{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:KFBV36WRSMTVXBMDTA3D2AJ4VR","short_pith_number":"pith:KFBV36WR","canonical_record":{"source":{"id":"1802.04889","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-13T23:05:05Z","cross_cats_sorted":["cs.LG","stat.ML"],"title_canon_sha256":"16fd61de20f8cd5fb05c0fca9564fec1b77c0a46f844e8df19865d761b73550f","abstract_canon_sha256":"ba38643b09dcf143201efc9192ac8aa4bd27e590a98d240c88d8a1655f05cb63"},"schema_version":"1.0"},"canonical_sha256":"51435dfad193275b858398363d013cac660a4a14c3b8900a185061b5ab4191b7","source":{"kind":"arxiv","id":"1802.04889","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1802.04889","created_at":"2026-05-18T00:23:22Z"},{"alias_kind":"arxiv_version","alias_value":"1802.04889v1","created_at":"2026-05-18T00:23:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1802.04889","created_at":"2026-05-18T00:23:22Z"},{"alias_kind":"pith_short_12","alias_value":"KFBV36WRSMTV","created_at":"2026-05-18T12:32:33Z"},{"alias_kind":"pith_short_16","alias_value":"KFBV36WRSMTVXBMD","created_at":"2026-05-18T12:32:33Z"},{"alias_kind":"pith_short_8","alias_value":"KFBV36WR","created_at":"2026-05-18T12:32:33Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:KFBV36WRSMTVXBMDTA3D2AJ4VR","target":"record","payload":{"canonical_record":{"source":{"id":"1802.04889","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-13T23:05:05Z","cross_cats_sorted":["cs.LG","stat.ML"],"title_canon_sha256":"16fd61de20f8cd5fb05c0fca9564fec1b77c0a46f844e8df19865d761b73550f","abstract_canon_sha256":"ba38643b09dcf143201efc9192ac8aa4bd27e590a98d240c88d8a1655f05cb63"},"schema_version":"1.0"},"canonical_sha256":"51435dfad193275b858398363d013cac660a4a14c3b8900a185061b5ab4191b7","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:23:22.306511Z","signature_b64":"kPQgQ5dTv8ry1stNEWE/4QzsANS1XdlaxJlSPqouex9bbCzS2ezOq0TJPKVUm792NO8C5Ko78jeS2KNdomt8Cw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"51435dfad193275b858398363d013cac660a4a14c3b8900a185061b5ab4191b7","last_reissued_at":"2026-05-18T00:23:22.305780Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:23:22.305780Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1802.04889","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:23:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"vH6R7b6dNq9ZRftXEN4MoJx/iOS5mX+2joS+gD87+Q4ri1PQd78UUk31Q3m8+sjCq5VxQfqCydv69qCwmlspBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T11:41:34.869460Z"},"content_sha256":"dd31571693adb03c6258916f7bb6e3cdd11fae59ff63c7d483963c62480ce37c","schema_version":"1.0","event_id":"sha256:dd31571693adb03c6258916f7bb6e3cdd11fae59ff63c7d483963c62480ce37c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:KFBV36WRSMTVXBMDTA3D2AJ4VR","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Understanding Membership Inferences on Well-Generalized Learning Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG","stat.ML"],"primary_cat":"cs.CR","authors_text":"Carl A. Gunter, Diyue Bu, Haixu Tang, Kai Chen, Lei Wang, Vincent Bindschaedler, Xiaofeng Wang, Yunhui Long","submitted_at":"2018-02-13T23:05:05Z","abstract_excerpt":"Membership Inference Attack (MIA) determines the presence of a record in a machine learning model's training data by querying the model. Prior work has shown that the attack is feasible when the model is overfitted to its training data or when the adversary controls the training algorithm. However, when the model is not overfitted and the adversary does not control the training algorithm, the threat is not well understood. In this paper, we report a study that discovers overfitting to be a sufficient but not a necessary condition for an MIA to succeed. More specifically, we demonstrate that ev"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1802.04889","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:23:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ngiWWQP131XwRHbxNZIvsa4u3QHexjVEtsYQeTBNH4IVNeEAIRxK8NRv0pucoxvhbICpdSw6LWo9LAK1u/eZBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T11:41:34.870129Z"},"content_sha256":"5aadeea6b6603f749b173c8c2e6ded5def284534866d6d593bb8f3e613cdfe54","schema_version":"1.0","event_id":"sha256:5aadeea6b6603f749b173c8c2e6ded5def284534866d6d593bb8f3e613cdfe54"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR/bundle.json","state_url":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T11:41:34Z","links":{"resolver":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR","bundle":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR/bundle.json","state":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR/state.json","well_known_bundle":"https://pith.science/.well-known/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:KFBV36WRSMTVXBMDTA3D2AJ4VR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ba38643b09dcf143201efc9192ac8aa4bd27e590a98d240c88d8a1655f05cb63","cross_cats_sorted":["cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-13T23:05:05Z","title_canon_sha256":"16fd61de20f8cd5fb05c0fca9564fec1b77c0a46f844e8df19865d761b73550f"},"schema_version":"1.0","source":{"id":"1802.04889","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1802.04889","created_at":"2026-05-18T00:23:22Z"},{"alias_kind":"arxiv_version","alias_value":"1802.04889v1","created_at":"2026-05-18T00:23:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1802.04889","created_at":"2026-05-18T00:23:22Z"},{"alias_kind":"pith_short_12","alias_value":"KFBV36WRSMTV","created_at":"2026-05-18T12:32:33Z"},{"alias_kind":"pith_short_16","alias_value":"KFBV36WRSMTVXBMD","created_at":"2026-05-18T12:32:33Z"},{"alias_kind":"pith_short_8","alias_value":"KFBV36WR","created_at":"2026-05-18T12:32:33Z"}],"graph_snapshots":[{"event_id":"sha256:5aadeea6b6603f749b173c8c2e6ded5def284534866d6d593bb8f3e613cdfe54","target":"graph","created_at":"2026-05-18T00:23:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Membership Inference Attack (MIA) determines the presence of a record in a machine learning model's training data by querying the model. Prior work has shown that the attack is feasible when the model is overfitted to its training data or when the adversary controls the training algorithm. However, when the model is not overfitted and the adversary does not control the training algorithm, the threat is not well understood. In this paper, we report a study that discovers overfitting to be a sufficient but not a necessary condition for an MIA to succeed. More specifically, we demonstrate that ev","authors_text":"Carl A. Gunter, Diyue Bu, Haixu Tang, Kai Chen, Lei Wang, Vincent Bindschaedler, Xiaofeng Wang, Yunhui Long","cross_cats":["cs.LG","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-13T23:05:05Z","title":"Understanding Membership Inferences on Well-Generalized Learning Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1802.04889","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:dd31571693adb03c6258916f7bb6e3cdd11fae59ff63c7d483963c62480ce37c","target":"record","created_at":"2026-05-18T00:23:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ba38643b09dcf143201efc9192ac8aa4bd27e590a98d240c88d8a1655f05cb63","cross_cats_sorted":["cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-13T23:05:05Z","title_canon_sha256":"16fd61de20f8cd5fb05c0fca9564fec1b77c0a46f844e8df19865d761b73550f"},"schema_version":"1.0","source":{"id":"1802.04889","kind":"arxiv","version":1}},"canonical_sha256":"51435dfad193275b858398363d013cac660a4a14c3b8900a185061b5ab4191b7","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"51435dfad193275b858398363d013cac660a4a14c3b8900a185061b5ab4191b7","first_computed_at":"2026-05-18T00:23:22.305780Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:23:22.305780Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"kPQgQ5dTv8ry1stNEWE/4QzsANS1XdlaxJlSPqouex9bbCzS2ezOq0TJPKVUm792NO8C5Ko78jeS2KNdomt8Cw==","signature_status":"signed_v1","signed_at":"2026-05-18T00:23:22.306511Z","signed_message":"canonical_sha256_bytes"},"source_id":"1802.04889","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:dd31571693adb03c6258916f7bb6e3cdd11fae59ff63c7d483963c62480ce37c","sha256:5aadeea6b6603f749b173c8c2e6ded5def284534866d6d593bb8f3e613cdfe54"],"state_sha256":"b8db5cbde9bfe9bebcd6dbbb160aca4ec779a7937bfa7366de4c8ace7e6e7fda"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"PBjlV/edLCW9K5Q8vjn9OIjhQWm+yzrfymN8bnAzrGi93RoSz9KX0KIZgogU4u5Sf8G7za3YGsAk55UG5p0FBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T11:41:34.873147Z","bundle_sha256":"427b9b508e19d76824ca62bbe0cfd46ac3106e4ebd7f6b1c0a255a06dffa0efc"}}