{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2021:HR6UYJGZ5CTKLHVQNXC2KK7VDF","short_pith_number":"pith:HR6UYJGZ","canonical_record":{"source":{"id":"2110.05524","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2021-10-11T18:02:52Z","cross_cats_sorted":[],"title_canon_sha256":"1dd77fb5f2134c2718a44f161102cc9d25eb357643b3af95241ed31453719cbb","abstract_canon_sha256":"078348d4f0dbad92fdc4c6ef70c94fad39b09afd20a9aca92a969843e94cda3b"},"schema_version":"1.0"},"canonical_sha256":"3c7d4c24d9e8a6a59eb06dc5a52bf5196424ce6771d55d8e4354a55636058b88","source":{"kind":"arxiv","id":"2110.05524","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2110.05524","created_at":"2026-07-05T03:22:03Z"},{"alias_kind":"arxiv_version","alias_value":"2110.05524v1","created_at":"2026-07-05T03:22:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2110.05524","created_at":"2026-07-05T03:22:03Z"},{"alias_kind":"pith_short_12","alias_value":"HR6UYJGZ5CTK","created_at":"2026-07-05T03:22:03Z"},{"alias_kind":"pith_short_16","alias_value":"HR6UYJGZ5CTKLHVQ","created_at":"2026-07-05T03:22:03Z"},{"alias_kind":"pith_short_8","alias_value":"HR6UYJGZ","created_at":"2026-07-05T03:22:03Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2021:HR6UYJGZ5CTKLHVQNXC2KK7VDF","target":"record","payload":{"canonical_record":{"source":{"id":"2110.05524","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2021-10-11T18:02:52Z","cross_cats_sorted":[],"title_canon_sha256":"1dd77fb5f2134c2718a44f161102cc9d25eb357643b3af95241ed31453719cbb","abstract_canon_sha256":"078348d4f0dbad92fdc4c6ef70c94fad39b09afd20a9aca92a969843e94cda3b"},"schema_version":"1.0"},"canonical_sha256":"3c7d4c24d9e8a6a59eb06dc5a52bf5196424ce6771d55d8e4354a55636058b88","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T03:22:03.737868Z","signature_b64":"uJSw+HiA5L+XbLJ1I1ZBP2tHuKR4xWQHcIDJ/TWdRgELH5jBfRWzJRHfX8Zi3M/l2DqaJs2PRN6LZf5BuwO7CQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3c7d4c24d9e8a6a59eb06dc5a52bf5196424ce6771d55d8e4354a55636058b88","last_reissued_at":"2026-07-05T03:22:03.737409Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T03:22:03.737409Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2110.05524","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T03:22:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"G3tiDzD2cQ81JgGifC2U9P3GAcGcoLfI+imtW2P7WrYLlV/xU74I84yB2wJbzfglq0tERd/IALn08SqlRjP5CQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-05T11:09:11.391018Z"},"content_sha256":"8d85de6eb1e983f47b76ad4e9535bea37e78a537be56600e9f1b766439d70a9d","schema_version":"1.0","event_id":"sha256:8d85de6eb1e983f47b76ad4e9535bea37e78a537be56600e9f1b766439d70a9d"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2021:HR6UYJGZ5CTKLHVQNXC2KK7VDF","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Generalization Techniques Empirically Outperform Differential Privacy against Membership Inference","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Florian Kerschbaum, Jiaxiang Liu, Simon Oya","submitted_at":"2021-10-11T18:02:52Z","abstract_excerpt":"Differentially private training algorithms provide protection against one of the most popular attacks in machine learning: the membership inference attack. However, these privacy algorithms incur a loss of the model's classification accuracy, therefore creating a privacy-utility trade-off. The amount of noise that differential privacy requires to provide strong theoretical protection guarantees in deep learning typically renders the models unusable, but authors have observed that even lower noise levels provide acceptable empirical protection against existing membership inference attacks.\n  In"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2110.05524","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2110.05524/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T03:22:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"RWsQUHJ1WabuXerUM/rBm31e3ElmMF/odEyK3okuUqrCScIEv6QhTr11l4cjDSR6qkmebGfMz5NqF0rhC8RuCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-05T11:09:11.391404Z"},"content_sha256":"aeca69c87d6d24c4c2f8b2857705e607d782758bb4373a96561587d4a48250d1","schema_version":"1.0","event_id":"sha256:aeca69c87d6d24c4c2f8b2857705e607d782758bb4373a96561587d4a48250d1"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/HR6UYJGZ5CTKLHVQNXC2KK7VDF/bundle.json","state_url":"https://pith.science/pith/HR6UYJGZ5CTKLHVQNXC2KK7VDF/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/HR6UYJGZ5CTKLHVQNXC2KK7VDF/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-05T11:09:11Z","links":{"resolver":"https://pith.science/pith/HR6UYJGZ5CTKLHVQNXC2KK7VDF","bundle":"https://pith.science/pith/HR6UYJGZ5CTKLHVQNXC2KK7VDF/bundle.json","state":"https://pith.science/pith/HR6UYJGZ5CTKLHVQNXC2KK7VDF/state.json","well_known_bundle":"https://pith.science/.well-known/pith/HR6UYJGZ5CTKLHVQNXC2KK7VDF/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2021:HR6UYJGZ5CTKLHVQNXC2KK7VDF","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"078348d4f0dbad92fdc4c6ef70c94fad39b09afd20a9aca92a969843e94cda3b","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2021-10-11T18:02:52Z","title_canon_sha256":"1dd77fb5f2134c2718a44f161102cc9d25eb357643b3af95241ed31453719cbb"},"schema_version":"1.0","source":{"id":"2110.05524","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2110.05524","created_at":"2026-07-05T03:22:03Z"},{"alias_kind":"arxiv_version","alias_value":"2110.05524v1","created_at":"2026-07-05T03:22:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2110.05524","created_at":"2026-07-05T03:22:03Z"},{"alias_kind":"pith_short_12","alias_value":"HR6UYJGZ5CTK","created_at":"2026-07-05T03:22:03Z"},{"alias_kind":"pith_short_16","alias_value":"HR6UYJGZ5CTKLHVQ","created_at":"2026-07-05T03:22:03Z"},{"alias_kind":"pith_short_8","alias_value":"HR6UYJGZ","created_at":"2026-07-05T03:22:03Z"}],"graph_snapshots":[{"event_id":"sha256:aeca69c87d6d24c4c2f8b2857705e607d782758bb4373a96561587d4a48250d1","target":"graph","created_at":"2026-07-05T03:22:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2110.05524/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Differentially private training algorithms provide protection against one of the most popular attacks in machine learning: the membership inference attack. However, these privacy algorithms incur a loss of the model's classification accuracy, therefore creating a privacy-utility trade-off. The amount of noise that differential privacy requires to provide strong theoretical protection guarantees in deep learning typically renders the models unusable, but authors have observed that even lower noise levels provide acceptable empirical protection against existing membership inference attacks.\n  In","authors_text":"Florian Kerschbaum, Jiaxiang Liu, Simon Oya","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2021-10-11T18:02:52Z","title":"Generalization Techniques Empirically Outperform Differential Privacy against Membership Inference"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2110.05524","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8d85de6eb1e983f47b76ad4e9535bea37e78a537be56600e9f1b766439d70a9d","target":"record","created_at":"2026-07-05T03:22:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"078348d4f0dbad92fdc4c6ef70c94fad39b09afd20a9aca92a969843e94cda3b","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2021-10-11T18:02:52Z","title_canon_sha256":"1dd77fb5f2134c2718a44f161102cc9d25eb357643b3af95241ed31453719cbb"},"schema_version":"1.0","source":{"id":"2110.05524","kind":"arxiv","version":1}},"canonical_sha256":"3c7d4c24d9e8a6a59eb06dc5a52bf5196424ce6771d55d8e4354a55636058b88","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"3c7d4c24d9e8a6a59eb06dc5a52bf5196424ce6771d55d8e4354a55636058b88","first_computed_at":"2026-07-05T03:22:03.737409Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T03:22:03.737409Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"uJSw+HiA5L+XbLJ1I1ZBP2tHuKR4xWQHcIDJ/TWdRgELH5jBfRWzJRHfX8Zi3M/l2DqaJs2PRN6LZf5BuwO7CQ==","signature_status":"signed_v1","signed_at":"2026-07-05T03:22:03.737868Z","signed_message":"canonical_sha256_bytes"},"source_id":"2110.05524","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8d85de6eb1e983f47b76ad4e9535bea37e78a537be56600e9f1b766439d70a9d","sha256:aeca69c87d6d24c4c2f8b2857705e607d782758bb4373a96561587d4a48250d1"],"state_sha256":"b098b7f87ce0e311d7995c28d4a4f74fca2ef0ce3415933f63bc230dc1767e43"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"z4TQ92eCoixhGHc4P2m70cz1lIJZFEe8xng3CXVrlwlNBZHYjC0jReTcr3j+DSdZauXkUErKCp6Fo9XbgDf/AA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-05T11:09:11.393359Z","bundle_sha256":"017db17c98b37cc472bd4e3e42356fbe22f1741e1d1c3442e91e11c37efd0a6a"}}