{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:BD4K44KACINW7NAOFZE27OHCL7","short_pith_number":"pith:BD4K44KA","schema_version":"1.0","canonical_sha256":"08f8ae7140121b6fb40e2e49afb8e25fd3fdede5d2786bdcea9aa79d0de8a89d","source":{"kind":"arxiv","id":"2005.03915","version":2},"attestation_state":"computed","paper":{"title":"Defending Model Inversion and Membership Inference Attacks via Prediction Purification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Bin Shao, Bohan Xuan, Ee-Chien Chang, Fan Zhang, Ziqi Yang","submitted_at":"2020-05-08T09:07:38Z","abstract_excerpt":"Neural networks are susceptible to data inference attacks such as the model inversion attack and the membership inference attack, where the attacker could infer the reconstruction and the membership of a data sample from the confidence scores predicted by the target classifier. In this paper, we propose a unified approach, namely purification framework, to defend data inference attacks. It purifies the confidence score vectors predicted by the target classifier by reducing their dispersion. The purifier can be further specialized in defending a particular attack via adversarial learning. We ev"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2005.03915","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-05-08T09:07:38Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"35c2f4584a4f225cc3554de306860c802304e8a6938e4410070f7d40d23b6225","abstract_canon_sha256":"1470b3a20bb15c81ec20e4fc2ed2fd19a3503da3ecbd70c793b9e8af7674fe1a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T01:28:30.419273Z","signature_b64":"h8GcbT1G9n02QpZePUhiF40VvBKb+M4CcIk9tOYrujiVsQthJ/rfr6Yuzre1LfVUJJDE+4IGIW34GKIWhmTwBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"08f8ae7140121b6fb40e2e49afb8e25fd3fdede5d2786bdcea9aa79d0de8a89d","last_reissued_at":"2026-07-05T01:28:30.418801Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T01:28:30.418801Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Defending Model Inversion and Membership Inference Attacks via Prediction Purification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Bin Shao, Bohan Xuan, Ee-Chien Chang, Fan Zhang, Ziqi Yang","submitted_at":"2020-05-08T09:07:38Z","abstract_excerpt":"Neural networks are susceptible to data inference attacks such as the model inversion attack and the membership inference attack, where the attacker could infer the reconstruction and the membership of a data sample from the confidence scores predicted by the target classifier. In this paper, we propose a unified approach, namely purification framework, to defend data inference attacks. It purifies the confidence score vectors predicted by the target classifier by reducing their dispersion. The purifier can be further specialized in defending a particular attack via adversarial learning. We ev"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2005.03915","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2005.03915/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2005.03915","created_at":"2026-07-05T01:28:30.418859+00:00"},{"alias_kind":"arxiv_version","alias_value":"2005.03915v2","created_at":"2026-07-05T01:28:30.418859+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2005.03915","created_at":"2026-07-05T01:28:30.418859+00:00"},{"alias_kind":"pith_short_12","alias_value":"BD4K44KACINW","created_at":"2026-07-05T01:28:30.418859+00:00"},{"alias_kind":"pith_short_16","alias_value":"BD4K44KACINW7NAO","created_at":"2026-07-05T01:28:30.418859+00:00"},{"alias_kind":"pith_short_8","alias_value":"BD4K44KA","created_at":"2026-07-05T01:28:30.418859+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/BD4K44KACINW7NAOFZE27OHCL7","json":"https://pith.science/pith/BD4K44KACINW7NAOFZE27OHCL7.json","graph_json":"https://pith.science/api/pith-number/BD4K44KACINW7NAOFZE27OHCL7/graph.json","events_json":"https://pith.science/api/pith-number/BD4K44KACINW7NAOFZE27OHCL7/events.json","paper":"https://pith.science/paper/BD4K44KA"},"agent_actions":{"view_html":"https://pith.science/pith/BD4K44KACINW7NAOFZE27OHCL7","download_json":"https://pith.science/pith/BD4K44KACINW7NAOFZE27OHCL7.json","view_paper":"https://pith.science/paper/BD4K44KA","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2005.03915&json=true","fetch_graph":"https://pith.science/api/pith-number/BD4K44KACINW7NAOFZE27OHCL7/graph.json","fetch_events":"https://pith.science/api/pith-number/BD4K44KACINW7NAOFZE27OHCL7/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/BD4K44KACINW7NAOFZE27OHCL7/action/timestamp_anchor","attest_storage":"https://pith.science/pith/BD4K44KACINW7NAOFZE27OHCL7/action/storage_attestation","attest_author":"https://pith.science/pith/BD4K44KACINW7NAOFZE27OHCL7/action/author_attestation","sign_citation":"https://pith.science/pith/BD4K44KACINW7NAOFZE27OHCL7/action/citation_signature","submit_replication":"https://pith.science/pith/BD4K44KACINW7NAOFZE27OHCL7/action/replication_record"}},"created_at":"2026-07-05T01:28:30.418859+00:00","updated_at":"2026-07-05T01:28:30.418859+00:00"}