{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:CJFL2NQ5LRWLIXYJKNLG3X6OTT","short_pith_number":"pith:CJFL2NQ5","schema_version":"1.0","canonical_sha256":"124abd361d5c6cb45f0953566ddfce9ccd08fa1a62e4b4adc57cfbcd097a4380","source":{"kind":"arxiv","id":"2502.09974","version":1},"attestation_state":"computed","paper":{"title":"Has My System Prompt Been Used? Large Language Model Prompt Membership Inference","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.AI","authors_text":"Abhimanyu Hans, Avi Schwarzschild, Roman Levin, Tom Goldstein, Valeriia Cherepanova","submitted_at":"2025-02-14T08:00:42Z","abstract_excerpt":"Prompt engineering has emerged as a powerful technique for optimizing large language models (LLMs) for specific applications, enabling faster prototyping and improved performance, and giving rise to the interest of the community in protecting proprietary system prompts. In this work, we explore a novel perspective on prompt privacy through the lens of membership inference. We develop Prompt Detective, a statistical method to reliably determine whether a given system prompt was used by a third-party language model. Our approach relies on a statistical test comparing the distributions of two gro"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2502.09974","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2025-02-14T08:00:42Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"dbb55307cef7db02a6239ff80f2f328a6d8ce09023ac0d19d28da84136e0d8b2","abstract_canon_sha256":"14f84e2852732fadf96e116210cbb6f19849794046f6685039bfe2600fba7ca4"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:14:15.473649Z","signature_b64":"CErXBjP2yrblJpuEGctvtGpMZslUFI2PbMqJE2SKleTnKW8vgr4DPUySLzw2i57DTp5pAmEKIWRrQa8ZXNLfAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"124abd361d5c6cb45f0953566ddfce9ccd08fa1a62e4b4adc57cfbcd097a4380","last_reissued_at":"2026-07-05T10:14:15.473244Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:14:15.473244Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Has My System Prompt Been Used? Large Language Model Prompt Membership Inference","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.AI","authors_text":"Abhimanyu Hans, Avi Schwarzschild, Roman Levin, Tom Goldstein, Valeriia Cherepanova","submitted_at":"2025-02-14T08:00:42Z","abstract_excerpt":"Prompt engineering has emerged as a powerful technique for optimizing large language models (LLMs) for specific applications, enabling faster prototyping and improved performance, and giving rise to the interest of the community in protecting proprietary system prompts. In this work, we explore a novel perspective on prompt privacy through the lens of membership inference. We develop Prompt Detective, a statistical method to reliably determine whether a given system prompt was used by a third-party language model. Our approach relies on a statistical test comparing the distributions of two gro"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2502.09974","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2502.09974/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2502.09974","created_at":"2026-07-05T10:14:15.473301+00:00"},{"alias_kind":"arxiv_version","alias_value":"2502.09974v1","created_at":"2026-07-05T10:14:15.473301+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2502.09974","created_at":"2026-07-05T10:14:15.473301+00:00"},{"alias_kind":"pith_short_12","alias_value":"CJFL2NQ5LRWL","created_at":"2026-07-05T10:14:15.473301+00:00"},{"alias_kind":"pith_short_16","alias_value":"CJFL2NQ5LRWLIXYJ","created_at":"2026-07-05T10:14:15.473301+00:00"},{"alias_kind":"pith_short_8","alias_value":"CJFL2NQ5","created_at":"2026-07-05T10:14:15.473301+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.07539","citing_title":"Prompt Governance? On Governing Technologies Governed by Natural Language","ref_index":185,"is_internal_anchor":false},{"citing_arxiv_id":"2605.10794","citing_title":"Can You Keep a Secret? Involuntary Information Leakage in Language Model Writing","ref_index":6,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/CJFL2NQ5LRWLIXYJKNLG3X6OTT","json":"https://pith.science/pith/CJFL2NQ5LRWLIXYJKNLG3X6OTT.json","graph_json":"https://pith.science/api/pith-number/CJFL2NQ5LRWLIXYJKNLG3X6OTT/graph.json","events_json":"https://pith.science/api/pith-number/CJFL2NQ5LRWLIXYJKNLG3X6OTT/events.json","paper":"https://pith.science/paper/CJFL2NQ5"},"agent_actions":{"view_html":"https://pith.science/pith/CJFL2NQ5LRWLIXYJKNLG3X6OTT","download_json":"https://pith.science/pith/CJFL2NQ5LRWLIXYJKNLG3X6OTT.json","view_paper":"https://pith.science/paper/CJFL2NQ5","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2502.09974&json=true","fetch_graph":"https://pith.science/api/pith-number/CJFL2NQ5LRWLIXYJKNLG3X6OTT/graph.json","fetch_events":"https://pith.science/api/pith-number/CJFL2NQ5LRWLIXYJKNLG3X6OTT/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/CJFL2NQ5LRWLIXYJKNLG3X6OTT/action/timestamp_anchor","attest_storage":"https://pith.science/pith/CJFL2NQ5LRWLIXYJKNLG3X6OTT/action/storage_attestation","attest_author":"https://pith.science/pith/CJFL2NQ5LRWLIXYJKNLG3X6OTT/action/author_attestation","sign_citation":"https://pith.science/pith/CJFL2NQ5LRWLIXYJKNLG3X6OTT/action/citation_signature","submit_replication":"https://pith.science/pith/CJFL2NQ5LRWLIXYJKNLG3X6OTT/action/replication_record"}},"created_at":"2026-07-05T10:14:15.473301+00:00","updated_at":"2026-07-05T10:14:15.473301+00:00"}