{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ","short_pith_number":"pith:JV7CC5KX","schema_version":"1.0","canonical_sha256":"4d7e2175574f33c52fb99bf10002fd92726a2ca304d15e4d9f7815602f7b9d85","source":{"kind":"arxiv","id":"2305.16157","version":1},"attestation_state":"computed","paper":{"title":"Training Data Extraction From Pre-trained Language Models: A Survey","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Shotaro Ishihara","submitted_at":"2023-05-25T15:23:29Z","abstract_excerpt":"As the deployment of pre-trained language models (PLMs) expands, pressing security concerns have arisen regarding the potential for malicious extraction of training data, posing a threat to data privacy. This study is the first to provide a comprehensive survey of training data extraction from PLMs. Our review covers more than 100 key papers in fields such as natural language processing and security. First, preliminary knowledge is recapped and a taxonomy of various definitions of memorization is presented. The approaches for attack and defense are then systemized. Furthermore, the empirical f"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2305.16157","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2023-05-25T15:23:29Z","cross_cats_sorted":[],"title_canon_sha256":"85873ef713f9e0239f0dbb94c9b93df00c75fc775fb278af23bebcb6be2fdc42","abstract_canon_sha256":"ee6477b8ed08a18194d620be8fc609a6466373101fc3a77568fdcf7017a5de74"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:14:00.088778Z","signature_b64":"6HDhusDKIY9m1xrU8urpuTzpd3X9FQrg7LI0Q6NI/bMiN9cR00xTOTngmIjA8BjW4KrsPdQikYvmSDCd/0ojBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4d7e2175574f33c52fb99bf10002fd92726a2ca304d15e4d9f7815602f7b9d85","last_reissued_at":"2026-07-05T06:14:00.088367Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:14:00.088367Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Training Data Extraction From Pre-trained Language Models: A Survey","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Shotaro Ishihara","submitted_at":"2023-05-25T15:23:29Z","abstract_excerpt":"As the deployment of pre-trained language models (PLMs) expands, pressing security concerns have arisen regarding the potential for malicious extraction of training data, posing a threat to data privacy. This study is the first to provide a comprehensive survey of training data extraction from PLMs. Our review covers more than 100 key papers in fields such as natural language processing and security. First, preliminary knowledge is recapped and a taxonomy of various definitions of memorization is presented. The approaches for attack and defense are then systemized. Furthermore, the empirical f"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2305.16157","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2305.16157/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2305.16157","created_at":"2026-07-05T06:14:00.088430+00:00"},{"alias_kind":"arxiv_version","alias_value":"2305.16157v1","created_at":"2026-07-05T06:14:00.088430+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2305.16157","created_at":"2026-07-05T06:14:00.088430+00:00"},{"alias_kind":"pith_short_12","alias_value":"JV7CC5KXJ4Z4","created_at":"2026-07-05T06:14:00.088430+00:00"},{"alias_kind":"pith_short_16","alias_value":"JV7CC5KXJ4Z4KL5Z","created_at":"2026-07-05T06:14:00.088430+00:00"},{"alias_kind":"pith_short_8","alias_value":"JV7CC5KX","created_at":"2026-07-05T06:14:00.088430+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.17110","citing_title":"Loss Landscape Poisoning: Targeted Extraction of Unseen Training Data from LLMs","ref_index":31,"is_internal_anchor":false},{"citing_arxiv_id":"2606.03399","citing_title":"Selective Token-Level Cryptographic Redaction for Privacy-Preserving Clinical Deployment of Large Language Models","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2605.26133","citing_title":"Pretraining Data Exposure in Large Language Models: A Survey of Membership Inference, Data Contamination, and Security Implications","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2402.16391","citing_title":"Industry Practitioners Perspectives on AI Model Quality: Perceptions, Challenges, and Solutions","ref_index":69,"is_internal_anchor":false},{"citing_arxiv_id":"2605.05224","citing_title":"Channel-Level Semantic Perturbations: Unlearnable Examples for Diverse Training Paradigms","ref_index":11,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ","json":"https://pith.science/pith/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ.json","graph_json":"https://pith.science/api/pith-number/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ/graph.json","events_json":"https://pith.science/api/pith-number/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ/events.json","paper":"https://pith.science/paper/JV7CC5KX"},"agent_actions":{"view_html":"https://pith.science/pith/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ","download_json":"https://pith.science/pith/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ.json","view_paper":"https://pith.science/paper/JV7CC5KX","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2305.16157&json=true","fetch_graph":"https://pith.science/api/pith-number/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ/graph.json","fetch_events":"https://pith.science/api/pith-number/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ/action/storage_attestation","attest_author":"https://pith.science/pith/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ/action/author_attestation","sign_citation":"https://pith.science/pith/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ/action/citation_signature","submit_replication":"https://pith.science/pith/JV7CC5KXJ4Z4KL5ZTPYQAAX5SJ/action/replication_record"}},"created_at":"2026-07-05T06:14:00.088430+00:00","updated_at":"2026-07-05T06:14:00.088430+00:00"}