{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:3APDENOSN4GXDQLSA6YCK4H7EN","short_pith_number":"pith:3APDENOS","schema_version":"1.0","canonical_sha256":"d81e3235d26f0d71c17207b02570ff234e27da75027b29f6384d87319be4094e","source":{"kind":"arxiv","id":"2411.07536","version":1},"attestation_state":"computed","paper":{"title":"Model Stealing for Any Low-Rank Language Model","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.DS","stat.ML"],"primary_cat":"cs.LG","authors_text":"Allen Liu, Ankur Moitra","submitted_at":"2024-11-12T04:25:31Z","abstract_excerpt":"Model stealing, where a learner tries to recover an unknown model via carefully chosen queries, is a critical problem in machine learning, as it threatens the security of proprietary models and the privacy of data they are trained on. In recent years, there has been particular interest in stealing large language models (LLMs). In this paper, we aim to build a theoretical understanding of stealing language models by studying a simple and mathematically tractable setting. We study model stealing for Hidden Markov Models (HMMs), and more generally low-rank language models.\n  We assume that the le"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2411.07536","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2024-11-12T04:25:31Z","cross_cats_sorted":["cs.AI","cs.DS","stat.ML"],"title_canon_sha256":"6f4b12388987b4786c5daaf09cc0d790a5709b9b0a4c472016f1ec4ebca96b48","abstract_canon_sha256":"9da3bb73aa1f99754263e2aefcefb44cdf16643939624f7eb67e5f9827c423fa"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:34:25.155688Z","signature_b64":"yBDeV92c0OdVTEm1AIC5Nk5OgoT36jOB29Y4WM699QeDPmxCK42xnL4cef1F1dTejGVD3x3p1qpxEcFA6QKhCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d81e3235d26f0d71c17207b02570ff234e27da75027b29f6384d87319be4094e","last_reissued_at":"2026-07-05T09:34:25.155224Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:34:25.155224Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Model Stealing for Any Low-Rank Language Model","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.DS","stat.ML"],"primary_cat":"cs.LG","authors_text":"Allen Liu, Ankur Moitra","submitted_at":"2024-11-12T04:25:31Z","abstract_excerpt":"Model stealing, where a learner tries to recover an unknown model via carefully chosen queries, is a critical problem in machine learning, as it threatens the security of proprietary models and the privacy of data they are trained on. In recent years, there has been particular interest in stealing large language models (LLMs). In this paper, we aim to build a theoretical understanding of stealing language models by studying a simple and mathematically tractable setting. We study model stealing for Hidden Markov Models (HMMs), and more generally low-rank language models.\n  We assume that the le"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2411.07536","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2411.07536/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2411.07536","created_at":"2026-07-05T09:34:25.155280+00:00"},{"alias_kind":"arxiv_version","alias_value":"2411.07536v1","created_at":"2026-07-05T09:34:25.155280+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2411.07536","created_at":"2026-07-05T09:34:25.155280+00:00"},{"alias_kind":"pith_short_12","alias_value":"3APDENOSN4GX","created_at":"2026-07-05T09:34:25.155280+00:00"},{"alias_kind":"pith_short_16","alias_value":"3APDENOSN4GXDQLS","created_at":"2026-07-05T09:34:25.155280+00:00"},{"alias_kind":"pith_short_8","alias_value":"3APDENOS","created_at":"2026-07-05T09:34:25.155280+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2604.04855","citing_title":"The Role of Generator Access in Autoregressive Post-Training","ref_index":12,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/3APDENOSN4GXDQLSA6YCK4H7EN","json":"https://pith.science/pith/3APDENOSN4GXDQLSA6YCK4H7EN.json","graph_json":"https://pith.science/api/pith-number/3APDENOSN4GXDQLSA6YCK4H7EN/graph.json","events_json":"https://pith.science/api/pith-number/3APDENOSN4GXDQLSA6YCK4H7EN/events.json","paper":"https://pith.science/paper/3APDENOS"},"agent_actions":{"view_html":"https://pith.science/pith/3APDENOSN4GXDQLSA6YCK4H7EN","download_json":"https://pith.science/pith/3APDENOSN4GXDQLSA6YCK4H7EN.json","view_paper":"https://pith.science/paper/3APDENOS","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2411.07536&json=true","fetch_graph":"https://pith.science/api/pith-number/3APDENOSN4GXDQLSA6YCK4H7EN/graph.json","fetch_events":"https://pith.science/api/pith-number/3APDENOSN4GXDQLSA6YCK4H7EN/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/3APDENOSN4GXDQLSA6YCK4H7EN/action/timestamp_anchor","attest_storage":"https://pith.science/pith/3APDENOSN4GXDQLSA6YCK4H7EN/action/storage_attestation","attest_author":"https://pith.science/pith/3APDENOSN4GXDQLSA6YCK4H7EN/action/author_attestation","sign_citation":"https://pith.science/pith/3APDENOSN4GXDQLSA6YCK4H7EN/action/citation_signature","submit_replication":"https://pith.science/pith/3APDENOSN4GXDQLSA6YCK4H7EN/action/replication_record"}},"created_at":"2026-07-05T09:34:25.155280+00:00","updated_at":"2026-07-05T09:34:25.155280+00:00"}