{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:5AIIDYFYVN2LERYJRKK4VRFLST","short_pith_number":"pith:5AIIDYFY","canonical_record":{"source":{"id":"2605.25902","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-25T14:29:36Z","cross_cats_sorted":[],"title_canon_sha256":"5825a819d7feeac1b5a1e408a2d0b9a6bfbf233865ee203bd7aafedd59ad5ba0","abstract_canon_sha256":"6dcb9c3bb40fe375d9434617c3dc11509b36492f5fbac7894d64d19187e30c91"},"schema_version":"1.0"},"canonical_sha256":"e81081e0b8ab74b247098a95cac4ab94ca3cd644ede4b10024b465bcdad3e87b","source":{"kind":"arxiv","id":"2605.25902","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.25902","created_at":"2026-05-26T02:05:17Z"},{"alias_kind":"arxiv_version","alias_value":"2605.25902v1","created_at":"2026-05-26T02:05:17Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.25902","created_at":"2026-05-26T02:05:17Z"},{"alias_kind":"pith_short_12","alias_value":"5AIIDYFYVN2L","created_at":"2026-05-26T02:05:17Z"},{"alias_kind":"pith_short_16","alias_value":"5AIIDYFYVN2LERYJ","created_at":"2026-05-26T02:05:17Z"},{"alias_kind":"pith_short_8","alias_value":"5AIIDYFY","created_at":"2026-05-26T02:05:17Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:5AIIDYFYVN2LERYJRKK4VRFLST","target":"record","payload":{"canonical_record":{"source":{"id":"2605.25902","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-25T14:29:36Z","cross_cats_sorted":[],"title_canon_sha256":"5825a819d7feeac1b5a1e408a2d0b9a6bfbf233865ee203bd7aafedd59ad5ba0","abstract_canon_sha256":"6dcb9c3bb40fe375d9434617c3dc11509b36492f5fbac7894d64d19187e30c91"},"schema_version":"1.0"},"canonical_sha256":"e81081e0b8ab74b247098a95cac4ab94ca3cd644ede4b10024b465bcdad3e87b","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T02:05:17.601258Z","signature_b64":"MC9HeM43XYYlXRIg3v1UN0b4gfbyKPGGlLRg5nnYbhb7NimIBdVjtoU4f8aIq2hq+wXOuq6f2b8pY3Eap6vMAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e81081e0b8ab74b247098a95cac4ab94ca3cd644ede4b10024b465bcdad3e87b","last_reissued_at":"2026-05-26T02:05:17.600578Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T02:05:17.600578Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.25902","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T02:05:17Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"a8wV+QEhuoDJXq8gcR61HBo4otacyTYz7NmzsumvcJeIMdJkBzd62x/LnQ/xMz5/W/bg+BLi5YPew2LrBRgfDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T20:41:17.109539Z"},"content_sha256":"558d547b6fa595128e56b7acf2b317b5d9f7e0bbf9c8a63134115cd45f978b22","schema_version":"1.0","event_id":"sha256:558d547b6fa595128e56b7acf2b317b5d9f7e0bbf9c8a63134115cd45f978b22"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:5AIIDYFYVN2LERYJRKK4VRFLST","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Reading the Finetuning Prior: Verbatim Content Recovery via Contrastive Decoding Diffing","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Enrico Cassano, Micha{\\l} Brzozowski, Neo Christopher Chung, Zuzanna Dubanowska","submitted_at":"2026-05-25T14:29:36Z","abstract_excerpt":"Narrowly finetuned language models memorize implanted content verbatim, but auditing what a deployed model has been taught, without access to its weights or training data, remains an open challenge. Recent work shows that activation differences between base and finetuned models carry readable traces of the finetuning domain; the state-of-the-art Activation Difference Lens (ADL) recovers a vague domain-level description but requires full \"white-box\" access to model internals. We introduce Contrastive Decoding Diffing (CDD), a model diffing method that operates on output-level logit distribution"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.25902","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.25902/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T02:05:17Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"LUpBzKcd2SzAKWRwvTUQe63BKXhzU6Lvnjc2RwZQhPMt/8OOpLsTU+rdiMMLsdoMl3y8gErFoQw2+Sgf9eNBCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T20:41:17.110153Z"},"content_sha256":"779b31ad031f54bf0742e7df13659788eba9425e12d4ad445a071432fe4110c9","schema_version":"1.0","event_id":"sha256:779b31ad031f54bf0742e7df13659788eba9425e12d4ad445a071432fe4110c9"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/5AIIDYFYVN2LERYJRKK4VRFLST/bundle.json","state_url":"https://pith.science/pith/5AIIDYFYVN2LERYJRKK4VRFLST/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/5AIIDYFYVN2LERYJRKK4VRFLST/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-27T20:41:17Z","links":{"resolver":"https://pith.science/pith/5AIIDYFYVN2LERYJRKK4VRFLST","bundle":"https://pith.science/pith/5AIIDYFYVN2LERYJRKK4VRFLST/bundle.json","state":"https://pith.science/pith/5AIIDYFYVN2LERYJRKK4VRFLST/state.json","well_known_bundle":"https://pith.science/.well-known/pith/5AIIDYFYVN2LERYJRKK4VRFLST/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:5AIIDYFYVN2LERYJRKK4VRFLST","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"6dcb9c3bb40fe375d9434617c3dc11509b36492f5fbac7894d64d19187e30c91","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-25T14:29:36Z","title_canon_sha256":"5825a819d7feeac1b5a1e408a2d0b9a6bfbf233865ee203bd7aafedd59ad5ba0"},"schema_version":"1.0","source":{"id":"2605.25902","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.25902","created_at":"2026-05-26T02:05:17Z"},{"alias_kind":"arxiv_version","alias_value":"2605.25902v1","created_at":"2026-05-26T02:05:17Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.25902","created_at":"2026-05-26T02:05:17Z"},{"alias_kind":"pith_short_12","alias_value":"5AIIDYFYVN2L","created_at":"2026-05-26T02:05:17Z"},{"alias_kind":"pith_short_16","alias_value":"5AIIDYFYVN2LERYJ","created_at":"2026-05-26T02:05:17Z"},{"alias_kind":"pith_short_8","alias_value":"5AIIDYFY","created_at":"2026-05-26T02:05:17Z"}],"graph_snapshots":[{"event_id":"sha256:779b31ad031f54bf0742e7df13659788eba9425e12d4ad445a071432fe4110c9","target":"graph","created_at":"2026-05-26T02:05:17Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.25902/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Narrowly finetuned language models memorize implanted content verbatim, but auditing what a deployed model has been taught, without access to its weights or training data, remains an open challenge. Recent work shows that activation differences between base and finetuned models carry readable traces of the finetuning domain; the state-of-the-art Activation Difference Lens (ADL) recovers a vague domain-level description but requires full \"white-box\" access to model internals. We introduce Contrastive Decoding Diffing (CDD), a model diffing method that operates on output-level logit distribution","authors_text":"Enrico Cassano, Micha{\\l} Brzozowski, Neo Christopher Chung, Zuzanna Dubanowska","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-25T14:29:36Z","title":"Reading the Finetuning Prior: Verbatim Content Recovery via Contrastive Decoding Diffing"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.25902","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:558d547b6fa595128e56b7acf2b317b5d9f7e0bbf9c8a63134115cd45f978b22","target":"record","created_at":"2026-05-26T02:05:17Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"6dcb9c3bb40fe375d9434617c3dc11509b36492f5fbac7894d64d19187e30c91","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-25T14:29:36Z","title_canon_sha256":"5825a819d7feeac1b5a1e408a2d0b9a6bfbf233865ee203bd7aafedd59ad5ba0"},"schema_version":"1.0","source":{"id":"2605.25902","kind":"arxiv","version":1}},"canonical_sha256":"e81081e0b8ab74b247098a95cac4ab94ca3cd644ede4b10024b465bcdad3e87b","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"e81081e0b8ab74b247098a95cac4ab94ca3cd644ede4b10024b465bcdad3e87b","first_computed_at":"2026-05-26T02:05:17.600578Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-26T02:05:17.600578Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"MC9HeM43XYYlXRIg3v1UN0b4gfbyKPGGlLRg5nnYbhb7NimIBdVjtoU4f8aIq2hq+wXOuq6f2b8pY3Eap6vMAg==","signature_status":"signed_v1","signed_at":"2026-05-26T02:05:17.601258Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.25902","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:558d547b6fa595128e56b7acf2b317b5d9f7e0bbf9c8a63134115cd45f978b22","sha256:779b31ad031f54bf0742e7df13659788eba9425e12d4ad445a071432fe4110c9"],"state_sha256":"1cd544092ac10e4092ac3fb13b92d5cc48ad84c25476d6bc0dee97d1005c7d45"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4KFf1hoHcnrE+/TpLuHL+YjIwUmjKe8EYS7TCr1qJmRLjBuq5Q3QZ0y2V8U2McsvcDYsoN3Iluy7m9xmillCAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-27T20:41:17.113439Z","bundle_sha256":"90eb82d6576f22f02d472dff15fd2a785ccbcd7257b15bdf5841656bb35d7f53"}}