{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:3L73ZDWZLKKQE4SQ3FJH7PZI6L","short_pith_number":"pith:3L73ZDWZ","schema_version":"1.0","canonical_sha256":"daffbc8ed95a95027250d9527fbf28f2c8d7ec8aa8980ef981b22f83189a2398","source":{"kind":"arxiv","id":"1905.11742","version":3},"attestation_state":"computed","paper":{"title":"Overlearning Reveals Sensitive Attributes","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.NE","stat.ML"],"primary_cat":"cs.LG","authors_text":"Congzheng Song, Vitaly Shmatikov","submitted_at":"2019-05-28T11:16:02Z","abstract_excerpt":"\"Overlearning\" means that a model trained for a seemingly simple objective implicitly learns to recognize attributes and concepts that are (1) not part of the learning objective, and (2) sensitive from a privacy or bias perspective. For example, a binary gender classifier of facial images also learns to recognize races\\textemdash even races that are not represented in the training data\\textemdash and identities.\n  We demonstrate overlearning in several vision and NLP models and analyze its harmful consequences. First, inference-time representations of an overlearned model reveal sensitive attr"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1905.11742","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-05-28T11:16:02Z","cross_cats_sorted":["cs.NE","stat.ML"],"title_canon_sha256":"e1aaf7b2f3727bdb9e7c3428d23d067998f5e8ca4c045fa5263a46428a468138","abstract_canon_sha256":"89f71d8bdee7b69f5c8340d0d9945f982eb0a94f8bea367a1cd62ef6818e65a7"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:39:11.880764Z","signature_b64":"f5Y2e3EH6OWgI4tQCdOeDpLF8J0hOgX4jCvy/QEWfY5hHDo9XWtouPNmEhAH5wqrKxhgKdFxRHfSbwW/M5jZCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"daffbc8ed95a95027250d9527fbf28f2c8d7ec8aa8980ef981b22f83189a2398","last_reissued_at":"2026-07-05T00:39:11.880238Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:39:11.880238Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Overlearning Reveals Sensitive Attributes","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.NE","stat.ML"],"primary_cat":"cs.LG","authors_text":"Congzheng Song, Vitaly Shmatikov","submitted_at":"2019-05-28T11:16:02Z","abstract_excerpt":"\"Overlearning\" means that a model trained for a seemingly simple objective implicitly learns to recognize attributes and concepts that are (1) not part of the learning objective, and (2) sensitive from a privacy or bias perspective. For example, a binary gender classifier of facial images also learns to recognize races\\textemdash even races that are not represented in the training data\\textemdash and identities.\n  We demonstrate overlearning in several vision and NLP models and analyze its harmful consequences. First, inference-time representations of an overlearned model reveal sensitive attr"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1905.11742","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1905.11742/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1905.11742","created_at":"2026-07-05T00:39:11.880321+00:00"},{"alias_kind":"arxiv_version","alias_value":"1905.11742v3","created_at":"2026-07-05T00:39:11.880321+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1905.11742","created_at":"2026-07-05T00:39:11.880321+00:00"},{"alias_kind":"pith_short_12","alias_value":"3L73ZDWZLKKQ","created_at":"2026-07-05T00:39:11.880321+00:00"},{"alias_kind":"pith_short_16","alias_value":"3L73ZDWZLKKQE4SQ","created_at":"2026-07-05T00:39:11.880321+00:00"},{"alias_kind":"pith_short_8","alias_value":"3L73ZDWZ","created_at":"2026-07-05T00:39:11.880321+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.08343","citing_title":"Private Vertical Federated Inference for Time-Series","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01204","citing_title":"FLRSP: Privacy-Preserving Federated Learning Using Randomly Selected Model Parameters","ref_index":33,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/3L73ZDWZLKKQE4SQ3FJH7PZI6L","json":"https://pith.science/pith/3L73ZDWZLKKQE4SQ3FJH7PZI6L.json","graph_json":"https://pith.science/api/pith-number/3L73ZDWZLKKQE4SQ3FJH7PZI6L/graph.json","events_json":"https://pith.science/api/pith-number/3L73ZDWZLKKQE4SQ3FJH7PZI6L/events.json","paper":"https://pith.science/paper/3L73ZDWZ"},"agent_actions":{"view_html":"https://pith.science/pith/3L73ZDWZLKKQE4SQ3FJH7PZI6L","download_json":"https://pith.science/pith/3L73ZDWZLKKQE4SQ3FJH7PZI6L.json","view_paper":"https://pith.science/paper/3L73ZDWZ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1905.11742&json=true","fetch_graph":"https://pith.science/api/pith-number/3L73ZDWZLKKQE4SQ3FJH7PZI6L/graph.json","fetch_events":"https://pith.science/api/pith-number/3L73ZDWZLKKQE4SQ3FJH7PZI6L/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/3L73ZDWZLKKQE4SQ3FJH7PZI6L/action/timestamp_anchor","attest_storage":"https://pith.science/pith/3L73ZDWZLKKQE4SQ3FJH7PZI6L/action/storage_attestation","attest_author":"https://pith.science/pith/3L73ZDWZLKKQE4SQ3FJH7PZI6L/action/author_attestation","sign_citation":"https://pith.science/pith/3L73ZDWZLKKQE4SQ3FJH7PZI6L/action/citation_signature","submit_replication":"https://pith.science/pith/3L73ZDWZLKKQE4SQ3FJH7PZI6L/action/replication_record"}},"created_at":"2026-07-05T00:39:11.880321+00:00","updated_at":"2026-07-05T00:39:11.880321+00:00"}