{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:HWRB4DAHSZY54LUQNCCIYQQD54","short_pith_number":"pith:HWRB4DAH","schema_version":"1.0","canonical_sha256":"3da21e0c079671de2e9068848c4203ef29c449134a3e0944847ccf6be7d5b823","source":{"kind":"arxiv","id":"2306.04192","version":4},"attestation_state":"computed","paper":{"title":"Extracting Cloud-based Model with Prior Knowledge","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Guowen Xu, Hongwei Li, Jian Zhang, Kangjie Chen, Meng Hao, Shiqian Zhao, Tianwei Zhang","submitted_at":"2023-06-07T07:00:02Z","abstract_excerpt":"Machine Learning-as-a-Service, a pay-as-you-go business pattern, is widely accepted by third-party users and developers. However, the open inference APIs may be utilized by malicious customers to conduct model extraction attacks, i.e., attackers can replicate a cloud-based black-box model merely via querying malicious examples. Existing model extraction attacks mainly depend on the posterior knowledge (i.e., predictions of query samples) from Oracle. Thus, they either require high query overhead to simulate the decision boundary, or suffer from generalization errors and overfitting problems du"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2306.04192","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2023-06-07T07:00:02Z","cross_cats_sorted":[],"title_canon_sha256":"dd927f289cf5cd3202db3f3f9b6fe8372a217e7067b2354e11c613d7ca3034b3","abstract_canon_sha256":"2aebe41e19161f423ef237b2d47ba5df9a6010aa10be5395878a23201b14ecc3"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:19:59.795433Z","signature_b64":"sV4M3SFhhpy+5izTk93epU9M+FDsa3BTujWqKS0oWyRBSbJ6FfFoyVpnPCSV6yw26M2MVKdbkjXxCoKO8nVZDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3da21e0c079671de2e9068848c4203ef29c449134a3e0944847ccf6be7d5b823","last_reissued_at":"2026-07-05T06:19:59.795029Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:19:59.795029Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Extracting Cloud-based Model with Prior Knowledge","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Guowen Xu, Hongwei Li, Jian Zhang, Kangjie Chen, Meng Hao, Shiqian Zhao, Tianwei Zhang","submitted_at":"2023-06-07T07:00:02Z","abstract_excerpt":"Machine Learning-as-a-Service, a pay-as-you-go business pattern, is widely accepted by third-party users and developers. However, the open inference APIs may be utilized by malicious customers to conduct model extraction attacks, i.e., attackers can replicate a cloud-based black-box model merely via querying malicious examples. Existing model extraction attacks mainly depend on the posterior knowledge (i.e., predictions of query samples) from Oracle. Thus, they either require high query overhead to simulate the decision boundary, or suffer from generalization errors and overfitting problems du"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2306.04192","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2306.04192/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2306.04192","created_at":"2026-07-05T06:19:59.795082+00:00"},{"alias_kind":"arxiv_version","alias_value":"2306.04192v4","created_at":"2026-07-05T06:19:59.795082+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2306.04192","created_at":"2026-07-05T06:19:59.795082+00:00"},{"alias_kind":"pith_short_12","alias_value":"HWRB4DAHSZY5","created_at":"2026-07-05T06:19:59.795082+00:00"},{"alias_kind":"pith_short_16","alias_value":"HWRB4DAHSZY54LUQ","created_at":"2026-07-05T06:19:59.795082+00:00"},{"alias_kind":"pith_short_8","alias_value":"HWRB4DAH","created_at":"2026-07-05T06:19:59.795082+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2508.21654","citing_title":"I Stolenly Swear That I Am Up to (No) Good: Design and Evaluation of Model Stealing Attacks","ref_index":103,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/HWRB4DAHSZY54LUQNCCIYQQD54","json":"https://pith.science/pith/HWRB4DAHSZY54LUQNCCIYQQD54.json","graph_json":"https://pith.science/api/pith-number/HWRB4DAHSZY54LUQNCCIYQQD54/graph.json","events_json":"https://pith.science/api/pith-number/HWRB4DAHSZY54LUQNCCIYQQD54/events.json","paper":"https://pith.science/paper/HWRB4DAH"},"agent_actions":{"view_html":"https://pith.science/pith/HWRB4DAHSZY54LUQNCCIYQQD54","download_json":"https://pith.science/pith/HWRB4DAHSZY54LUQNCCIYQQD54.json","view_paper":"https://pith.science/paper/HWRB4DAH","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2306.04192&json=true","fetch_graph":"https://pith.science/api/pith-number/HWRB4DAHSZY54LUQNCCIYQQD54/graph.json","fetch_events":"https://pith.science/api/pith-number/HWRB4DAHSZY54LUQNCCIYQQD54/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/HWRB4DAHSZY54LUQNCCIYQQD54/action/timestamp_anchor","attest_storage":"https://pith.science/pith/HWRB4DAHSZY54LUQNCCIYQQD54/action/storage_attestation","attest_author":"https://pith.science/pith/HWRB4DAHSZY54LUQNCCIYQQD54/action/author_attestation","sign_citation":"https://pith.science/pith/HWRB4DAHSZY54LUQNCCIYQQD54/action/citation_signature","submit_replication":"https://pith.science/pith/HWRB4DAHSZY54LUQNCCIYQQD54/action/replication_record"}},"created_at":"2026-07-05T06:19:59.795082+00:00","updated_at":"2026-07-05T06:19:59.795082+00:00"}