{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:6KFM5LCRJ3EIC6M6XGTW53P2EA","short_pith_number":"pith:6KFM5LCR","schema_version":"1.0","canonical_sha256":"f28aceac514ec881799eb9a76eedfa200d9ecbb25aa03acf28496bbd87f03be5","source":{"kind":"arxiv","id":"2111.03702","version":1},"attestation_state":"computed","paper":{"title":"Reconstructing Training Data from Diverse ML Models by Ensemble Inversion","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CV"],"primary_cat":"cs.LG","authors_text":"Daniel Kurz, Qian Wang","submitted_at":"2021-11-05T18:59:01Z","abstract_excerpt":"Model Inversion (MI), in which an adversary abuses access to a trained Machine Learning (ML) model attempting to infer sensitive information about its original training data, has attracted increasing research attention. During MI, the trained model under attack (MUA) is usually frozen and used to guide the training of a generator, such as a Generative Adversarial Network (GAN), to reconstruct the distribution of the original training data of that model. This might cause leakage of original training samples, and if successful, the privacy of dataset subjects will be at risk if the training data"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2111.03702","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2021-11-05T18:59:01Z","cross_cats_sorted":["cs.AI","cs.CV"],"title_canon_sha256":"9d665941fa0d477d858b7d0440a5f0e73194ba2fb8da4f7c0db49ab88fc7423c","abstract_canon_sha256":"88dbc7e489c25f6ae1d251019c8f6e4779d020f091f50c1d624adbd981d52d08"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T03:29:30.616602Z","signature_b64":"PiV7EGwo/6KczDbA2yH6MBBq4dZkIVpiwv3mJt/OgHxKg5BXDfcCk9WJyVAbqcKvY/el0NI/k4A544L0n5ZiCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f28aceac514ec881799eb9a76eedfa200d9ecbb25aa03acf28496bbd87f03be5","last_reissued_at":"2026-07-05T03:29:30.616209Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T03:29:30.616209Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Reconstructing Training Data from Diverse ML Models by Ensemble Inversion","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CV"],"primary_cat":"cs.LG","authors_text":"Daniel Kurz, Qian Wang","submitted_at":"2021-11-05T18:59:01Z","abstract_excerpt":"Model Inversion (MI), in which an adversary abuses access to a trained Machine Learning (ML) model attempting to infer sensitive information about its original training data, has attracted increasing research attention. During MI, the trained model under attack (MUA) is usually frozen and used to guide the training of a generator, such as a Generative Adversarial Network (GAN), to reconstruct the distribution of the original training data of that model. This might cause leakage of original training samples, and if successful, the privacy of dataset subjects will be at risk if the training data"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2111.03702","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2111.03702/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2111.03702","created_at":"2026-07-05T03:29:30.616274+00:00"},{"alias_kind":"arxiv_version","alias_value":"2111.03702v1","created_at":"2026-07-05T03:29:30.616274+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2111.03702","created_at":"2026-07-05T03:29:30.616274+00:00"},{"alias_kind":"pith_short_12","alias_value":"6KFM5LCRJ3EI","created_at":"2026-07-05T03:29:30.616274+00:00"},{"alias_kind":"pith_short_16","alias_value":"6KFM5LCRJ3EIC6M6","created_at":"2026-07-05T03:29:30.616274+00:00"},{"alias_kind":"pith_short_8","alias_value":"6KFM5LCR","created_at":"2026-07-05T03:29:30.616274+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2502.00760","citing_title":"Privacy Preserving Properties of Vision Classifiers","ref_index":16,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/6KFM5LCRJ3EIC6M6XGTW53P2EA","json":"https://pith.science/pith/6KFM5LCRJ3EIC6M6XGTW53P2EA.json","graph_json":"https://pith.science/api/pith-number/6KFM5LCRJ3EIC6M6XGTW53P2EA/graph.json","events_json":"https://pith.science/api/pith-number/6KFM5LCRJ3EIC6M6XGTW53P2EA/events.json","paper":"https://pith.science/paper/6KFM5LCR"},"agent_actions":{"view_html":"https://pith.science/pith/6KFM5LCRJ3EIC6M6XGTW53P2EA","download_json":"https://pith.science/pith/6KFM5LCRJ3EIC6M6XGTW53P2EA.json","view_paper":"https://pith.science/paper/6KFM5LCR","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2111.03702&json=true","fetch_graph":"https://pith.science/api/pith-number/6KFM5LCRJ3EIC6M6XGTW53P2EA/graph.json","fetch_events":"https://pith.science/api/pith-number/6KFM5LCRJ3EIC6M6XGTW53P2EA/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/6KFM5LCRJ3EIC6M6XGTW53P2EA/action/timestamp_anchor","attest_storage":"https://pith.science/pith/6KFM5LCRJ3EIC6M6XGTW53P2EA/action/storage_attestation","attest_author":"https://pith.science/pith/6KFM5LCRJ3EIC6M6XGTW53P2EA/action/author_attestation","sign_citation":"https://pith.science/pith/6KFM5LCRJ3EIC6M6XGTW53P2EA/action/citation_signature","submit_replication":"https://pith.science/pith/6KFM5LCRJ3EIC6M6XGTW53P2EA/action/replication_record"}},"created_at":"2026-07-05T03:29:30.616274+00:00","updated_at":"2026-07-05T03:29:30.616274+00:00"}