{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:46FPUWXJL3PO75VXSPNJWERTDA","short_pith_number":"pith:46FPUWXJ","canonical_record":{"source":{"id":"2605.23158","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-22T02:14:16Z","cross_cats_sorted":["cs.CL","cs.LG"],"title_canon_sha256":"51731a9f8ec084cc52f4f48d11b7e0d530a62ec1d0718590b4a27a2b417dc20c","abstract_canon_sha256":"0527b89d5724e2389b6f0d700bd76abedf9896dbd5135c6a64c0e4d5fc95ed33"},"schema_version":"1.0"},"canonical_sha256":"e78afa5ae95edeeff6b793da9b1233183572fd6ae1bfeda75bf2c37a9e852676","source":{"kind":"arxiv","id":"2605.23158","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.23158","created_at":"2026-05-25T02:01:40Z"},{"alias_kind":"arxiv_version","alias_value":"2605.23158v1","created_at":"2026-05-25T02:01:40Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.23158","created_at":"2026-05-25T02:01:40Z"},{"alias_kind":"pith_short_12","alias_value":"46FPUWXJL3PO","created_at":"2026-05-25T02:01:40Z"},{"alias_kind":"pith_short_16","alias_value":"46FPUWXJL3PO75VX","created_at":"2026-05-25T02:01:40Z"},{"alias_kind":"pith_short_8","alias_value":"46FPUWXJ","created_at":"2026-05-25T02:01:40Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:46FPUWXJL3PO75VXSPNJWERTDA","target":"record","payload":{"canonical_record":{"source":{"id":"2605.23158","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-22T02:14:16Z","cross_cats_sorted":["cs.CL","cs.LG"],"title_canon_sha256":"51731a9f8ec084cc52f4f48d11b7e0d530a62ec1d0718590b4a27a2b417dc20c","abstract_canon_sha256":"0527b89d5724e2389b6f0d700bd76abedf9896dbd5135c6a64c0e4d5fc95ed33"},"schema_version":"1.0"},"canonical_sha256":"e78afa5ae95edeeff6b793da9b1233183572fd6ae1bfeda75bf2c37a9e852676","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-25T02:01:40.895231Z","signature_b64":"LWu4VKBYF61hExw4u5bN6W+MbkaGC2Zz3YrQsJ1uiMNsTwp4oO9StZ0NWQXoXO5kGOE2aTBFlbLkkK+IOwcCBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e78afa5ae95edeeff6b793da9b1233183572fd6ae1bfeda75bf2c37a9e852676","last_reissued_at":"2026-05-25T02:01:40.894682Z","signature_status":"signed_v1","first_computed_at":"2026-05-25T02:01:40.894682Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.23158","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-25T02:01:40Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"n/juMid2T1c8sXHW1JjYA1oZC2gI28QdDXIdnyK1i2ujWbcZDgtO1qdEoq+Dj9ZBflTDd/fGZSQsQrwyrITTBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T10:22:00.020919Z"},"content_sha256":"d740bf5c07561815c5a88d8aa8e6b5fd52ee4a11f281e9f2b8beab67360a02a0","schema_version":"1.0","event_id":"sha256:d740bf5c07561815c5a88d8aa8e6b5fd52ee4a11f281e9f2b8beab67360a02a0"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:46FPUWXJL3PO75VXSPNJWERTDA","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"What Does the Server See? Understanding Privacy Leakage from Large Language Models in Split Inference","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Cen Chen, Fuyi Wang, Mingyuan Fan, Yu Liu","submitted_at":"2026-05-22T02:14:16Z","abstract_excerpt":"The deployment of large language models (LLMs) on resource-constrained devices remains challenging, spurring interest in split inference, where models are partitioned between client and server to reduce computational burden and enhance privacy by transmitting only intermediate activations. However, the privacy-preserving capabilities of split inference, particularly in the context of LLMs, have not been exhaustively investigated. To fill this gap, we introduce ActInv, which solves an intermediate activation matching problem to reconstruct the client's input. Extensive evaluations demonstrate t"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.23158","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.23158/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-25T02:01:40Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"RZ7g/ePjNnztA3eRI/Dp5J/88n1JaINdi1XvhF+bDcBoFoLDxrt4GgUACdN57UshhPvtEHzTotkYkAsmYd0DDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-28T10:22:00.021291Z"},"content_sha256":"89bc4ecb32ecd5267cbf26c1f42a0fcc23eb54eae9cac689dc97547856dcb1a5","schema_version":"1.0","event_id":"sha256:89bc4ecb32ecd5267cbf26c1f42a0fcc23eb54eae9cac689dc97547856dcb1a5"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/46FPUWXJL3PO75VXSPNJWERTDA/bundle.json","state_url":"https://pith.science/pith/46FPUWXJL3PO75VXSPNJWERTDA/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/46FPUWXJL3PO75VXSPNJWERTDA/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-28T10:22:00Z","links":{"resolver":"https://pith.science/pith/46FPUWXJL3PO75VXSPNJWERTDA","bundle":"https://pith.science/pith/46FPUWXJL3PO75VXSPNJWERTDA/bundle.json","state":"https://pith.science/pith/46FPUWXJL3PO75VXSPNJWERTDA/state.json","well_known_bundle":"https://pith.science/.well-known/pith/46FPUWXJL3PO75VXSPNJWERTDA/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:46FPUWXJL3PO75VXSPNJWERTDA","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0527b89d5724e2389b6f0d700bd76abedf9896dbd5135c6a64c0e4d5fc95ed33","cross_cats_sorted":["cs.CL","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-22T02:14:16Z","title_canon_sha256":"51731a9f8ec084cc52f4f48d11b7e0d530a62ec1d0718590b4a27a2b417dc20c"},"schema_version":"1.0","source":{"id":"2605.23158","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.23158","created_at":"2026-05-25T02:01:40Z"},{"alias_kind":"arxiv_version","alias_value":"2605.23158v1","created_at":"2026-05-25T02:01:40Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.23158","created_at":"2026-05-25T02:01:40Z"},{"alias_kind":"pith_short_12","alias_value":"46FPUWXJL3PO","created_at":"2026-05-25T02:01:40Z"},{"alias_kind":"pith_short_16","alias_value":"46FPUWXJL3PO75VX","created_at":"2026-05-25T02:01:40Z"},{"alias_kind":"pith_short_8","alias_value":"46FPUWXJ","created_at":"2026-05-25T02:01:40Z"}],"graph_snapshots":[{"event_id":"sha256:89bc4ecb32ecd5267cbf26c1f42a0fcc23eb54eae9cac689dc97547856dcb1a5","target":"graph","created_at":"2026-05-25T02:01:40Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.23158/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"The deployment of large language models (LLMs) on resource-constrained devices remains challenging, spurring interest in split inference, where models are partitioned between client and server to reduce computational burden and enhance privacy by transmitting only intermediate activations. However, the privacy-preserving capabilities of split inference, particularly in the context of LLMs, have not been exhaustively investigated. To fill this gap, we introduce ActInv, which solves an intermediate activation matching problem to reconstruct the client's input. Extensive evaluations demonstrate t","authors_text":"Cen Chen, Fuyi Wang, Mingyuan Fan, Yu Liu","cross_cats":["cs.CL","cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-22T02:14:16Z","title":"What Does the Server See? Understanding Privacy Leakage from Large Language Models in Split Inference"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.23158","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:d740bf5c07561815c5a88d8aa8e6b5fd52ee4a11f281e9f2b8beab67360a02a0","target":"record","created_at":"2026-05-25T02:01:40Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0527b89d5724e2389b6f0d700bd76abedf9896dbd5135c6a64c0e4d5fc95ed33","cross_cats_sorted":["cs.CL","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-22T02:14:16Z","title_canon_sha256":"51731a9f8ec084cc52f4f48d11b7e0d530a62ec1d0718590b4a27a2b417dc20c"},"schema_version":"1.0","source":{"id":"2605.23158","kind":"arxiv","version":1}},"canonical_sha256":"e78afa5ae95edeeff6b793da9b1233183572fd6ae1bfeda75bf2c37a9e852676","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"e78afa5ae95edeeff6b793da9b1233183572fd6ae1bfeda75bf2c37a9e852676","first_computed_at":"2026-05-25T02:01:40.894682Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-25T02:01:40.894682Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"LWu4VKBYF61hExw4u5bN6W+MbkaGC2Zz3YrQsJ1uiMNsTwp4oO9StZ0NWQXoXO5kGOE2aTBFlbLkkK+IOwcCBA==","signature_status":"signed_v1","signed_at":"2026-05-25T02:01:40.895231Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.23158","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:d740bf5c07561815c5a88d8aa8e6b5fd52ee4a11f281e9f2b8beab67360a02a0","sha256:89bc4ecb32ecd5267cbf26c1f42a0fcc23eb54eae9cac689dc97547856dcb1a5"],"state_sha256":"a0bb08f387a7b1de6e39f89e59256fa023f7a8d581fc2349e6c2a14442b32cea"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"grgCWFdib5DETm3jFditE/UI30FltMCUQQzDHtBHUxDZlYtCm6MEm0ufs7y68NN55hwO/SjwapPe+E+p9mO/Cw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-28T10:22:00.023279Z","bundle_sha256":"7f2a00211b703ab5454dfccbb20f3f2b965c606d740689010bb32a551fc0aa84"}}