{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:5BZP6NW7TQBA4J7YMPMYBW3EGA","short_pith_number":"pith:5BZP6NW7","schema_version":"1.0","canonical_sha256":"e872ff36df9c020e27f863d980db643033a882da21f4e0533d42ec9f105c9b88","source":{"kind":"arxiv","id":"2608.02995","version":1},"attestation_state":"computed","paper":{"title":"SparSEEty: Extracting Tokens from Sparsity-Exploiting LLM Serving Systems via Deterministic Side Channels","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Dokyung Song, Euihyun Lee, Jinyoung Park, Yongwan Jo","submitted_at":"2026-08-04T01:21:29Z","abstract_excerpt":"Modern large language models (LLMs) exhibit activation sparsity, wherein only a subset of their neurons is activated for given input tokens. Researchers have leveraged this property to optimize LLM serving systems by omitting weight accesses and computations pertaining to inactive neurons. Unfortunately, however, such optimizations create input-dependent weight accesses, which can be leaked over side channels.\n  We present SparSEEty, a new token extraction attack that exploits input-dependent neuron weight accesses introduced by sparsity-exploiting LLM serving systems. SparSEEty first construc"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2608.02995","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-08-04T01:21:29Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"fc17741d02d0d20ceef0f4e9d1462c1e24ee6234f861739bb1ec4ea7187442bd","abstract_canon_sha256":"db7d609393d20fe7d01573eab395015fda8e3215871395daadf565ea2879799f"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-08-05T00:44:21.490690Z","signature_b64":"iqJtzWVXKEQzyR5HwCAur2ubGm6uM0NoIzE8R2c9lIdy0CUVLEJjxOqFBjrNxhIUd9aEEppShfqrZ3jczUGODQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e872ff36df9c020e27f863d980db643033a882da21f4e0533d42ec9f105c9b88","last_reissued_at":"2026-08-05T00:44:21.488179Z","signature_status":"signed_v1","first_computed_at":"2026-08-05T00:44:21.488179Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"SparSEEty: Extracting Tokens from Sparsity-Exploiting LLM Serving Systems via Deterministic Side Channels","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Dokyung Song, Euihyun Lee, Jinyoung Park, Yongwan Jo","submitted_at":"2026-08-04T01:21:29Z","abstract_excerpt":"Modern large language models (LLMs) exhibit activation sparsity, wherein only a subset of their neurons is activated for given input tokens. Researchers have leveraged this property to optimize LLM serving systems by omitting weight accesses and computations pertaining to inactive neurons. Unfortunately, however, such optimizations create input-dependent weight accesses, which can be leaked over side channels.\n  We present SparSEEty, a new token extraction attack that exploits input-dependent neuron weight accesses introduced by sparsity-exploiting LLM serving systems. SparSEEty first construc"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2608.02995","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2608.02995/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2608.02995","created_at":"2026-08-05T00:44:21.489110+00:00"},{"alias_kind":"arxiv_version","alias_value":"2608.02995v1","created_at":"2026-08-05T00:44:21.489110+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2608.02995","created_at":"2026-08-05T00:44:21.489110+00:00"},{"alias_kind":"pith_short_12","alias_value":"5BZP6NW7TQBA","created_at":"2026-08-05T00:44:21.489110+00:00"},{"alias_kind":"pith_short_16","alias_value":"5BZP6NW7TQBA4J7Y","created_at":"2026-08-05T00:44:21.489110+00:00"},{"alias_kind":"pith_short_8","alias_value":"5BZP6NW7","created_at":"2026-08-05T00:44:21.489110+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/5BZP6NW7TQBA4J7YMPMYBW3EGA","json":"https://pith.science/pith/5BZP6NW7TQBA4J7YMPMYBW3EGA.json","graph_json":"https://pith.science/api/pith-number/5BZP6NW7TQBA4J7YMPMYBW3EGA/graph.json","events_json":"https://pith.science/api/pith-number/5BZP6NW7TQBA4J7YMPMYBW3EGA/events.json","paper":"https://pith.science/paper/5BZP6NW7"},"agent_actions":{"view_html":"https://pith.science/pith/5BZP6NW7TQBA4J7YMPMYBW3EGA","download_json":"https://pith.science/pith/5BZP6NW7TQBA4J7YMPMYBW3EGA.json","view_paper":"https://pith.science/paper/5BZP6NW7","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2608.02995&json=true","fetch_graph":"https://pith.science/api/pith-number/5BZP6NW7TQBA4J7YMPMYBW3EGA/graph.json","fetch_events":"https://pith.science/api/pith-number/5BZP6NW7TQBA4J7YMPMYBW3EGA/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/5BZP6NW7TQBA4J7YMPMYBW3EGA/action/timestamp_anchor","attest_storage":"https://pith.science/pith/5BZP6NW7TQBA4J7YMPMYBW3EGA/action/storage_attestation","attest_author":"https://pith.science/pith/5BZP6NW7TQBA4J7YMPMYBW3EGA/action/author_attestation","sign_citation":"https://pith.science/pith/5BZP6NW7TQBA4J7YMPMYBW3EGA/action/citation_signature","submit_replication":"https://pith.science/pith/5BZP6NW7TQBA4J7YMPMYBW3EGA/action/replication_record"}},"created_at":"2026-08-05T00:44:21.489110+00:00","updated_at":"2026-08-05T00:44:21.489110+00:00"}