{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:JHB5PTHFJAFEQNEEANQ6UIIBOH","short_pith_number":"pith:JHB5PTHF","schema_version":"1.0","canonical_sha256":"49c3d7cce5480a4834840361ea210171f8321e2e9f4fcf801d008ab976114c80","source":{"kind":"arxiv","id":"2002.00937","version":1},"attestation_state":"computed","paper":{"title":"Radioactive data: tracing through training","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","cs.LG"],"primary_cat":"stat.ML","authors_text":"Alexandre Sablayrolles, Cordelia Schmid, Herv\\'e J\\'egou, Matthijs Douze","submitted_at":"2020-02-03T18:41:08Z","abstract_excerpt":"We want to detect whether a particular image dataset has been used to train a model. We propose a new technique, \\emph{radioactive data}, that makes imperceptible changes to this dataset such that any model trained on it will bear an identifiable mark. The mark is robust to strong variations such as different architectures or optimization methods. Given a trained model, our technique detects the use of radioactive data and provides a level of confidence (p-value). Our experiments on large-scale benchmarks (Imagenet), using standard architectures (Resnet-18, VGG-16, Densenet-121) and training p"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2002.00937","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2020-02-03T18:41:08Z","cross_cats_sorted":["cs.CR","cs.CV","cs.LG"],"title_canon_sha256":"cd9a8df564030c9ab3c22e13eec74b8e6955d2da1357f45a962fc252102a21f8","abstract_canon_sha256":"59be2589be4e12151f0d7c4a10f429f4139e652b0326c35bbc067841f1f17b90"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:38:37.413812Z","signature_b64":"Tkafd72LcOfGDF/wXSfneqbRx4Q/ajdF1yXtf7MeTVl/bPt9VC8YxLIUA/O6clymzxMNaDXY8UTpp02Hu8zbDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"49c3d7cce5480a4834840361ea210171f8321e2e9f4fcf801d008ab976114c80","last_reissued_at":"2026-07-05T00:38:37.413302Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:38:37.413302Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Radioactive data: tracing through training","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV","cs.LG"],"primary_cat":"stat.ML","authors_text":"Alexandre Sablayrolles, Cordelia Schmid, Herv\\'e J\\'egou, Matthijs Douze","submitted_at":"2020-02-03T18:41:08Z","abstract_excerpt":"We want to detect whether a particular image dataset has been used to train a model. We propose a new technique, \\emph{radioactive data}, that makes imperceptible changes to this dataset such that any model trained on it will bear an identifiable mark. The mark is robust to strong variations such as different architectures or optimization methods. Given a trained model, our technique detects the use of radioactive data and provides a level of confidence (p-value). Our experiments on large-scale benchmarks (Imagenet), using standard architectures (Resnet-18, VGG-16, Densenet-121) and training p"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2002.00937","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2002.00937/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2002.00937","created_at":"2026-07-05T00:38:37.413373+00:00"},{"alias_kind":"arxiv_version","alias_value":"2002.00937v1","created_at":"2026-07-05T00:38:37.413373+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2002.00937","created_at":"2026-07-05T00:38:37.413373+00:00"},{"alias_kind":"pith_short_12","alias_value":"JHB5PTHFJAFE","created_at":"2026-07-05T00:38:37.413373+00:00"},{"alias_kind":"pith_short_16","alias_value":"JHB5PTHFJAFEQNEE","created_at":"2026-07-05T00:38:37.413373+00:00"},{"alias_kind":"pith_short_8","alias_value":"JHB5PTHF","created_at":"2026-07-05T00:38:37.413373+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.16462","citing_title":"Asking Back: Interaction-Layer Antidistillation Watermarks","ref_index":27,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/JHB5PTHFJAFEQNEEANQ6UIIBOH","json":"https://pith.science/pith/JHB5PTHFJAFEQNEEANQ6UIIBOH.json","graph_json":"https://pith.science/api/pith-number/JHB5PTHFJAFEQNEEANQ6UIIBOH/graph.json","events_json":"https://pith.science/api/pith-number/JHB5PTHFJAFEQNEEANQ6UIIBOH/events.json","paper":"https://pith.science/paper/JHB5PTHF"},"agent_actions":{"view_html":"https://pith.science/pith/JHB5PTHFJAFEQNEEANQ6UIIBOH","download_json":"https://pith.science/pith/JHB5PTHFJAFEQNEEANQ6UIIBOH.json","view_paper":"https://pith.science/paper/JHB5PTHF","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2002.00937&json=true","fetch_graph":"https://pith.science/api/pith-number/JHB5PTHFJAFEQNEEANQ6UIIBOH/graph.json","fetch_events":"https://pith.science/api/pith-number/JHB5PTHFJAFEQNEEANQ6UIIBOH/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/JHB5PTHFJAFEQNEEANQ6UIIBOH/action/timestamp_anchor","attest_storage":"https://pith.science/pith/JHB5PTHFJAFEQNEEANQ6UIIBOH/action/storage_attestation","attest_author":"https://pith.science/pith/JHB5PTHFJAFEQNEEANQ6UIIBOH/action/author_attestation","sign_citation":"https://pith.science/pith/JHB5PTHFJAFEQNEEANQ6UIIBOH/action/citation_signature","submit_replication":"https://pith.science/pith/JHB5PTHFJAFEQNEEANQ6UIIBOH/action/replication_record"}},"created_at":"2026-07-05T00:38:37.413373+00:00","updated_at":"2026-07-05T00:38:37.413373+00:00"}