{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2018:7EQGDF6BYQ76R4F4IZA763VTWB","short_pith_number":"pith:7EQGDF6B","schema_version":"1.0","canonical_sha256":"f9206197c1c43fe8f0bc4641ff6eb3b078a6862cb2329a523af0a6a22e393322","source":{"kind":"arxiv","id":"1806.01246","version":2},"attestation_state":"computed","paper":{"title":"ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Ahmed Salem, Mario Fritz, Mathias Humbert, Michael Backes, Pascal Berrang, Yang Zhang","submitted_at":"2018-06-04T17:38:42Z","abstract_excerpt":"Machine learning (ML) has become a core component of many real-world applications and training data is a key factor that drives current progress. This huge success has led Internet companies to deploy machine learning as a service (MLaaS). Recently, the first membership inference attack has shown that extraction of information on the training set is possible in such MLaaS settings, which has severe security and privacy implications.\n  However, the early demonstrations of the feasibility of such attacks have many assumptions on the adversary, such as using multiple so-called shadow models, know"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1806.01246","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-06-04T17:38:42Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"190ed574a47bf6818f6dafe111d53c85d531feb3e427d744b9d8aa22e2de0a1f","abstract_canon_sha256":"4f8c61886eb859c7126b44947b76c4d8a77b57acd774cf0e0224c5bb4c143868"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:58:14.233244Z","signature_b64":"4KdASlhJYZb3WVenaSvALSsfhtfp05hk+G6ONmrTIdfBYJQM+EMaAM7fb8wKiWhWx+dgbgfb/mmqbaIQd3izBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f9206197c1c43fe8f0bc4641ff6eb3b078a6862cb2329a523af0a6a22e393322","last_reissued_at":"2026-05-17T23:58:14.232738Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:58:14.232738Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Ahmed Salem, Mario Fritz, Mathias Humbert, Michael Backes, Pascal Berrang, Yang Zhang","submitted_at":"2018-06-04T17:38:42Z","abstract_excerpt":"Machine learning (ML) has become a core component of many real-world applications and training data is a key factor that drives current progress. This huge success has led Internet companies to deploy machine learning as a service (MLaaS). Recently, the first membership inference attack has shown that extraction of information on the training set is possible in such MLaaS settings, which has severe security and privacy implications.\n  However, the early demonstrations of the feasibility of such attacks have many assumptions on the adversary, such as using multiple so-called shadow models, know"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1806.01246","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1806.01246","created_at":"2026-05-17T23:58:14.232819+00:00"},{"alias_kind":"arxiv_version","alias_value":"1806.01246v2","created_at":"2026-05-17T23:58:14.232819+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1806.01246","created_at":"2026-05-17T23:58:14.232819+00:00"},{"alias_kind":"pith_short_12","alias_value":"7EQGDF6BYQ76","created_at":"2026-05-18T12:32:11.075285+00:00"},{"alias_kind":"pith_short_16","alias_value":"7EQGDF6BYQ76R4F4","created_at":"2026-05-18T12:32:11.075285+00:00"},{"alias_kind":"pith_short_8","alias_value":"7EQGDF6B","created_at":"2026-05-18T12:32:11.075285+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":19,"internal_anchor_count":13,"sample":[{"citing_arxiv_id":"2606.23030","citing_title":"Have You Ever Seen Them? Entity-level Membership Inference through Interrogating Large Language Models","ref_index":69,"is_internal_anchor":true},{"citing_arxiv_id":"2606.04384","citing_title":"Revisiting Privacy Amplification by Subsampling in Selective Release DPSGD","ref_index":33,"is_internal_anchor":true},{"citing_arxiv_id":"2606.04069","citing_title":"Bayesian Membership Privacy for Graph Neural Networks","ref_index":25,"is_internal_anchor":true},{"citing_arxiv_id":"2605.14686","citing_title":"ReMIA: a Powerful and Efficient Alternative to Membership Inference Attacks against Synthetic Data Generators","ref_index":40,"is_internal_anchor":true},{"citing_arxiv_id":"2605.01129","citing_title":"Revisiting Privacy Leakage in Machine Unlearning: Membership Inference Beyond the Forgotten Set","ref_index":18,"is_internal_anchor":true},{"citing_arxiv_id":"2605.27825","citing_title":"MRMMIA: Membership Inference Attacks on Memory in Chat Agents","ref_index":23,"is_internal_anchor":true},{"citing_arxiv_id":"2605.29454","citing_title":"A Full-Pipeline Framework for Evaluating Membership Inference Attacks in Machine Learning","ref_index":21,"is_internal_anchor":true},{"citing_arxiv_id":"2605.30462","citing_title":"idSCD: Identifying Training Datasets through Semantic Correlation Descriptors","ref_index":40,"is_internal_anchor":true},{"citing_arxiv_id":"2605.17341","citing_title":"Single-Sample Black-Box Membership Inference Attack against Vision-Language Models via Cross-modal Semantic Alignment","ref_index":48,"is_internal_anchor":true},{"citing_arxiv_id":"2508.11742","citing_title":"Cross-Flow Correlations Survive Synthesis: Measuring Source-Level Privacy Leakage in Synthetic Network Traces","ref_index":13,"is_internal_anchor":true},{"citing_arxiv_id":"2510.21783","citing_title":"Noise Aggregation Analysis Driven by Small-Noise Injection: Efficient Membership Inference for Diffusion Models","ref_index":11,"is_internal_anchor":true},{"citing_arxiv_id":"2602.22611","citing_title":"Mitigating Membership Inference in Intermediate Representations with Differentially Private Training","ref_index":10,"is_internal_anchor":true},{"citing_arxiv_id":"2605.12574","citing_title":"DistractMIA: Black-Box Membership Inference on Vision-Language Models via Semantic Distraction","ref_index":19,"is_internal_anchor":true},{"citing_arxiv_id":"2604.04030","citing_title":"Jellyfish: Zero-Shot Federated Unlearning Scheme with Knowledge Disentanglement","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2605.04901","citing_title":"On the (In-)Security of the Shuffling Defense in the Transformer Secure Inference","ref_index":89,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01129","citing_title":"Revisiting Privacy Leakage in Machine Unlearning: Membership Inference Beyond the Forgotten Set","ref_index":18,"is_internal_anchor":false},{"citing_arxiv_id":"2604.19653","citing_title":"A Dual Perspective on Synthetic Trajectory Generators: Utility Framework and Privacy Vulnerabilities","ref_index":106,"is_internal_anchor":false},{"citing_arxiv_id":"2604.04800","citing_title":"Forgetting to Witness: Efficient Federated Unlearning and Its Visible Evaluation","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2604.16536","citing_title":"Towards Reliable Testing of Machine Unlearning","ref_index":36,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/7EQGDF6BYQ76R4F4IZA763VTWB","json":"https://pith.science/pith/7EQGDF6BYQ76R4F4IZA763VTWB.json","graph_json":"https://pith.science/api/pith-number/7EQGDF6BYQ76R4F4IZA763VTWB/graph.json","events_json":"https://pith.science/api/pith-number/7EQGDF6BYQ76R4F4IZA763VTWB/events.json","paper":"https://pith.science/paper/7EQGDF6B"},"agent_actions":{"view_html":"https://pith.science/pith/7EQGDF6BYQ76R4F4IZA763VTWB","download_json":"https://pith.science/pith/7EQGDF6BYQ76R4F4IZA763VTWB.json","view_paper":"https://pith.science/paper/7EQGDF6B","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1806.01246&json=true","fetch_graph":"https://pith.science/api/pith-number/7EQGDF6BYQ76R4F4IZA763VTWB/graph.json","fetch_events":"https://pith.science/api/pith-number/7EQGDF6BYQ76R4F4IZA763VTWB/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/7EQGDF6BYQ76R4F4IZA763VTWB/action/timestamp_anchor","attest_storage":"https://pith.science/pith/7EQGDF6BYQ76R4F4IZA763VTWB/action/storage_attestation","attest_author":"https://pith.science/pith/7EQGDF6BYQ76R4F4IZA763VTWB/action/author_attestation","sign_citation":"https://pith.science/pith/7EQGDF6BYQ76R4F4IZA763VTWB/action/citation_signature","submit_replication":"https://pith.science/pith/7EQGDF6BYQ76R4F4IZA763VTWB/action/replication_record"}},"created_at":"2026-05-17T23:58:14.232819+00:00","updated_at":"2026-05-17T23:58:14.232819+00:00"}