{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:CJA6FM66UZQICZVR4Y6GL2DQV7","short_pith_number":"pith:CJA6FM66","schema_version":"1.0","canonical_sha256":"1241e2b3dea6608166b1e63c65e870afe2d133c482c76c4e723aaa66f283526e","source":{"kind":"arxiv","id":"2503.06808","version":1},"attestation_state":"computed","paper":{"title":"Privacy Auditing of Large Language Models","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Ashwinee Panda, Christopher A. Choquette-Choo, Milad Nasr, Prateek Mittal, Xinyu Tang","submitted_at":"2025-03-09T23:32:15Z","abstract_excerpt":"Current techniques for privacy auditing of large language models (LLMs) have limited efficacy -- they rely on basic approaches to generate canaries which leads to weak membership inference attacks that in turn give loose lower bounds on the empirical privacy leakage. We develop canaries that are far more effective than those used in prior work under threat models that cover a range of realistic settings. We demonstrate through extensive experiments on multiple families of fine-tuned LLMs that our approach sets a new standard for detection of privacy leakage. For measuring the memorization rate"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2503.06808","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-09T23:32:15Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"10ba89f470c560f28713ebdbb4cab7ac62b25083930be03bfdd339713756da3b","abstract_canon_sha256":"2b01247c91f74259546f02b5741762cd3830e662023e5e1567b4910a9871880d"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:27:42.958270Z","signature_b64":"i2SPS6qsHXWc4KMJmBhVJHSm0xdOGWi7smdufjUL/3TPWgBZtyW0IGWK2GMv/hAxmbB6+ob1ESBOXJJNVKvNCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1241e2b3dea6608166b1e63c65e870afe2d133c482c76c4e723aaa66f283526e","last_reissued_at":"2026-07-05T10:27:42.957489Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:27:42.957489Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Privacy Auditing of Large Language Models","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Ashwinee Panda, Christopher A. Choquette-Choo, Milad Nasr, Prateek Mittal, Xinyu Tang","submitted_at":"2025-03-09T23:32:15Z","abstract_excerpt":"Current techniques for privacy auditing of large language models (LLMs) have limited efficacy -- they rely on basic approaches to generate canaries which leads to weak membership inference attacks that in turn give loose lower bounds on the empirical privacy leakage. We develop canaries that are far more effective than those used in prior work under threat models that cover a range of realistic settings. We demonstrate through extensive experiments on multiple families of fine-tuned LLMs that our approach sets a new standard for detection of privacy leakage. For measuring the memorization rate"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.06808","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2503.06808/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2503.06808","created_at":"2026-07-05T10:27:42.957600+00:00"},{"alias_kind":"arxiv_version","alias_value":"2503.06808v1","created_at":"2026-07-05T10:27:42.957600+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.06808","created_at":"2026-07-05T10:27:42.957600+00:00"},{"alias_kind":"pith_short_12","alias_value":"CJA6FM66UZQI","created_at":"2026-07-05T10:27:42.957600+00:00"},{"alias_kind":"pith_short_16","alias_value":"CJA6FM66UZQICZVR","created_at":"2026-07-05T10:27:42.957600+00:00"},{"alias_kind":"pith_short_8","alias_value":"CJA6FM66","created_at":"2026-07-05T10:27:42.957600+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.26627","citing_title":"Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents","ref_index":87,"is_internal_anchor":false},{"citing_arxiv_id":"2606.10481","citing_title":"Advancing the State-of-the-Art in Empirical Privacy Auditing","ref_index":73,"is_internal_anchor":false},{"citing_arxiv_id":"2605.21816","citing_title":"Barriers to Evidence in AI-Related Cases and the Privatization of Proof","ref_index":43,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/CJA6FM66UZQICZVR4Y6GL2DQV7","json":"https://pith.science/pith/CJA6FM66UZQICZVR4Y6GL2DQV7.json","graph_json":"https://pith.science/api/pith-number/CJA6FM66UZQICZVR4Y6GL2DQV7/graph.json","events_json":"https://pith.science/api/pith-number/CJA6FM66UZQICZVR4Y6GL2DQV7/events.json","paper":"https://pith.science/paper/CJA6FM66"},"agent_actions":{"view_html":"https://pith.science/pith/CJA6FM66UZQICZVR4Y6GL2DQV7","download_json":"https://pith.science/pith/CJA6FM66UZQICZVR4Y6GL2DQV7.json","view_paper":"https://pith.science/paper/CJA6FM66","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2503.06808&json=true","fetch_graph":"https://pith.science/api/pith-number/CJA6FM66UZQICZVR4Y6GL2DQV7/graph.json","fetch_events":"https://pith.science/api/pith-number/CJA6FM66UZQICZVR4Y6GL2DQV7/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/CJA6FM66UZQICZVR4Y6GL2DQV7/action/timestamp_anchor","attest_storage":"https://pith.science/pith/CJA6FM66UZQICZVR4Y6GL2DQV7/action/storage_attestation","attest_author":"https://pith.science/pith/CJA6FM66UZQICZVR4Y6GL2DQV7/action/author_attestation","sign_citation":"https://pith.science/pith/CJA6FM66UZQICZVR4Y6GL2DQV7/action/citation_signature","submit_replication":"https://pith.science/pith/CJA6FM66UZQICZVR4Y6GL2DQV7/action/replication_record"}},"created_at":"2026-07-05T10:27:42.957600+00:00","updated_at":"2026-07-05T10:27:42.957600+00:00"}