{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:L5CMHKT2Y4KOHDR2ZFIAD2DGAX","short_pith_number":"pith:L5CMHKT2","schema_version":"1.0","canonical_sha256":"5f44c3aa7ac714e38e3ac95001e86605f19526db52d76212ee3cc9a6d328046d","source":{"kind":"arxiv","id":"2505.13758","version":1},"attestation_state":"computed","paper":{"title":"BeamClean: Language Aware Embedding Reconstruction","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Jay Roberts, Kaan Kale, Kyle Mylonakis, Sidhartha Roy","submitted_at":"2025-05-19T22:14:22Z","abstract_excerpt":"In this work, we consider an inversion attack on the obfuscated input embeddings sent to a language model on a server, where the adversary has no access to the language model or the obfuscation mechanism and sees only the obfuscated embeddings along with the model's embedding table. We propose BeamClean, an inversion attack that jointly estimates the noise parameters and decodes token sequences by integrating a language-model prior. Against Laplacian and Gaussian obfuscation mechanisms, BeamClean always surpasses naive distance-based attacks. This work highlights the necessity for and robustne"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2505.13758","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2025-05-19T22:14:22Z","cross_cats_sorted":[],"title_canon_sha256":"26141d1883f02fef7cb525f0c445f86a8dc0aebf57d6f9f62f7ce70355088ef8","abstract_canon_sha256":"87c220851e232179bc1dad6144f43c096100e064bf483eb0e08a37c950cca039"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:05:50.685369Z","signature_b64":"PRLVYemAP8TdgREt6LoDbmfFZKIR0APDZbfmPjP+5AzyMbTUxHU5BFkvJHEpXskWNbahMS6Xm00ah3BJAARvDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5f44c3aa7ac714e38e3ac95001e86605f19526db52d76212ee3cc9a6d328046d","last_reissued_at":"2026-07-05T11:05:50.684854Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:05:50.684854Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"BeamClean: Language Aware Embedding Reconstruction","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Jay Roberts, Kaan Kale, Kyle Mylonakis, Sidhartha Roy","submitted_at":"2025-05-19T22:14:22Z","abstract_excerpt":"In this work, we consider an inversion attack on the obfuscated input embeddings sent to a language model on a server, where the adversary has no access to the language model or the obfuscation mechanism and sees only the obfuscated embeddings along with the model's embedding table. We propose BeamClean, an inversion attack that jointly estimates the noise parameters and decodes token sequences by integrating a language-model prior. Against Laplacian and Gaussian obfuscation mechanisms, BeamClean always surpasses naive distance-based attacks. This work highlights the necessity for and robustne"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2505.13758","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2505.13758/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2505.13758","created_at":"2026-07-05T11:05:50.684907+00:00"},{"alias_kind":"arxiv_version","alias_value":"2505.13758v1","created_at":"2026-07-05T11:05:50.684907+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2505.13758","created_at":"2026-07-05T11:05:50.684907+00:00"},{"alias_kind":"pith_short_12","alias_value":"L5CMHKT2Y4KO","created_at":"2026-07-05T11:05:50.684907+00:00"},{"alias_kind":"pith_short_16","alias_value":"L5CMHKT2Y4KOHDR2","created_at":"2026-07-05T11:05:50.684907+00:00"},{"alias_kind":"pith_short_8","alias_value":"L5CMHKT2","created_at":"2026-07-05T11:05:50.684907+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2506.09452","citing_title":"Learning Obfuscations Of LLM Embedding Sequences: Stained Glass Transform","ref_index":38,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/L5CMHKT2Y4KOHDR2ZFIAD2DGAX","json":"https://pith.science/pith/L5CMHKT2Y4KOHDR2ZFIAD2DGAX.json","graph_json":"https://pith.science/api/pith-number/L5CMHKT2Y4KOHDR2ZFIAD2DGAX/graph.json","events_json":"https://pith.science/api/pith-number/L5CMHKT2Y4KOHDR2ZFIAD2DGAX/events.json","paper":"https://pith.science/paper/L5CMHKT2"},"agent_actions":{"view_html":"https://pith.science/pith/L5CMHKT2Y4KOHDR2ZFIAD2DGAX","download_json":"https://pith.science/pith/L5CMHKT2Y4KOHDR2ZFIAD2DGAX.json","view_paper":"https://pith.science/paper/L5CMHKT2","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2505.13758&json=true","fetch_graph":"https://pith.science/api/pith-number/L5CMHKT2Y4KOHDR2ZFIAD2DGAX/graph.json","fetch_events":"https://pith.science/api/pith-number/L5CMHKT2Y4KOHDR2ZFIAD2DGAX/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/L5CMHKT2Y4KOHDR2ZFIAD2DGAX/action/timestamp_anchor","attest_storage":"https://pith.science/pith/L5CMHKT2Y4KOHDR2ZFIAD2DGAX/action/storage_attestation","attest_author":"https://pith.science/pith/L5CMHKT2Y4KOHDR2ZFIAD2DGAX/action/author_attestation","sign_citation":"https://pith.science/pith/L5CMHKT2Y4KOHDR2ZFIAD2DGAX/action/citation_signature","submit_replication":"https://pith.science/pith/L5CMHKT2Y4KOHDR2ZFIAD2DGAX/action/replication_record"}},"created_at":"2026-07-05T11:05:50.684907+00:00","updated_at":"2026-07-05T11:05:50.684907+00:00"}