":"d6cc971b-6990-4a4d-bb36-32a0697f54b7","resolution":{"observed_at":"2026-08-06T14:22:38.225032Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T20:31:43.751972Z","title":"Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, Itay Yona, Eric Wallace, David Rolnick, and Florian Tramèr","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.10404","last_updated":"2025-08-14T07:12:44Z","snapshot_observed_at":"2026-08-08T02:31:17.622343Z","submitted_at":"2025-08-14T07:12:44Z","title":"Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation","version":1},"reference_index":117,"source":"pdf_text","source_observed_at":"2026-08-05T20:31:43.751972Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2508.10404"},"observation_digest":"sha256:8c4ad6bb0ef214fc9e7dd7eaa21fb192b2fcd1714a76ac28e63a1b6c7436c888","observation_id":"8ae517b6-acfb-4e47-a9c9-c69450885e54","resolution":{"observed_at":"2026-08-05T20:31:43.751972Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T19:39:09.558565Z","title":"Stealing part of a production language model","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.12175","last_updated":"2025-08-16T22:56:51Z","snapshot_observed_at":"2026-08-09T06:07:29.095199Z","submitted_at":"2025-08-16T22:56:51Z","title":"Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-05T19:39:09.558565Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2508.12175"},"observation_digest":"sha256:2c26925d6fdd3f5ecb365ac66c7d7df8e06e4d988aa79be03e55a0f5aa78b59c","observation_id":"8b0fc8b7-9127-4251-8ab1-858a626df843","resolution":{"observed_at":"2026-08-05T19:39:09.558565Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T18:12:36.156283Z","title":"Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, Itay Yona, Eric Wallace, David Rolnick, and Florian Tram‘er","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.15031","last_updated":"2025-08-27T05:10:26Z","snapshot_observed_at":"2026-08-06T09:22:49.031430Z","submitted_at":"2025-08-20T19:49:59Z","title":"A Systematic Survey of Model Extraction Attacks and Defenses: State-of-the-Art and Perspectives","version":2},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-05T18:12:36.156283Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2508.15031"},"observation_digest":"sha256:d68d7338b35a35f273f6b2a48ccf8a888967ba97b8ac9295fdadc37c56d76b07","observation_id":"fb9fe567-86a7-4880-ac39-825b1a7a7b1f","resolution":{"observed_at":"2026-08-05T18:12:36.156283Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2509.25448","last_updated":"2026-05-19T03:11:28Z","snapshot_observed_at":"2026-08-01T13:25:46.475978Z","submitted_at":"2025-09-29T19:54:36Z","title":"Fingerprinting LLMs via Prompt Injection","version":3},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-05-21T21:29:26.153307Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2509.25448"},"observation_digest":"sha256:aa2094adec38f3d14fab42024213167e5145d29337f831cba2b7dded4f4460bf","observation_id":"7f7ae2e8-8747-41c1-babe-7158987e99cc","resolution":{"observed_at":"2026-05-21T21:30:39.350060Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-03T20:28:51.160758Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2511.19711","last_updated":"2026-07-23T20:56:40Z","snapshot_observed_at":"2026-08-06T13:59:53.166673Z","submitted_at":"2025-11-24T21:21:55Z","title":"CrypTorch: PyTorch-based Auto-tuning Compiler for Machine Learning with Multi-party Computation","version":2},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-03T20:28:51.160758Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2511.19711"},"observation_digest":"sha256:ca89623d85cd8e7cbf717a52ac6ff3d7fe66cd8e4e97b84f4ae45cde62304379","observation_id":"3f63330e-4d56-4554-83f7-a46df38057f5","resolution":{"observed_at":"2026-08-03T20:28:51.160758Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-07-15T13:15:31.225992Z","title":"Stealing part of a production language model,","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2603.07457","last_updated":"2026-03-08T04:16:06Z","snapshot_observed_at":"2026-08-08T01:21:30.388475Z","submitted_at":"2026-03-08T04:16:06Z","title":"How Well Do AI Systems Solve AP Physics? A Comparative Evaluation of Large Language Models on Algebra-Based Free Response Questions","version":1},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-07-15T13:15:31.225992Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2603.07457"},"observation_digest":"sha256:7267558a5b695f9609245ec023dfed9362bfb764cd69f05d8e2975529e326c1e","observation_id":"c64fe9a5-af37-4d5a-af0c-d61d304bbd01","resolution":{"observed_at":"2026-07-15T13:15:31.225992Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-07-13T22:20:23.676745Z","title":"URL https://www.usenix.org/conference/usenixsecuri ty21/presentation/carlini-extracting","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2603.18908","last_updated":"2026-05-25T12:02:45Z","snapshot_observed_at":"2026-08-06T03:46:42.950885Z","submitted_at":"2026-03-19T13:43:32Z","title":"Characterizing Linear Alignment Across Language Models","version":4},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-07-13T22:20:23.676745Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2603.18908"},"observation_digest":"sha256:63e01acab620e1d8f74132e10dac907cf86bf47556345515984e1cd7502d9b6e","observation_id":"95a0a283-8970-463a-a036-3aa3001dabfc","resolution":{"observed_at":"2026-07-13T22:20:23.676745Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2604.23338","last_updated":"2026-05-06T17:17:02Z","snapshot_observed_at":"2026-08-06T19:46:39.219000Z","submitted_at":"2026-04-25T14:57:15Z","title":"A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework","version":2},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-05-08T07:53:13.746141Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2604.23338"},"observation_digest":"sha256:bc7d6f2c561674e24a44d5cd32d8e70c0640882f1b640a0fa9a585cbb48d18cd","observation_id":"58a334a5-cd02-4c1b-8a6a-72c40a4a69f2","resolution":{"observed_at":"2026-05-11T20:51:09.728099Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2605.04901","last_updated":"2026-05-06T13:31:15Z","snapshot_observed_at":"2026-07-06T23:17:38.226365Z","submitted_at":"2026-05-06T13:31:15Z","title":"On the (In-)Security of the Shuffling Defense in the Transformer Secure Inference","version":1},"reference_index":163,"source":"arxiv_source","source_observed_at":"2026-05-08T17:24:04.123827Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2605.04901"},"observation_digest":"sha256:e1829b2532bb81e670723f1c03dce874da98268cac8fb38598daab7fc10b02f9","observation_id":"e00a2d22-2289-476c-9e5a-3f71f23555fe","resolution":{"observed_at":"2026-05-11T17:36:06.501167Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2605.11170","last_updated":"2026-06-02T13:57:02Z","snapshot_observed_at":"2026-08-02T02:13:17.912919Z","submitted_at":"2026-05-11T19:28:33Z","title":"Unlearning with Asymmetric Sources: Improved Unlearning-Utility Trade-off with Public Data","version":1},"reference_index":85,"source":"arxiv_source","source_observed_at":"2026-05-13T05:56:38.042978Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2605.11170"},"observation_digest":"sha256:b53ec794fd4fb7079efb170108019d09e208648b9b16f8f4be92dd17eb880959","observation_id":"c310ef3d-748e-4d87-8fcf-70172becfe8a","resolution":{"observed_at":"2026-05-13T05:57:21.574789Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2605.30454","last_updated":"2026-05-28T18:26:40Z","snapshot_observed_at":"2026-07-31T16:31:43.334849Z","submitted_at":"2026-05-28T18:26:40Z","title":"The Surface You Test Is Not the Surface That Breaks","version":1},"reference_index":7,"source":"arxiv_source","source_observed_at":"2026-06-29T06:37:19.674012Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2605.30454"},"observation_digest":"sha256:f40069a28cee222e1c06a4156ab4a2e2e2a2f3556b0ddc676708a29895bbef8c","observation_id":"3a8d368c-665a-4992-9445-d2efd5c3034a","resolution":{"observed_at":"2026-06-29T14:33:31.196589Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2606.06854","last_updated":"2026-06-05T02:57:48Z","snapshot_observed_at":"2026-08-09T06:47:24.753136Z","submitted_at":"2026-06-05T02:57:48Z","title":"The Geometry of Last-Layer Model Stealing","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-06-27T22:38:51.570323Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2606.06854"},"observation_digest":"sha256:6c55d84958c959acec3e91988c8d03f9ab6ff5d242a702e574a9af5b725860e6","observation_id":"6e1f4a1c-6ff8-432b-9b5f-226f5cf5d927","resolution":{"observed_at":"2026-07-02T16:27:09.535940Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2606.10091","last_updated":"2026-06-08T19:16:58Z","snapshot_observed_at":"2026-08-05T00:07:01.562006Z","submitted_at":"2026-06-08T19:16:58Z","title":"SoK: Colluding Adversaries in Machine Learning Pipelines","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-06-27T16:10:51.471822Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2606.10091"},"observation_digest":"sha256:94cbf11bc4e282f6e5fd5769339dac9280dd4b20826d7dfcdcefda3516a34758","observation_id":"94efd86d-ba91-4802-af11-79be1c394e34","resolution":{"observed_at":"2026-07-03T02:07:33.530859Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2606.17358","last_updated":"2026-06-23T01:32:01Z","snapshot_observed_at":"2026-08-08T05:52:08.843280Z","submitted_at":"2026-06-15T23:21:32Z","title":"OTRO: Oblivious Tokenization Path with Square-Root ORAM","version":2},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-06-27T02:53:23.964034Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2606.17358"},"observation_digest":"sha256:2d52ae332fe29c561a75ce8e6168978b36a6f43f7b61ffac1b86303021ebb965","observation_id":"bf19d2af-e8e1-4d36-a17c-4fc5c33f01bb","resolution":{"observed_at":"2026-07-03T18:28:49.722869Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2606.22019","last_updated":"2026-06-20T12:48:31Z","snapshot_observed_at":"2026-08-06T19:21:18.734073Z","submitted_at":"2026-06-20T12:48:31Z","title":"Channel Location Constrains the Auditability of Subliminal Learning","version":1},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-06-26T11:52:03.948568Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2606.22019"},"observation_digest":"sha256:beab46c952e599fde0eead2b68fc16d65fe751fea5d21d93a60c22207500e4fb","observation_id":"83fcb56b-12d2-446f-92ad-13bf22621414","resolution":{"observed_at":"2026-07-04T08:19:44.429061Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2606.32008","last_updated":"2026-06-30T17:43:44Z","snapshot_observed_at":"2026-08-08T09:19:54.150532Z","submitted_at":"2026-06-30T17:43:44Z","title":"Surrogate Fidelity: When Can Open LLMs Explain Closed Ones?","version":1},"reference_index":56,"source":"arxiv_source","source_observed_at":"2026-07-01T06:15:42.011563Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2606.32008"},"observation_digest":"sha256:758c6520638ec9934ed130475e0de0454df3c9c487df81b37f291e8c68b3501d","observation_id":"59e7817f-0402-4097-a72f-42a48e7716a3","resolution":{"observed_at":"2026-07-01T09:45:40.067713Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":"2403.06634","doi":"10.48550/arxiv.2403.06634","metadata_source":"arxiv_reference","pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-05T02:28:24.338817Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634","venue":"arXiv (Cornell University)","work_id":"0ab070c2-82e2-41d8-8d46-379236a08dbe","year":2024},"citing_paper":{"arxiv_id":"2607.01313","last_updated":"2026-07-01T17:53:10Z","snapshot_observed_at":"2026-08-06T09:46:43.846052Z","submitted_at":"2026-07-01T17:53:10Z","title":"Black-Box Inference of LLM Architectural Properties with Restrictive API Access","version":1},"reference_index":14,"source":"arxiv_source","source_observed_at":"2026-07-03T21:34:24.902867Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2607.01313"},"observation_digest":"sha256:9988b547ec03505abd05fa0842f234478b4ec62e7a5d7acc273ef4f4b8279a85","observation_id":"d6d491e5-9e09-4ed9-9c0a-f9c281da15ac","resolution":{"observed_at":"2026-07-03T21:38:58.167809Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-09T06:31:02.800959+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-07-14T09:13:20.561611Z","title":"Stealing part of a production language model","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2607.10794","last_updated":"2026-07-12T15:05:04Z","snapshot_observed_at":"2026-08-08T15:30:52.692215Z","submitted_at":"2026-07-12T15:05:04Z","title":"Can Watermarking Techniques Help Prevent LLM Model Stealing?","version":1},"reference_index":61,"source":"arxiv_source","source_observed_at":"2026-07-14T09:13:20.561611Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2607.10794"},"observation_digest":"sha256:abea55621fdecc0936ebb3338e4fb896409161e967bd5d09be240f43aec8a77a","observation_id":"3c42abf6-f1ef-4a00-b1dc-878cc251cc65","resolution":{"observed_at":"2026-07-14T09:13:20.561611Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-02T02:34:08.606939Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634,","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2607.14306","last_updated":"2026-08-01T03:22:14Z","snapshot_observed_at":"2026-08-09T11:09:07.053763Z","submitted_at":"2026-07-15T19:11:54Z","title":"Tracing LLM Behavior to the Training Data with Empirical Next-Token Distributions","version":1},"reference_index":2022,"source":"pdf_text","source_observed_at":"2026-08-02T02:34:08.606939Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2607.14306"},"observation_digest":"sha256:2ee17eca21b4194942a4444b65f9ba75037fdbb50881e6a052643ffe3d05df02","observation_id":"d1692e84-1271-44fa-bb01-77d0f6edbccd","resolution":{"observed_at":"2026-08-02T02:34:08.606939Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2403.06634","snapshot_observed_at":"2026-08-04T01:45:18.338994Z","title":"Stealing part of a production language model.arXiv preprint arXiv:2403.06634,","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2607.14306","last_updated":"2026-08-01T03:22:14Z","snapshot_observed_at":"2026-08-09T11:09:07.053763Z","submitted_at":"2026-07-15T19:11:54Z","title":"Tracing LLM Behavior to the Training Data with Empirical Next-Token Distributions","version":2},"reference_index":2022,"source":"pdf_text","source_observed_at":"2026-08-04T01:45:18.338994Z"},"links":{"cited_paper":"/paper/2403.06634","citing_paper":"/paper/2607.14306"},"observation_digest":"sha256:687c68ab6ad347f207f386ad59ff27760632e29dd5aefa5db34bae7c6a368d5d","observation_id":"13dc8bbc-f492-4229-9cb5-4ada2d9b8f04","resolution":{"observed_at":"2026-08-04T01:45:18.338994Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2403.06634/citation-record","integrity":"/paper/2403.06634/integrity","json":"/paper/2403.06634/citation-record.json","paper":"/paper/2403.06634"},"outbound":[],"paper":{"arxiv_id":"2403.06634","last_updated":"2024-07-09T17:44:00Z","latest_version":2,"primary_category":"cs.CR","snapshot_observed_at":"2026-07-06T17:42:33.242895Z","submitted_at":"2024-03-11T11:46:12Z","title":"Stealing Part of a Production Language Model"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-09T06:31:02.800959+00:00","source":"crossref"},{"observed_at":"2026-08-09T06:30:57.326959+00:00","source":"retraction_watch"}],"thesis":"As of 9 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 30 inbound Pith citation observations for arXiv:2403.06634."}