{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:AZ7LVCJ2WWJTKYCOCGLALTNF6B","short_pith_number":"pith:AZ7LVCJ2","schema_version":"1.0","canonical_sha256":"067eba893ab59335604e119605cda5f04bacf67cf1943c05cf70d9de3016fc00","source":{"kind":"arxiv","id":"2310.12462","version":1},"attestation_state":"computed","paper":{"title":"Unmasking Transformers: A Theoretical Approach to Data Recovery via Attention Weights","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.CL","stat.ML"],"primary_cat":"cs.LG","authors_text":"Chiwun Yang, Shenghao Xie, Yichuan Deng, Zhao Song","submitted_at":"2023-10-19T04:41:01Z","abstract_excerpt":"In the realm of deep learning, transformers have emerged as a dominant architecture, particularly in natural language processing tasks. However, with their widespread adoption, concerns regarding the security and privacy of the data processed by these models have arisen. In this paper, we address a pivotal question: Can the data fed into transformers be recovered using their attention weights and outputs? We introduce a theoretical framework to tackle this problem. Specifically, we present an algorithm that aims to recover the input data $X \\in \\mathbb{R}^{d \\times n}$ from given attention wei"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2310.12462","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2023-10-19T04:41:01Z","cross_cats_sorted":["cs.CL","stat.ML"],"title_canon_sha256":"57f59174b0e0680d66a78b25637fbcd6e5ae166dcec42cd1cfc9eb9fe6e107fb","abstract_canon_sha256":"9d45eff85d4825b3b4032bb73d55b0444c46b13405ddd8238d7a0d3caf7827dd"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:02:38.439951Z","signature_b64":"rAv99Yx/yN9bviHMb5ZHyjNkHlSHx3okucjRXfpIkPJdVky3mbIMHqXNGxxpYUi/LP5gvIz7HuvsB2hgOiS3CA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"067eba893ab59335604e119605cda5f04bacf67cf1943c05cf70d9de3016fc00","last_reissued_at":"2026-07-05T07:02:38.439485Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:02:38.439485Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Unmasking Transformers: A Theoretical Approach to Data Recovery via Attention Weights","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.CL","stat.ML"],"primary_cat":"cs.LG","authors_text":"Chiwun Yang, Shenghao Xie, Yichuan Deng, Zhao Song","submitted_at":"2023-10-19T04:41:01Z","abstract_excerpt":"In the realm of deep learning, transformers have emerged as a dominant architecture, particularly in natural language processing tasks. However, with their widespread adoption, concerns regarding the security and privacy of the data processed by these models have arisen. In this paper, we address a pivotal question: Can the data fed into transformers be recovered using their attention weights and outputs? We introduce a theoretical framework to tackle this problem. Specifically, we present an algorithm that aims to recover the input data $X \\in \\mathbb{R}^{d \\times n}$ from given attention wei"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2310.12462","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2310.12462/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2310.12462","created_at":"2026-07-05T07:02:38.439548+00:00"},{"alias_kind":"arxiv_version","alias_value":"2310.12462v1","created_at":"2026-07-05T07:02:38.439548+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2310.12462","created_at":"2026-07-05T07:02:38.439548+00:00"},{"alias_kind":"pith_short_12","alias_value":"AZ7LVCJ2WWJT","created_at":"2026-07-05T07:02:38.439548+00:00"},{"alias_kind":"pith_short_16","alias_value":"AZ7LVCJ2WWJTKYCO","created_at":"2026-07-05T07:02:38.439548+00:00"},{"alias_kind":"pith_short_8","alias_value":"AZ7LVCJ2","created_at":"2026-07-05T07:02:38.439548+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2306.14048","citing_title":"H$_2$O: Heavy-Hitter Oracle for Efficient Generative Inference of Large Language Models","ref_index":116,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/AZ7LVCJ2WWJTKYCOCGLALTNF6B","json":"https://pith.science/pith/AZ7LVCJ2WWJTKYCOCGLALTNF6B.json","graph_json":"https://pith.science/api/pith-number/AZ7LVCJ2WWJTKYCOCGLALTNF6B/graph.json","events_json":"https://pith.science/api/pith-number/AZ7LVCJ2WWJTKYCOCGLALTNF6B/events.json","paper":"https://pith.science/paper/AZ7LVCJ2"},"agent_actions":{"view_html":"https://pith.science/pith/AZ7LVCJ2WWJTKYCOCGLALTNF6B","download_json":"https://pith.science/pith/AZ7LVCJ2WWJTKYCOCGLALTNF6B.json","view_paper":"https://pith.science/paper/AZ7LVCJ2","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2310.12462&json=true","fetch_graph":"https://pith.science/api/pith-number/AZ7LVCJ2WWJTKYCOCGLALTNF6B/graph.json","fetch_events":"https://pith.science/api/pith-number/AZ7LVCJ2WWJTKYCOCGLALTNF6B/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/AZ7LVCJ2WWJTKYCOCGLALTNF6B/action/timestamp_anchor","attest_storage":"https://pith.science/pith/AZ7LVCJ2WWJTKYCOCGLALTNF6B/action/storage_attestation","attest_author":"https://pith.science/pith/AZ7LVCJ2WWJTKYCOCGLALTNF6B/action/author_attestation","sign_citation":"https://pith.science/pith/AZ7LVCJ2WWJTKYCOCGLALTNF6B/action/citation_signature","submit_replication":"https://pith.science/pith/AZ7LVCJ2WWJTKYCOCGLALTNF6B/action/replication_record"}},"created_at":"2026-07-05T07:02:38.439548+00:00","updated_at":"2026-07-05T07:02:38.439548+00:00"}