{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:43TGKL6I3UW27CK6UCNXVUOBQT","short_pith_number":"pith:43TGKL6I","canonical_record":{"source":{"id":"2606.09401","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-08T12:21:02Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"88abe7207493948ec2aa1c3003a8f5c129df32b2e0ac2248f433362080fcce01","abstract_canon_sha256":"aee10c37f0302c3368336331ffede9971f9e03e2cde29ad946507facfb067800"},"schema_version":"1.0"},"canonical_sha256":"e6e6652fc8dd2daf895ea09b7ad1c184d969dcac70bba18cde76a57ddb806724","source":{"kind":"arxiv","id":"2606.09401","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.09401","created_at":"2026-06-09T02:08:20Z"},{"alias_kind":"arxiv_version","alias_value":"2606.09401v1","created_at":"2026-06-09T02:08:20Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.09401","created_at":"2026-06-09T02:08:20Z"},{"alias_kind":"pith_short_12","alias_value":"43TGKL6I3UW2","created_at":"2026-06-09T02:08:20Z"},{"alias_kind":"pith_short_16","alias_value":"43TGKL6I3UW27CK6","created_at":"2026-06-09T02:08:20Z"},{"alias_kind":"pith_short_8","alias_value":"43TGKL6I","created_at":"2026-06-09T02:08:20Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:43TGKL6I3UW27CK6UCNXVUOBQT","target":"record","payload":{"canonical_record":{"source":{"id":"2606.09401","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-08T12:21:02Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"88abe7207493948ec2aa1c3003a8f5c129df32b2e0ac2248f433362080fcce01","abstract_canon_sha256":"aee10c37f0302c3368336331ffede9971f9e03e2cde29ad946507facfb067800"},"schema_version":"1.0"},"canonical_sha256":"e6e6652fc8dd2daf895ea09b7ad1c184d969dcac70bba18cde76a57ddb806724","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-09T02:08:20.229937Z","signature_b64":"i9ltNBhZINbFbCampoNCEYbybmbRDQBF7JXzO796YThZUdyL31k+yBT6LYwda1whY6GwTlkZ/xz3Xzv4QxOZAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e6e6652fc8dd2daf895ea09b7ad1c184d969dcac70bba18cde76a57ddb806724","last_reissued_at":"2026-06-09T02:08:20.229147Z","signature_status":"signed_v1","first_computed_at":"2026-06-09T02:08:20.229147Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.09401","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T02:08:20Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"3NmYnczdoTZE7IoSUyeafPEyhC/v8wu/q0WyDo1e36j8hKkmoFba1hzbGb1/CcD/bzcrF1/kOeWWa5duVwWGBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T09:29:16.578922Z"},"content_sha256":"0f9f96bddefa7a012fcb1c96dea2db1f46fb77e48cce838b2ad2d95b29cea48a","schema_version":"1.0","event_id":"sha256:0f9f96bddefa7a012fcb1c96dea2db1f46fb77e48cce838b2ad2d95b29cea48a"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:43TGKL6I3UW27CK6UCNXVUOBQT","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Benchmarking Empirical Privacy Protection for Adaptations of Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Adam Dziedzic, Bart{\\l}omiej Marek, Franziska Boenisch, Lorenzo Rossi, Michael Backes, Vincent Hanke, Xun Wang","submitted_at":"2026-06-08T12:21:02Z","abstract_excerpt":"Recent work has applied differential privacy (DP) to adapt large language models (LLMs) for sensitive applications, offering theoretical guarantees. However, its practical effectiveness remains unclear, partly due to LLM pretraining, where overlaps and interdependencies with adaptation data can undermine privacy despite DP efforts. To analyze this issue in practice, we investigate privacy risks under DP adaptations in LLMs using state-of-the-art attacks such as robust membership inference and canary data extraction. We benchmark these risks by systematically varying the adaptation data distrib"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.09401","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.09401/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T02:08:20Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"AFAsVqDiMtU8uP33rhEeTdlF+QlgyIYxVS50nNDY50c7Bi7DNj2TyDGJyn/r4z1v11bS017Nb2K+J9p++eS7BA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T09:29:16.579534Z"},"content_sha256":"6d9f3d01fa6635262f347cdd83e27d7dad2968aa837669e96a78a48976defb29","schema_version":"1.0","event_id":"sha256:6d9f3d01fa6635262f347cdd83e27d7dad2968aa837669e96a78a48976defb29"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/43TGKL6I3UW27CK6UCNXVUOBQT/bundle.json","state_url":"https://pith.science/pith/43TGKL6I3UW27CK6UCNXVUOBQT/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/43TGKL6I3UW27CK6UCNXVUOBQT/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-28T09:29:16Z","links":{"resolver":"https://pith.science/pith/43TGKL6I3UW27CK6UCNXVUOBQT","bundle":"https://pith.science/pith/43TGKL6I3UW27CK6UCNXVUOBQT/bundle.json","state":"https://pith.science/pith/43TGKL6I3UW27CK6UCNXVUOBQT/state.json","well_known_bundle":"https://pith.science/.well-known/pith/43TGKL6I3UW27CK6UCNXVUOBQT/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:43TGKL6I3UW27CK6UCNXVUOBQT","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"aee10c37f0302c3368336331ffede9971f9e03e2cde29ad946507facfb067800","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-08T12:21:02Z","title_canon_sha256":"88abe7207493948ec2aa1c3003a8f5c129df32b2e0ac2248f433362080fcce01"},"schema_version":"1.0","source":{"id":"2606.09401","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.09401","created_at":"2026-06-09T02:08:20Z"},{"alias_kind":"arxiv_version","alias_value":"2606.09401v1","created_at":"2026-06-09T02:08:20Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.09401","created_at":"2026-06-09T02:08:20Z"},{"alias_kind":"pith_short_12","alias_value":"43TGKL6I3UW2","created_at":"2026-06-09T02:08:20Z"},{"alias_kind":"pith_short_16","alias_value":"43TGKL6I3UW27CK6","created_at":"2026-06-09T02:08:20Z"},{"alias_kind":"pith_short_8","alias_value":"43TGKL6I","created_at":"2026-06-09T02:08:20Z"}],"graph_snapshots":[{"event_id":"sha256:6d9f3d01fa6635262f347cdd83e27d7dad2968aa837669e96a78a48976defb29","target":"graph","created_at":"2026-06-09T02:08:20Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.09401/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Recent work has applied differential privacy (DP) to adapt large language models (LLMs) for sensitive applications, offering theoretical guarantees. However, its practical effectiveness remains unclear, partly due to LLM pretraining, where overlaps and interdependencies with adaptation data can undermine privacy despite DP efforts. To analyze this issue in practice, we investigate privacy risks under DP adaptations in LLMs using state-of-the-art attacks such as robust membership inference and canary data extraction. We benchmark these risks by systematically varying the adaptation data distrib","authors_text":"Adam Dziedzic, Bart{\\l}omiej Marek, Franziska Boenisch, Lorenzo Rossi, Michael Backes, Vincent Hanke, Xun Wang","cross_cats":["cs.CR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-08T12:21:02Z","title":"Benchmarking Empirical Privacy Protection for Adaptations of Large Language Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.09401","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:0f9f96bddefa7a012fcb1c96dea2db1f46fb77e48cce838b2ad2d95b29cea48a","target":"record","created_at":"2026-06-09T02:08:20Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"aee10c37f0302c3368336331ffede9971f9e03e2cde29ad946507facfb067800","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-08T12:21:02Z","title_canon_sha256":"88abe7207493948ec2aa1c3003a8f5c129df32b2e0ac2248f433362080fcce01"},"schema_version":"1.0","source":{"id":"2606.09401","kind":"arxiv","version":1}},"canonical_sha256":"e6e6652fc8dd2daf895ea09b7ad1c184d969dcac70bba18cde76a57ddb806724","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"e6e6652fc8dd2daf895ea09b7ad1c184d969dcac70bba18cde76a57ddb806724","first_computed_at":"2026-06-09T02:08:20.229147Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-09T02:08:20.229147Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"i9ltNBhZINbFbCampoNCEYbybmbRDQBF7JXzO796YThZUdyL31k+yBT6LYwda1whY6GwTlkZ/xz3Xzv4QxOZAQ==","signature_status":"signed_v1","signed_at":"2026-06-09T02:08:20.229937Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.09401","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:0f9f96bddefa7a012fcb1c96dea2db1f46fb77e48cce838b2ad2d95b29cea48a","sha256:6d9f3d01fa6635262f347cdd83e27d7dad2968aa837669e96a78a48976defb29"],"state_sha256":"046f3e07bb4b4f95966a31199932b5199097d798d92660fef1a48fb7f48986db"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"JwwdeuUkDooR9hZAxu5tBWrWAMaq2oj9HUDK6+Ejw565pAfBz7/g5AmIQMDvncTPpeF0XcbcEfMoeoKwGklqCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-28T09:29:16.582153Z","bundle_sha256":"3220086235ccd2d49326e23a6404d996d13db73f50ec6175903931322c006f1f"}}