{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:FM7N42CGPSPROA5IG4722AJNCR","short_pith_number":"pith:FM7N42CG","canonical_record":{"source":{"id":"1807.05185","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-07-13T17:15:00Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"2e783a0fe325f98539290f8f2bf633fd0ad2aeb674b9c5b8f3f6390c7a769cc1","abstract_canon_sha256":"1273ecfb795cbfc0f8d022c177b85b48860ab99353d7dedf2cb0d4b7472aee4f"},"schema_version":"1.0"},"canonical_sha256":"2b3ede68467c9f1703a8373fad012d14631b8d7adf56dd5af56c0296ba3691db","source":{"kind":"arxiv","id":"1807.05185","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1807.05185","created_at":"2026-05-18T00:10:48Z"},{"alias_kind":"arxiv_version","alias_value":"1807.05185v1","created_at":"2026-05-18T00:10:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1807.05185","created_at":"2026-05-18T00:10:48Z"},{"alias_kind":"pith_short_12","alias_value":"FM7N42CGPSPR","created_at":"2026-05-18T12:32:22Z"},{"alias_kind":"pith_short_16","alias_value":"FM7N42CGPSPROA5I","created_at":"2026-05-18T12:32:22Z"},{"alias_kind":"pith_short_8","alias_value":"FM7N42CG","created_at":"2026-05-18T12:32:22Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:FM7N42CGPSPROA5IG4722AJNCR","target":"record","payload":{"canonical_record":{"source":{"id":"1807.05185","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-07-13T17:15:00Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"2e783a0fe325f98539290f8f2bf633fd0ad2aeb674b9c5b8f3f6390c7a769cc1","abstract_canon_sha256":"1273ecfb795cbfc0f8d022c177b85b48860ab99353d7dedf2cb0d4b7472aee4f"},"schema_version":"1.0"},"canonical_sha256":"2b3ede68467c9f1703a8373fad012d14631b8d7adf56dd5af56c0296ba3691db","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:10:48.570197Z","signature_b64":"FyuwrGStcgT1ou/sdNcp7DtXCcfylk1nAXTP1Or18eyus65BQxI361T5dWHvntYO1BaAZffTe729kMz1ogTVAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2b3ede68467c9f1703a8373fad012d14631b8d7adf56dd5af56c0296ba3691db","last_reissued_at":"2026-05-18T00:10:48.569676Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:10:48.569676Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1807.05185","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:10:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"nFcv/rY6N2TZ5YMLDw+ybvjDoSX5dTr4veLnX0a17ixNRSZka6CyKFexe86xdeG55m6HlKwnN5/d5TBpZNMJDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T16:40:41.377503Z"},"content_sha256":"a24192ceae4e4dcb6ba43192404e2c10f78647803fe8b969e4e5cfe4090374c3","schema_version":"1.0","event_id":"sha256:a24192ceae4e4dcb6ba43192404e2c10f78647803fe8b969e4e5cfe4090374c3"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:FM7N42CGPSPROA5IG4722AJNCR","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Model Reconstruction from Model Explanations","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"stat.ML","authors_text":"Anca D. Dragan, Ludwig Schmidt, Moritz Hardt, Smitha Milli","submitted_at":"2018-07-13T17:15:00Z","abstract_excerpt":"We show through theory and experiment that gradient-based explanations of a model quickly reveal the model itself. Our results speak to a tension between the desire to keep a proprietary model secret and the ability to offer model explanations. On the theoretical side, we give an algorithm that provably learns a two-layer ReLU network in a setting where the algorithm may query the gradient of the model with respect to chosen inputs. The number of queries is independent of the dimension and nearly optimal in its dependence on the model size. Of interest not only from a learning-theoretic perspe"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1807.05185","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:10:48Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"KIFmSMn2Pq9bZ98Mar+uSqAdt35uu/TQ0yOLuHn2/NXT530l1ZY5hWNdn/j9G7v1p4C4S8F3U3z+mBtGADNyAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T16:40:41.377857Z"},"content_sha256":"09b8c2879b54b8cbd9ae81a1e3ab8c2238e4c27223912b8bff9b7e8d6e0db3ec","schema_version":"1.0","event_id":"sha256:09b8c2879b54b8cbd9ae81a1e3ab8c2238e4c27223912b8bff9b7e8d6e0db3ec"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/FM7N42CGPSPROA5IG4722AJNCR/bundle.json","state_url":"https://pith.science/pith/FM7N42CGPSPROA5IG4722AJNCR/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/FM7N42CGPSPROA5IG4722AJNCR/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-09T16:40:41Z","links":{"resolver":"https://pith.science/pith/FM7N42CGPSPROA5IG4722AJNCR","bundle":"https://pith.science/pith/FM7N42CGPSPROA5IG4722AJNCR/bundle.json","state":"https://pith.science/pith/FM7N42CGPSPROA5IG4722AJNCR/state.json","well_known_bundle":"https://pith.science/.well-known/pith/FM7N42CGPSPROA5IG4722AJNCR/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:FM7N42CGPSPROA5IG4722AJNCR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"1273ecfb795cbfc0f8d022c177b85b48860ab99353d7dedf2cb0d4b7472aee4f","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-07-13T17:15:00Z","title_canon_sha256":"2e783a0fe325f98539290f8f2bf633fd0ad2aeb674b9c5b8f3f6390c7a769cc1"},"schema_version":"1.0","source":{"id":"1807.05185","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1807.05185","created_at":"2026-05-18T00:10:48Z"},{"alias_kind":"arxiv_version","alias_value":"1807.05185v1","created_at":"2026-05-18T00:10:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1807.05185","created_at":"2026-05-18T00:10:48Z"},{"alias_kind":"pith_short_12","alias_value":"FM7N42CGPSPR","created_at":"2026-05-18T12:32:22Z"},{"alias_kind":"pith_short_16","alias_value":"FM7N42CGPSPROA5I","created_at":"2026-05-18T12:32:22Z"},{"alias_kind":"pith_short_8","alias_value":"FM7N42CG","created_at":"2026-05-18T12:32:22Z"}],"graph_snapshots":[{"event_id":"sha256:09b8c2879b54b8cbd9ae81a1e3ab8c2238e4c27223912b8bff9b7e8d6e0db3ec","target":"graph","created_at":"2026-05-18T00:10:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We show through theory and experiment that gradient-based explanations of a model quickly reveal the model itself. Our results speak to a tension between the desire to keep a proprietary model secret and the ability to offer model explanations. On the theoretical side, we give an algorithm that provably learns a two-layer ReLU network in a setting where the algorithm may query the gradient of the model with respect to chosen inputs. The number of queries is independent of the dimension and nearly optimal in its dependence on the model size. Of interest not only from a learning-theoretic perspe","authors_text":"Anca D. Dragan, Ludwig Schmidt, Moritz Hardt, Smitha Milli","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-07-13T17:15:00Z","title":"Model Reconstruction from Model Explanations"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1807.05185","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:a24192ceae4e4dcb6ba43192404e2c10f78647803fe8b969e4e5cfe4090374c3","target":"record","created_at":"2026-05-18T00:10:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"1273ecfb795cbfc0f8d022c177b85b48860ab99353d7dedf2cb0d4b7472aee4f","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2018-07-13T17:15:00Z","title_canon_sha256":"2e783a0fe325f98539290f8f2bf633fd0ad2aeb674b9c5b8f3f6390c7a769cc1"},"schema_version":"1.0","source":{"id":"1807.05185","kind":"arxiv","version":1}},"canonical_sha256":"2b3ede68467c9f1703a8373fad012d14631b8d7adf56dd5af56c0296ba3691db","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"2b3ede68467c9f1703a8373fad012d14631b8d7adf56dd5af56c0296ba3691db","first_computed_at":"2026-05-18T00:10:48.569676Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:10:48.569676Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"FyuwrGStcgT1ou/sdNcp7DtXCcfylk1nAXTP1Or18eyus65BQxI361T5dWHvntYO1BaAZffTe729kMz1ogTVAQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:10:48.570197Z","signed_message":"canonical_sha256_bytes"},"source_id":"1807.05185","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:a24192ceae4e4dcb6ba43192404e2c10f78647803fe8b969e4e5cfe4090374c3","sha256:09b8c2879b54b8cbd9ae81a1e3ab8c2238e4c27223912b8bff9b7e8d6e0db3ec"],"state_sha256":"09ca7f69be062a4ff4f2a5e733cac067b0a9125abc6e591d6b06d2fd443c0361"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"gKBe8XyaJbWTdI4zo+Dn4eAOX4joQEIR8D/Fas40NfFjFJGzaPzPD5NaA7W+ypI6sE+2QiDTHtopEjHytMmUBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-09T16:40:41.379856Z","bundle_sha256":"0bb496d45466a07b0fb5333b71768bc56b1ff3c2e905b740f8ec7f063a89c0b1"}}