{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:7EEOPPTRPQ6ZHGQZBPZAAUXJ4T","short_pith_number":"pith:7EEOPPTR","schema_version":"1.0","canonical_sha256":"f908e7be717c3d939a190bf20052e9e4dc943b79a1c362884643e850f21ef70c","source":{"kind":"arxiv","id":"2305.10036","version":3},"attestation_state":"computed","paper":{"title":"Are You Copying My Model? Protecting the Copyright of Large Language Models for EaaS via Backdoor Watermark","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CY"],"primary_cat":"cs.CL","authors_text":"Binxing Jiao, Bin Zhu, Fangzhao Wu, Guangzhong Sun, Jingwei Yi, Lingjuan Lyu, Shangxi Wu, Tong Xu, Wenjun Peng, Xing Xie","submitted_at":"2023-05-17T08:28:54Z","abstract_excerpt":"Large language models (LLMs) have demonstrated powerful capabilities in both text understanding and generation. Companies have begun to offer Embedding as a Service (EaaS) based on these LLMs, which can benefit various natural language processing (NLP) tasks for customers. However, previous studies have shown that EaaS is vulnerable to model extraction attacks, which can cause significant losses for the owners of LLMs, as training these models is extremely expensive. To protect the copyright of LLMs for EaaS, we propose an Embedding Watermark method called EmbMarker that implants backdoors on "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2305.10036","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2023-05-17T08:28:54Z","cross_cats_sorted":["cs.CY"],"title_canon_sha256":"233eea780887cf492eb37cf78322fdbd6d66d4a4180b3e3abf5b018d4070c705","abstract_canon_sha256":"e2db2fee785fd1bf78aa5111cf7ff402316ff0c5d866a9a4f33bbec8e2ca5fde"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:16:50.415466Z","signature_b64":"BezjsFXOdFBekdEdxSQKRmMOsxi+Axrec2WxUMpiCD7AcHIpGk34hobpb41O0RObvOHKR4XN7R9oElUmPjHhCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f908e7be717c3d939a190bf20052e9e4dc943b79a1c362884643e850f21ef70c","last_reissued_at":"2026-07-05T06:16:50.415020Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:16:50.415020Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Are You Copying My Model? Protecting the Copyright of Large Language Models for EaaS via Backdoor Watermark","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CY"],"primary_cat":"cs.CL","authors_text":"Binxing Jiao, Bin Zhu, Fangzhao Wu, Guangzhong Sun, Jingwei Yi, Lingjuan Lyu, Shangxi Wu, Tong Xu, Wenjun Peng, Xing Xie","submitted_at":"2023-05-17T08:28:54Z","abstract_excerpt":"Large language models (LLMs) have demonstrated powerful capabilities in both text understanding and generation. Companies have begun to offer Embedding as a Service (EaaS) based on these LLMs, which can benefit various natural language processing (NLP) tasks for customers. However, previous studies have shown that EaaS is vulnerable to model extraction attacks, which can cause significant losses for the owners of LLMs, as training these models is extremely expensive. To protect the copyright of LLMs for EaaS, we propose an Embedding Watermark method called EmbMarker that implants backdoors on "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2305.10036","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2305.10036/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2305.10036","created_at":"2026-07-05T06:16:50.415076+00:00"},{"alias_kind":"arxiv_version","alias_value":"2305.10036v3","created_at":"2026-07-05T06:16:50.415076+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2305.10036","created_at":"2026-07-05T06:16:50.415076+00:00"},{"alias_kind":"pith_short_12","alias_value":"7EEOPPTRPQ6Z","created_at":"2026-07-05T06:16:50.415076+00:00"},{"alias_kind":"pith_short_16","alias_value":"7EEOPPTRPQ6ZHGQZ","created_at":"2026-07-05T06:16:50.415076+00:00"},{"alias_kind":"pith_short_8","alias_value":"7EEOPPTR","created_at":"2026-07-05T06:16:50.415076+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2604.25247","citing_title":"R-CoT: A Reasoning-Layer Watermark via Redundant Chain-of-Thought in Large Language Models","ref_index":16,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T","json":"https://pith.science/pith/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T.json","graph_json":"https://pith.science/api/pith-number/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T/graph.json","events_json":"https://pith.science/api/pith-number/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T/events.json","paper":"https://pith.science/paper/7EEOPPTR"},"agent_actions":{"view_html":"https://pith.science/pith/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T","download_json":"https://pith.science/pith/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T.json","view_paper":"https://pith.science/paper/7EEOPPTR","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2305.10036&json=true","fetch_graph":"https://pith.science/api/pith-number/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T/graph.json","fetch_events":"https://pith.science/api/pith-number/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T/action/timestamp_anchor","attest_storage":"https://pith.science/pith/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T/action/storage_attestation","attest_author":"https://pith.science/pith/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T/action/author_attestation","sign_citation":"https://pith.science/pith/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T/action/citation_signature","submit_replication":"https://pith.science/pith/7EEOPPTRPQ6ZHGQZBPZAAUXJ4T/action/replication_record"}},"created_at":"2026-07-05T06:16:50.415076+00:00","updated_at":"2026-07-05T06:16:50.415076+00:00"}