{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2023:DPZ6ZE6PPP4RUVE6KXWDRO7GLE","short_pith_number":"pith:DPZ6ZE6P","canonical_record":{"source":{"id":"2308.06822","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2023-08-13T17:40:56Z","cross_cats_sorted":["cs.AI","cs.CR","math.OC"],"title_canon_sha256":"073ef82c14d359328d0385288817ecd41bb08e1a427feed2fed9cb5f6e6cecce","abstract_canon_sha256":"ab0acd3340e5e7f546810a55a6d753a3e657939913e63b26c75fc306c3fa8c5b"},"schema_version":"1.0"},"canonical_sha256":"1bf3ec93cf7bf91a549e55ec38bbe65937c376ea15ca020a965640f909ac1d45","source":{"kind":"arxiv","id":"2308.06822","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2308.06822","created_at":"2026-05-20T00:01:31Z"},{"alias_kind":"arxiv_version","alias_value":"2308.06822v3","created_at":"2026-05-20T00:01:31Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2308.06822","created_at":"2026-05-20T00:01:31Z"},{"alias_kind":"pith_short_12","alias_value":"DPZ6ZE6PPP4R","created_at":"2026-05-20T00:01:31Z"},{"alias_kind":"pith_short_16","alias_value":"DPZ6ZE6PPP4RUVE6","created_at":"2026-05-20T00:01:31Z"},{"alias_kind":"pith_short_8","alias_value":"DPZ6ZE6P","created_at":"2026-05-20T00:01:31Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2023:DPZ6ZE6PPP4RUVE6KXWDRO7GLE","target":"record","payload":{"canonical_record":{"source":{"id":"2308.06822","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2023-08-13T17:40:56Z","cross_cats_sorted":["cs.AI","cs.CR","math.OC"],"title_canon_sha256":"073ef82c14d359328d0385288817ecd41bb08e1a427feed2fed9cb5f6e6cecce","abstract_canon_sha256":"ab0acd3340e5e7f546810a55a6d753a3e657939913e63b26c75fc306c3fa8c5b"},"schema_version":"1.0"},"canonical_sha256":"1bf3ec93cf7bf91a549e55ec38bbe65937c376ea15ca020a965640f909ac1d45","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-20T00:01:31.909262Z","signature_b64":"C4KO5AYXt+i8lAlveEuTVoiVjxUSDmq0pW3i9VktzufYL4yZWbjIFtyKjxufSfVR3eq3t0S3VOyxsceamQpEAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1bf3ec93cf7bf91a549e55ec38bbe65937c376ea15ca020a965640f909ac1d45","last_reissued_at":"2026-05-20T00:01:31.908552Z","signature_status":"signed_v1","first_computed_at":"2026-05-20T00:01:31.908552Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2308.06822","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:01:31Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"a1bBIdOH9QPw7mEdK4m5elNELpRaDo4DGAYn9aEUk4MtGVqs25At1eRypVlwOeg5UM8TMgM5Z1UI0DfiaSfhDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T16:37:39.616992Z"},"content_sha256":"9a4767e0592ea858d8d1c86d26267c74dd50d9c3f9905a58bd76ff134a19ac88","schema_version":"1.0","event_id":"sha256:9a4767e0592ea858d8d1c86d26267c74dd50d9c3f9905a58bd76ff134a19ac88"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2023:DPZ6ZE6PPP4RUVE6KXWDRO7GLE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Approximate and Weighted Data Reconstruction Attack in Federated Learning","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CR","math.OC"],"primary_cat":"cs.LG","authors_text":"Enrique Zuazua, Yongcun Song, Ziqi Wang","submitted_at":"2023-08-13T17:40:56Z","abstract_excerpt":"Federated Learning (FL) is a distributed learning paradigm that enables multiple clients to collaborate on building a machine learning model without sharing their private data. Although FL is considered privacy-preserved by design, recent data reconstruction attacks demonstrate that an attacker can recover clients' training data based on the parameters shared in FL. However, most existing methods fail to attack the most widely used horizontal Federated Averaging (FedAvg) scenario, where clients share model parameters after multiple local training steps. To tackle this issue, we propose an inte"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2308.06822","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2308.06822/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:01:31Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"y4unRO8UG9rAzUum+uGnxFcIHIf+5MrjREh0gm99Ps2FkEFNpPwSW6o1jTBy1Tn36LKkNsMxlbWleZuMWSc5Bw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T16:37:39.617549Z"},"content_sha256":"93142f95c7f7e09542283e4dbc32bc45d27188b13cf21fa1baaa447976e7c3c8","schema_version":"1.0","event_id":"sha256:93142f95c7f7e09542283e4dbc32bc45d27188b13cf21fa1baaa447976e7c3c8"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/DPZ6ZE6PPP4RUVE6KXWDRO7GLE/bundle.json","state_url":"https://pith.science/pith/DPZ6ZE6PPP4RUVE6KXWDRO7GLE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/DPZ6ZE6PPP4RUVE6KXWDRO7GLE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T16:37:39Z","links":{"resolver":"https://pith.science/pith/DPZ6ZE6PPP4RUVE6KXWDRO7GLE","bundle":"https://pith.science/pith/DPZ6ZE6PPP4RUVE6KXWDRO7GLE/bundle.json","state":"https://pith.science/pith/DPZ6ZE6PPP4RUVE6KXWDRO7GLE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/DPZ6ZE6PPP4RUVE6KXWDRO7GLE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2023:DPZ6ZE6PPP4RUVE6KXWDRO7GLE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ab0acd3340e5e7f546810a55a6d753a3e657939913e63b26c75fc306c3fa8c5b","cross_cats_sorted":["cs.AI","cs.CR","math.OC"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2023-08-13T17:40:56Z","title_canon_sha256":"073ef82c14d359328d0385288817ecd41bb08e1a427feed2fed9cb5f6e6cecce"},"schema_version":"1.0","source":{"id":"2308.06822","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2308.06822","created_at":"2026-05-20T00:01:31Z"},{"alias_kind":"arxiv_version","alias_value":"2308.06822v3","created_at":"2026-05-20T00:01:31Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2308.06822","created_at":"2026-05-20T00:01:31Z"},{"alias_kind":"pith_short_12","alias_value":"DPZ6ZE6PPP4R","created_at":"2026-05-20T00:01:31Z"},{"alias_kind":"pith_short_16","alias_value":"DPZ6ZE6PPP4RUVE6","created_at":"2026-05-20T00:01:31Z"},{"alias_kind":"pith_short_8","alias_value":"DPZ6ZE6P","created_at":"2026-05-20T00:01:31Z"}],"graph_snapshots":[{"event_id":"sha256:93142f95c7f7e09542283e4dbc32bc45d27188b13cf21fa1baaa447976e7c3c8","target":"graph","created_at":"2026-05-20T00:01:31Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2308.06822/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Federated Learning (FL) is a distributed learning paradigm that enables multiple clients to collaborate on building a machine learning model without sharing their private data. Although FL is considered privacy-preserved by design, recent data reconstruction attacks demonstrate that an attacker can recover clients' training data based on the parameters shared in FL. However, most existing methods fail to attack the most widely used horizontal Federated Averaging (FedAvg) scenario, where clients share model parameters after multiple local training steps. To tackle this issue, we propose an inte","authors_text":"Enrique Zuazua, Yongcun Song, Ziqi Wang","cross_cats":["cs.AI","cs.CR","math.OC"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2023-08-13T17:40:56Z","title":"Approximate and Weighted Data Reconstruction Attack in Federated Learning"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2308.06822","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:9a4767e0592ea858d8d1c86d26267c74dd50d9c3f9905a58bd76ff134a19ac88","target":"record","created_at":"2026-05-20T00:01:31Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ab0acd3340e5e7f546810a55a6d753a3e657939913e63b26c75fc306c3fa8c5b","cross_cats_sorted":["cs.AI","cs.CR","math.OC"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2023-08-13T17:40:56Z","title_canon_sha256":"073ef82c14d359328d0385288817ecd41bb08e1a427feed2fed9cb5f6e6cecce"},"schema_version":"1.0","source":{"id":"2308.06822","kind":"arxiv","version":3}},"canonical_sha256":"1bf3ec93cf7bf91a549e55ec38bbe65937c376ea15ca020a965640f909ac1d45","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"1bf3ec93cf7bf91a549e55ec38bbe65937c376ea15ca020a965640f909ac1d45","first_computed_at":"2026-05-20T00:01:31.908552Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:01:31.908552Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"C4KO5AYXt+i8lAlveEuTVoiVjxUSDmq0pW3i9VktzufYL4yZWbjIFtyKjxufSfVR3eq3t0S3VOyxsceamQpEAQ==","signature_status":"signed_v1","signed_at":"2026-05-20T00:01:31.909262Z","signed_message":"canonical_sha256_bytes"},"source_id":"2308.06822","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:9a4767e0592ea858d8d1c86d26267c74dd50d9c3f9905a58bd76ff134a19ac88","sha256:93142f95c7f7e09542283e4dbc32bc45d27188b13cf21fa1baaa447976e7c3c8"],"state_sha256":"f03dcecea50920a14c677dc3ee7566bff65d00da92fff9fd15dd6716634ac88b"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"s/eWOp9rFVzINRU5LYWo+AS2AEwbMjJHxS0ElgGws0DK+3ERt+4FDUSRJzr8PDyJvf7HI/R865LyC38FKhQWAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T16:37:39.620812Z","bundle_sha256":"d048c63dd5882219ae4daec01eac5f490f0a0ca6b37b956d05910b719e56fc67"}}