{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:E3JCUALXUZ7ZQLOXL6JW6OLNL2","short_pith_number":"pith:E3JCUALX","schema_version":"1.0","canonical_sha256":"26d22a0177a67f982dd75f936f396d5eb8ccb3e43b0eb644d1a265d7d8221bc7","source":{"kind":"arxiv","id":"2603.07466","version":2},"attestation_state":"computed","paper":{"title":"Trusting What You Cannot See: Auditable Fine-Tuning and Inference for Proprietary AI","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Chaoyu Zhang, Heng Jin, Hexuan Yu, Ning Zhang, Shanghao Shi, Wenjing Lou, Y. Thomas Hou","submitted_at":"2026-03-08T05:06:45Z","abstract_excerpt":"Cloud-based infrastructure has become the dominant platform for deploying large models, particularly large language models (LLMs). Fine-tuning and inference are increasingly delegated to cloud providers for simplified deployment and access to proprietary models, yet this creates a fundamental trust gap. Although cryptographic and TEE-based verification approaches exist, prohibitive proving costs and limited TEE memory prevent them from scaling to modern LLMs, leaving clients unable to practically audit these processes. This lack of transparency creates concrete security risks that can silently"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2603.07466","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-03-08T05:06:45Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"24aa0c92fd989e5b0d4d0e82f74c3c286fb340aecbbe2874f26a39d48ea62c84","abstract_canon_sha256":"04b244492f83adb4e748daf9780c1d9815900e47ef3ab6eb34b589eb2e9fba26"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-23T01:23:34.527799Z","signature_b64":"m2kJn3xIq1yxQtOefXc4FFuuHSFQJTCC9hekK7nt2eeNr79zC3w3ZUJ2OaiJwj+sHZZDID1cJgjFqRMz7UPfCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"26d22a0177a67f982dd75f936f396d5eb8ccb3e43b0eb644d1a265d7d8221bc7","last_reissued_at":"2026-07-23T01:23:34.526841Z","signature_status":"signed_v1","first_computed_at":"2026-07-23T01:23:34.526841Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Trusting What You Cannot See: Auditable Fine-Tuning and Inference for Proprietary AI","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Chaoyu Zhang, Heng Jin, Hexuan Yu, Ning Zhang, Shanghao Shi, Wenjing Lou, Y. Thomas Hou","submitted_at":"2026-03-08T05:06:45Z","abstract_excerpt":"Cloud-based infrastructure has become the dominant platform for deploying large models, particularly large language models (LLMs). Fine-tuning and inference are increasingly delegated to cloud providers for simplified deployment and access to proprietary models, yet this creates a fundamental trust gap. Although cryptographic and TEE-based verification approaches exist, prohibitive proving costs and limited TEE memory prevent them from scaling to modern LLMs, leaving clients unable to practically audit these processes. This lack of transparency creates concrete security risks that can silently"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2603.07466","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2603.07466/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2603.07466","created_at":"2026-07-23T01:23:34.527292+00:00"},{"alias_kind":"arxiv_version","alias_value":"2603.07466v2","created_at":"2026-07-23T01:23:34.527292+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2603.07466","created_at":"2026-07-23T01:23:34.527292+00:00"},{"alias_kind":"pith_short_12","alias_value":"E3JCUALXUZ7Z","created_at":"2026-07-23T01:23:34.527292+00:00"},{"alias_kind":"pith_short_16","alias_value":"E3JCUALXUZ7ZQLOX","created_at":"2026-07-23T01:23:34.527292+00:00"},{"alias_kind":"pith_short_8","alias_value":"E3JCUALX","created_at":"2026-07-23T01:23:34.527292+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":2,"sample":[{"citing_arxiv_id":"2605.15164","citing_title":"Position: Behavioural Assurance Cannot Verify the Safety Claims Governance Now Demands","ref_index":70,"is_internal_anchor":true},{"citing_arxiv_id":"2604.18179","citing_title":"Committed SAE-Feature Traces for Audited-Session Substitution Detection in Hosted LLMs","ref_index":20,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/E3JCUALXUZ7ZQLOXL6JW6OLNL2","json":"https://pith.science/pith/E3JCUALXUZ7ZQLOXL6JW6OLNL2.json","graph_json":"https://pith.science/api/pith-number/E3JCUALXUZ7ZQLOXL6JW6OLNL2/graph.json","events_json":"https://pith.science/api/pith-number/E3JCUALXUZ7ZQLOXL6JW6OLNL2/events.json","paper":"https://pith.science/paper/E3JCUALX"},"agent_actions":{"view_html":"https://pith.science/pith/E3JCUALXUZ7ZQLOXL6JW6OLNL2","download_json":"https://pith.science/pith/E3JCUALXUZ7ZQLOXL6JW6OLNL2.json","view_paper":"https://pith.science/paper/E3JCUALX","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2603.07466&json=true","fetch_graph":"https://pith.science/api/pith-number/E3JCUALXUZ7ZQLOXL6JW6OLNL2/graph.json","fetch_events":"https://pith.science/api/pith-number/E3JCUALXUZ7ZQLOXL6JW6OLNL2/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/E3JCUALXUZ7ZQLOXL6JW6OLNL2/action/timestamp_anchor","attest_storage":"https://pith.science/pith/E3JCUALXUZ7ZQLOXL6JW6OLNL2/action/storage_attestation","attest_author":"https://pith.science/pith/E3JCUALXUZ7ZQLOXL6JW6OLNL2/action/author_attestation","sign_citation":"https://pith.science/pith/E3JCUALXUZ7ZQLOXL6JW6OLNL2/action/citation_signature","submit_replication":"https://pith.science/pith/E3JCUALXUZ7ZQLOXL6JW6OLNL2/action/replication_record"}},"created_at":"2026-07-23T01:23:34.527292+00:00","updated_at":"2026-07-23T01:23:34.527292+00:00"}