{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:COPHPMY5HY43GVCBPACBNQV625","short_pith_number":"pith:COPHPMY5","canonical_record":{"source":{"id":"2605.30470","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-28T18:41:20Z","cross_cats_sorted":[],"title_canon_sha256":"a21c029a72a14bca7e488e9f50e73fbf859dd1f97f4c79ef5eedc4dbbd50ad79","abstract_canon_sha256":"2e2ff59abbee22a067b93bc36f4b777c7d915bd03c6f7072f7f7a9d23d16aec9"},"schema_version":"1.0"},"canonical_sha256":"139e77b31d3e39b35441780416c2bed764c8a51aae8cd686c1e541adf951f374","source":{"kind":"arxiv","id":"2605.30470","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.30470","created_at":"2026-06-01T01:02:56Z"},{"alias_kind":"arxiv_version","alias_value":"2605.30470v1","created_at":"2026-06-01T01:02:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.30470","created_at":"2026-06-01T01:02:56Z"},{"alias_kind":"pith_short_12","alias_value":"COPHPMY5HY43","created_at":"2026-06-01T01:02:56Z"},{"alias_kind":"pith_short_16","alias_value":"COPHPMY5HY43GVCB","created_at":"2026-06-01T01:02:56Z"},{"alias_kind":"pith_short_8","alias_value":"COPHPMY5","created_at":"2026-06-01T01:02:56Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:COPHPMY5HY43GVCBPACBNQV625","target":"record","payload":{"canonical_record":{"source":{"id":"2605.30470","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-28T18:41:20Z","cross_cats_sorted":[],"title_canon_sha256":"a21c029a72a14bca7e488e9f50e73fbf859dd1f97f4c79ef5eedc4dbbd50ad79","abstract_canon_sha256":"2e2ff59abbee22a067b93bc36f4b777c7d915bd03c6f7072f7f7a9d23d16aec9"},"schema_version":"1.0"},"canonical_sha256":"139e77b31d3e39b35441780416c2bed764c8a51aae8cd686c1e541adf951f374","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-01T01:02:56.009779Z","signature_b64":"qyntq+wk2HOyCMi+O81/blqsEGyd9T+Z3O85NpUc3Gw8iwZiVgOWTeUgVwsgeohFQ72ZGGBndavP2BNo9nDICQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"139e77b31d3e39b35441780416c2bed764c8a51aae8cd686c1e541adf951f374","last_reissued_at":"2026-06-01T01:02:56.008822Z","signature_status":"signed_v1","first_computed_at":"2026-06-01T01:02:56.008822Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.30470","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-01T01:02:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"phF+5eGsBj5vldZU0BEe8zQ3EoEpYSTznv7hj9GZP8re/QjV+BHoX+/tGJPA9P2idLkMnASvQroi4X/HYOTiBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T08:09:57.104202Z"},"content_sha256":"b3af53a46578e99b2f7705cf1b1bf39dc5d72f0227bb17767a95eb7681843e21","schema_version":"1.0","event_id":"sha256:b3af53a46578e99b2f7705cf1b1bf39dc5d72f0227bb17767a95eb7681843e21"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:COPHPMY5HY43GVCBPACBNQV625","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Can Subgraph Explanations Be Weaponized to Steal Graph Neural Networks?","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Jiate Li, Ojas Nimase, Yue Zhao, Yushun Dong","submitted_at":"2026-05-28T18:41:20Z","abstract_excerpt":"Graph Machine Learning as a Service (GMLaaS) platforms increasingly implement explainability interfaces to meet regulatory transparency requirements. However, this transparency creates exploitable vulnerabilities for model extraction attacks. We present the first model extraction attack specifically designed for graph classification under strict black-box constraints where the attacker observes only discrete class labels and binary explanation masks (no probability scores, gradients, or confidence values). Our method (1) uses model explanation outputs to guide Monte Carlo edge sensitivity esti"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.30470","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.30470/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-01T01:02:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"uwOVzUgt9QJvxOdJvGHcrZVKLlcGol1+HhZqx2GNB4zmWorx/JqzL+d5t5eUq/+Yy1xrebmp0Z6mujjb0rEICg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T08:09:57.104997Z"},"content_sha256":"7c40537c8857bb161f92660c096fdd9f9dd9cea6b465372b1f9a546df12ddf75","schema_version":"1.0","event_id":"sha256:7c40537c8857bb161f92660c096fdd9f9dd9cea6b465372b1f9a546df12ddf75"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/COPHPMY5HY43GVCBPACBNQV625/bundle.json","state_url":"https://pith.science/pith/COPHPMY5HY43GVCBPACBNQV625/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/COPHPMY5HY43GVCBPACBNQV625/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-06T08:09:57Z","links":{"resolver":"https://pith.science/pith/COPHPMY5HY43GVCBPACBNQV625","bundle":"https://pith.science/pith/COPHPMY5HY43GVCBPACBNQV625/bundle.json","state":"https://pith.science/pith/COPHPMY5HY43GVCBPACBNQV625/state.json","well_known_bundle":"https://pith.science/.well-known/pith/COPHPMY5HY43GVCBPACBNQV625/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:COPHPMY5HY43GVCBPACBNQV625","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"2e2ff59abbee22a067b93bc36f4b777c7d915bd03c6f7072f7f7a9d23d16aec9","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-28T18:41:20Z","title_canon_sha256":"a21c029a72a14bca7e488e9f50e73fbf859dd1f97f4c79ef5eedc4dbbd50ad79"},"schema_version":"1.0","source":{"id":"2605.30470","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.30470","created_at":"2026-06-01T01:02:56Z"},{"alias_kind":"arxiv_version","alias_value":"2605.30470v1","created_at":"2026-06-01T01:02:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.30470","created_at":"2026-06-01T01:02:56Z"},{"alias_kind":"pith_short_12","alias_value":"COPHPMY5HY43","created_at":"2026-06-01T01:02:56Z"},{"alias_kind":"pith_short_16","alias_value":"COPHPMY5HY43GVCB","created_at":"2026-06-01T01:02:56Z"},{"alias_kind":"pith_short_8","alias_value":"COPHPMY5","created_at":"2026-06-01T01:02:56Z"}],"graph_snapshots":[{"event_id":"sha256:7c40537c8857bb161f92660c096fdd9f9dd9cea6b465372b1f9a546df12ddf75","target":"graph","created_at":"2026-06-01T01:02:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.30470/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Graph Machine Learning as a Service (GMLaaS) platforms increasingly implement explainability interfaces to meet regulatory transparency requirements. However, this transparency creates exploitable vulnerabilities for model extraction attacks. We present the first model extraction attack specifically designed for graph classification under strict black-box constraints where the attacker observes only discrete class labels and binary explanation masks (no probability scores, gradients, or confidence values). Our method (1) uses model explanation outputs to guide Monte Carlo edge sensitivity esti","authors_text":"Jiate Li, Ojas Nimase, Yue Zhao, Yushun Dong","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-28T18:41:20Z","title":"Can Subgraph Explanations Be Weaponized to Steal Graph Neural Networks?"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.30470","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:b3af53a46578e99b2f7705cf1b1bf39dc5d72f0227bb17767a95eb7681843e21","target":"record","created_at":"2026-06-01T01:02:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"2e2ff59abbee22a067b93bc36f4b777c7d915bd03c6f7072f7f7a9d23d16aec9","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-28T18:41:20Z","title_canon_sha256":"a21c029a72a14bca7e488e9f50e73fbf859dd1f97f4c79ef5eedc4dbbd50ad79"},"schema_version":"1.0","source":{"id":"2605.30470","kind":"arxiv","version":1}},"canonical_sha256":"139e77b31d3e39b35441780416c2bed764c8a51aae8cd686c1e541adf951f374","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"139e77b31d3e39b35441780416c2bed764c8a51aae8cd686c1e541adf951f374","first_computed_at":"2026-06-01T01:02:56.008822Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-01T01:02:56.008822Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"qyntq+wk2HOyCMi+O81/blqsEGyd9T+Z3O85NpUc3Gw8iwZiVgOWTeUgVwsgeohFQ72ZGGBndavP2BNo9nDICQ==","signature_status":"signed_v1","signed_at":"2026-06-01T01:02:56.009779Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.30470","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:b3af53a46578e99b2f7705cf1b1bf39dc5d72f0227bb17767a95eb7681843e21","sha256:7c40537c8857bb161f92660c096fdd9f9dd9cea6b465372b1f9a546df12ddf75"],"state_sha256":"ee32902020c9f74379a5e4750c5bb76c258c0140dba4486103aca0cc960078cc"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/e07L/fSwEI+FjgMwE7lZDlLmlidWxtcC373M0vCO4MDv2eF13fmhxKy7Qq1xYKN3wrI+KHMaquFiOVzEKMUAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-06T08:09:57.109832Z","bundle_sha256":"744f531fd68649169b5c48406547963b3423c7b89ab7ea953b8983357eadfcc6"}}