{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:2ELMMKPP6RGZFWJ24TM42O2IPY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"a436b9d59efbbb6dec8ddd08d92606167124d927c4ba5814eb7b80455cb80532","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-07T10:52:15Z","title_canon_sha256":"3c30280e653d1ea5277c546984f37fdc1dabcbafd547bf8543597438832b6161"},"schema_version":"1.0","source":{"id":"1906.03006","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1906.03006","created_at":"2026-05-17T23:43:55Z"},{"alias_kind":"arxiv_version","alias_value":"1906.03006v1","created_at":"2026-05-17T23:43:55Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.03006","created_at":"2026-05-17T23:43:55Z"},{"alias_kind":"pith_short_12","alias_value":"2ELMMKPP6RGZ","created_at":"2026-05-18T12:33:07Z"},{"alias_kind":"pith_short_16","alias_value":"2ELMMKPP6RGZFWJ2","created_at":"2026-05-18T12:33:07Z"},{"alias_kind":"pith_short_8","alias_value":"2ELMMKPP","created_at":"2026-05-18T12:33:07Z"}],"graph_snapshots":[{"event_id":"sha256:786be8c0168b436a6180d2ea15c8ed095fec8125fd235c6a1130227da0dd21ba","target":"graph","created_at":"2026-05-17T23:43:55Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We present two information leakage attacks that outperform previous work on membership inference against generative models. The first attack allows membership inference without assumptions on the type of the generative model. Contrary to previous evaluation metrics for generative models, like Kernel Density Estimation, it only considers samples of the model which are close to training data records. The second attack specifically targets Variational Autoencoders, achieving high membership inference accuracy. Furthermore, previous work mostly considers membership inference adversaries who perfor","authors_text":"Benjamin Hilprecht, Daniel Bernau, Martin H\\\"arterich","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-07T10:52:15Z","title":"Reconstruction and Membership Inference Attacks against Generative Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.03006","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:25662a117fe8d3adceb9dd2a9d2ecb7bed799e62d98b446d6cbaa6b143c51075","target":"record","created_at":"2026-05-17T23:43:55Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"a436b9d59efbbb6dec8ddd08d92606167124d927c4ba5814eb7b80455cb80532","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-07T10:52:15Z","title_canon_sha256":"3c30280e653d1ea5277c546984f37fdc1dabcbafd547bf8543597438832b6161"},"schema_version":"1.0","source":{"id":"1906.03006","kind":"arxiv","version":1}},"canonical_sha256":"d116c629eff44d92d93ae4d9cd3b487e1ca1a7400df60181bef8d181c7a6acac","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d116c629eff44d92d93ae4d9cd3b487e1ca1a7400df60181bef8d181c7a6acac","first_computed_at":"2026-05-17T23:43:55.394726Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:43:55.394726Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"7xJMwwsRQG1gzvWOhgD4Ptc2nQHtr2jKZvmAeh1PKpkjJr+MUkjxAiE58eN7W0UHWlJclJNu7R13ovKYhzotAA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:43:55.395464Z","signed_message":"canonical_sha256_bytes"},"source_id":"1906.03006","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:25662a117fe8d3adceb9dd2a9d2ecb7bed799e62d98b446d6cbaa6b143c51075","sha256:786be8c0168b436a6180d2ea15c8ed095fec8125fd235c6a1130227da0dd21ba"],"state_sha256":"c73bc5cf2e7ffe03de58c3c6d864020f47fc065f8bf699f50038a1dc9aaa8127"}