{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2018:HQY667GOFQNXBK6ENTCOSKQ5KZ","short_pith_number":"pith:HQY667GO","schema_version":"1.0","canonical_sha256":"3c31ef7cce2c1b70abc46cc4e92a1d5643382cc419daccb40fde98d5c00022be","source":{"kind":"arxiv","id":"1811.01134","version":1},"attestation_state":"computed","paper":{"title":"A Marauder's Map of Security and Privacy in Machine Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Nicolas Papernot","submitted_at":"2018-11-03T00:25:50Z","abstract_excerpt":"There is growing recognition that machine learning (ML) exposes new security and privacy vulnerabilities in software systems, yet the technical community's understanding of the nature and extent of these vulnerabilities remains limited but expanding. In this talk, we explore the threat model space of ML algorithms through the lens of Saltzer and Schroeder's principles for the design of secure computer systems. This characterization of the threat space prompts an investigation of current and future research directions. We structure our discussion around three of these directions, which we belie"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1811.01134","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-11-03T00:25:50Z","cross_cats_sorted":[],"title_canon_sha256":"2dbbc66c6d03af0068ab432bc0bff9f96da04689f0a751c996fe14c97377873b","abstract_canon_sha256":"d482b27d140485b92788678e54432e026111926111d49ee60bfe0c390fe36f54"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:01:35.286937Z","signature_b64":"bepjU0TYOKixL1fS1HzhgaA5DC2F3udebWBt8SLiH77cVRKlUiylLd8JFuiYp9gVyJZ6YiyHjvcQcWD3anveAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3c31ef7cce2c1b70abc46cc4e92a1d5643382cc419daccb40fde98d5c00022be","last_reissued_at":"2026-05-18T00:01:35.286209Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:01:35.286209Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"A Marauder's Map of Security and Privacy in Machine Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Nicolas Papernot","submitted_at":"2018-11-03T00:25:50Z","abstract_excerpt":"There is growing recognition that machine learning (ML) exposes new security and privacy vulnerabilities in software systems, yet the technical community's understanding of the nature and extent of these vulnerabilities remains limited but expanding. In this talk, we explore the threat model space of ML algorithms through the lens of Saltzer and Schroeder's principles for the design of secure computer systems. This characterization of the threat space prompts an investigation of current and future research directions. We structure our discussion around three of these directions, which we belie"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1811.01134","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1811.01134","created_at":"2026-05-18T00:01:35.286331+00:00"},{"alias_kind":"arxiv_version","alias_value":"1811.01134v1","created_at":"2026-05-18T00:01:35.286331+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1811.01134","created_at":"2026-05-18T00:01:35.286331+00:00"},{"alias_kind":"pith_short_12","alias_value":"HQY667GOFQNX","created_at":"2026-05-18T12:32:28.185984+00:00"},{"alias_kind":"pith_short_16","alias_value":"HQY667GOFQNXBK6E","created_at":"2026-05-18T12:32:28.185984+00:00"},{"alias_kind":"pith_short_8","alias_value":"HQY667GO","created_at":"2026-05-18T12:32:28.185984+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2508.05677","citing_title":"Adversarial Attacks on Reinforcement Learning-based Medical Questionnaire Systems: Input-level Perturbation Strategies and Medical Constraint Validation","ref_index":11,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/HQY667GOFQNXBK6ENTCOSKQ5KZ","json":"https://pith.science/pith/HQY667GOFQNXBK6ENTCOSKQ5KZ.json","graph_json":"https://pith.science/api/pith-number/HQY667GOFQNXBK6ENTCOSKQ5KZ/graph.json","events_json":"https://pith.science/api/pith-number/HQY667GOFQNXBK6ENTCOSKQ5KZ/events.json","paper":"https://pith.science/paper/HQY667GO"},"agent_actions":{"view_html":"https://pith.science/pith/HQY667GOFQNXBK6ENTCOSKQ5KZ","download_json":"https://pith.science/pith/HQY667GOFQNXBK6ENTCOSKQ5KZ.json","view_paper":"https://pith.science/paper/HQY667GO","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1811.01134&json=true","fetch_graph":"https://pith.science/api/pith-number/HQY667GOFQNXBK6ENTCOSKQ5KZ/graph.json","fetch_events":"https://pith.science/api/pith-number/HQY667GOFQNXBK6ENTCOSKQ5KZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/HQY667GOFQNXBK6ENTCOSKQ5KZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/HQY667GOFQNXBK6ENTCOSKQ5KZ/action/storage_attestation","attest_author":"https://pith.science/pith/HQY667GOFQNXBK6ENTCOSKQ5KZ/action/author_attestation","sign_citation":"https://pith.science/pith/HQY667GOFQNXBK6ENTCOSKQ5KZ/action/citation_signature","submit_replication":"https://pith.science/pith/HQY667GOFQNXBK6ENTCOSKQ5KZ/action/replication_record"}},"created_at":"2026-05-18T00:01:35.286331+00:00","updated_at":"2026-05-18T00:01:35.286331+00:00"}