{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:4Q654H2RCREX6D4DVOQSXNRQ7V","short_pith_number":"pith:4Q654H2R","schema_version":"1.0","canonical_sha256":"e43dde1f5114497f0f83aba12bb630fd779f6085f645fd09439c1f5d8bd22db3","source":{"kind":"arxiv","id":"2310.06549","version":5},"attestation_state":"computed","paper":{"title":"Be Careful What You Smooth For: Label Smoothing Can Be a Privacy Shield but Also a Catalyst for Model Inversion Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Dominik Hintersdorf, Kristian Kersting, Lukas Struppek","submitted_at":"2023-10-10T11:51:12Z","abstract_excerpt":"Label smoothing -- using softened labels instead of hard ones -- is a widely adopted regularization method for deep learning, showing diverse benefits such as enhanced generalization and calibration. Its implications for preserving model privacy, however, have remained unexplored. To fill this gap, we investigate the impact of label smoothing on model inversion attacks (MIAs), which aim to generate class-representative samples by exploiting the knowledge encoded in a classifier, thereby inferring sensitive information about its training data. Through extensive analyses, we uncover that traditi"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2310.06549","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2023-10-10T11:51:12Z","cross_cats_sorted":["cs.CR","cs.CV"],"title_canon_sha256":"10bbde45fb43a77cd13eca17287b77774123616a9ce891a19b0336049911039e","abstract_canon_sha256":"615bc331f35de11c6fd1974bf8b2747e6d7ef0c1f53db36f9ae58c6f6c275c27"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:40:56.120155Z","signature_b64":"LpQzORGYmHmVpPANvQlbmMTruNJBvTssXcW/3QsN2wwxybX4l6cCw36wW2jFJFs0RX+y3inezHkUERBM7zshAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e43dde1f5114497f0f83aba12bb630fd779f6085f645fd09439c1f5d8bd22db3","last_reissued_at":"2026-07-05T08:40:56.119704Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:40:56.119704Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Be Careful What You Smooth For: Label Smoothing Can Be a Privacy Shield but Also a Catalyst for Model Inversion Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Dominik Hintersdorf, Kristian Kersting, Lukas Struppek","submitted_at":"2023-10-10T11:51:12Z","abstract_excerpt":"Label smoothing -- using softened labels instead of hard ones -- is a widely adopted regularization method for deep learning, showing diverse benefits such as enhanced generalization and calibration. Its implications for preserving model privacy, however, have remained unexplored. To fill this gap, we investigate the impact of label smoothing on model inversion attacks (MIAs), which aim to generate class-representative samples by exploiting the knowledge encoded in a classifier, thereby inferring sensitive information about its training data. Through extensive analyses, we uncover that traditi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2310.06549","kind":"arxiv","version":5},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2310.06549/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2310.06549","created_at":"2026-07-05T08:40:56.119763+00:00"},{"alias_kind":"arxiv_version","alias_value":"2310.06549v5","created_at":"2026-07-05T08:40:56.119763+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2310.06549","created_at":"2026-07-05T08:40:56.119763+00:00"},{"alias_kind":"pith_short_12","alias_value":"4Q654H2RCREX","created_at":"2026-07-05T08:40:56.119763+00:00"},{"alias_kind":"pith_short_16","alias_value":"4Q654H2RCREX6D4D","created_at":"2026-07-05T08:40:56.119763+00:00"},{"alias_kind":"pith_short_8","alias_value":"4Q654H2R","created_at":"2026-07-05T08:40:56.119763+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2506.15412","citing_title":"Partitioning for Intrinsic Model Inversion Resistance in Collaborative Inference","ref_index":31,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/4Q654H2RCREX6D4DVOQSXNRQ7V","json":"https://pith.science/pith/4Q654H2RCREX6D4DVOQSXNRQ7V.json","graph_json":"https://pith.science/api/pith-number/4Q654H2RCREX6D4DVOQSXNRQ7V/graph.json","events_json":"https://pith.science/api/pith-number/4Q654H2RCREX6D4DVOQSXNRQ7V/events.json","paper":"https://pith.science/paper/4Q654H2R"},"agent_actions":{"view_html":"https://pith.science/pith/4Q654H2RCREX6D4DVOQSXNRQ7V","download_json":"https://pith.science/pith/4Q654H2RCREX6D4DVOQSXNRQ7V.json","view_paper":"https://pith.science/paper/4Q654H2R","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2310.06549&json=true","fetch_graph":"https://pith.science/api/pith-number/4Q654H2RCREX6D4DVOQSXNRQ7V/graph.json","fetch_events":"https://pith.science/api/pith-number/4Q654H2RCREX6D4DVOQSXNRQ7V/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/4Q654H2RCREX6D4DVOQSXNRQ7V/action/timestamp_anchor","attest_storage":"https://pith.science/pith/4Q654H2RCREX6D4DVOQSXNRQ7V/action/storage_attestation","attest_author":"https://pith.science/pith/4Q654H2RCREX6D4DVOQSXNRQ7V/action/author_attestation","sign_citation":"https://pith.science/pith/4Q654H2RCREX6D4DVOQSXNRQ7V/action/citation_signature","submit_replication":"https://pith.science/pith/4Q654H2RCREX6D4DVOQSXNRQ7V/action/replication_record"}},"created_at":"2026-07-05T08:40:56.119763+00:00","updated_at":"2026-07-05T08:40:56.119763+00:00"}