{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:DTFV3CZYNNVWSWOCI76GGMPW7T","short_pith_number":"pith:DTFV3CZY","schema_version":"1.0","canonical_sha256":"1ccb5d8b386b6b6959c247fc6331f6fcf2699031f3dc7468ae48d05c8064e799","source":{"kind":"arxiv","id":"1912.07721","version":1},"attestation_state":"computed","paper":{"title":"Adversarial Model Extraction on Graph Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Arti Ramesh, David DeFazio","submitted_at":"2019-12-16T21:54:21Z","abstract_excerpt":"Along with the advent of deep neural networks came various methods of exploitation, such as fooling the classifier or contaminating its training data. Another such attack is known as model extraction, where provided API access to some black box neural network, the adversary extracts the underlying model. This is done by querying the model in such a way that the underlying neural network provides enough information to the adversary to be reconstructed. While several works have achieved impressive results with neural network extraction in the propositional domain, this problem has not yet been c"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1912.07721","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2019-12-16T21:54:21Z","cross_cats_sorted":["stat.ML"],"title_canon_sha256":"5f59519cacc7a2351d528406d822bb5d7e5a9ec8b377c0e3a85e965bece67c1a","abstract_canon_sha256":"4fec123bb51125651c919df377c030e9e78d39f0675c5378c74c886a1f47bab5"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:26:25.473249Z","signature_b64":"dzGaPGVHx9uCu67qEAYc8NZFNzEtNsjSTL+pAuRTmDu4jqWRpt8bcdcApS7/ucc2wlIJXKvVonUyuZvoVVWcCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1ccb5d8b386b6b6959c247fc6331f6fcf2699031f3dc7468ae48d05c8064e799","last_reissued_at":"2026-07-05T00:26:25.472836Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:26:25.472836Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Adversarial Model Extraction on Graph Neural Networks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["stat.ML"],"primary_cat":"cs.LG","authors_text":"Arti Ramesh, David DeFazio","submitted_at":"2019-12-16T21:54:21Z","abstract_excerpt":"Along with the advent of deep neural networks came various methods of exploitation, such as fooling the classifier or contaminating its training data. Another such attack is known as model extraction, where provided API access to some black box neural network, the adversary extracts the underlying model. This is done by querying the model in such a way that the underlying neural network provides enough information to the adversary to be reconstructed. While several works have achieved impressive results with neural network extraction in the propositional domain, this problem has not yet been c"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1912.07721","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1912.07721/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1912.07721","created_at":"2026-07-05T00:26:25.472889+00:00"},{"alias_kind":"arxiv_version","alias_value":"1912.07721v1","created_at":"2026-07-05T00:26:25.472889+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1912.07721","created_at":"2026-07-05T00:26:25.472889+00:00"},{"alias_kind":"pith_short_12","alias_value":"DTFV3CZYNNVW","created_at":"2026-07-05T00:26:25.472889+00:00"},{"alias_kind":"pith_short_16","alias_value":"DTFV3CZYNNVWSWOC","created_at":"2026-07-05T00:26:25.472889+00:00"},{"alias_kind":"pith_short_8","alias_value":"DTFV3CZY","created_at":"2026-07-05T00:26:25.472889+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.12827","citing_title":"GraphIP-Bench: How Hard Is It to Steal a Graph Neural Network, and Can We Stop It?","ref_index":3,"is_internal_anchor":false},{"citing_arxiv_id":"2605.12827","citing_title":"GraphIP-Bench: How Hard Is It to Steal a Graph Neural Network, and Can We Stop It?","ref_index":3,"is_internal_anchor":false},{"citing_arxiv_id":"2605.05360","citing_title":"COPYCOP: Ownership Verification for Graph Neural Networks","ref_index":11,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/DTFV3CZYNNVWSWOCI76GGMPW7T","json":"https://pith.science/pith/DTFV3CZYNNVWSWOCI76GGMPW7T.json","graph_json":"https://pith.science/api/pith-number/DTFV3CZYNNVWSWOCI76GGMPW7T/graph.json","events_json":"https://pith.science/api/pith-number/DTFV3CZYNNVWSWOCI76GGMPW7T/events.json","paper":"https://pith.science/paper/DTFV3CZY"},"agent_actions":{"view_html":"https://pith.science/pith/DTFV3CZYNNVWSWOCI76GGMPW7T","download_json":"https://pith.science/pith/DTFV3CZYNNVWSWOCI76GGMPW7T.json","view_paper":"https://pith.science/paper/DTFV3CZY","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1912.07721&json=true","fetch_graph":"https://pith.science/api/pith-number/DTFV3CZYNNVWSWOCI76GGMPW7T/graph.json","fetch_events":"https://pith.science/api/pith-number/DTFV3CZYNNVWSWOCI76GGMPW7T/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/DTFV3CZYNNVWSWOCI76GGMPW7T/action/timestamp_anchor","attest_storage":"https://pith.science/pith/DTFV3CZYNNVWSWOCI76GGMPW7T/action/storage_attestation","attest_author":"https://pith.science/pith/DTFV3CZYNNVWSWOCI76GGMPW7T/action/author_attestation","sign_citation":"https://pith.science/pith/DTFV3CZYNNVWSWOCI76GGMPW7T/action/citation_signature","submit_replication":"https://pith.science/pith/DTFV3CZYNNVWSWOCI76GGMPW7T/action/replication_record"}},"created_at":"2026-07-05T00:26:25.472889+00:00","updated_at":"2026-07-05T00:26:25.472889+00:00"}