{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:LBC6N3OXIETTWFUYK2QPHD2I7G","short_pith_number":"pith:LBC6N3OX","schema_version":"1.0","canonical_sha256":"5845e6edd741273b169856a0f38f48f99b8b874f99e10d00d71ee57aba6c88d5","source":{"kind":"arxiv","id":"2508.03703","version":2},"attestation_state":"computed","paper":{"title":"Privacy Risks of LLM-Empowered Recommender Systems: An Inversion Attack Perspective","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.IR","authors_text":"Min Tang, Nuo Shen, Shujie Cui, Weiqing Wang, Yubo Wang","submitted_at":"2025-07-20T05:03:02Z","abstract_excerpt":"The large language model (LLM) powered recommendation paradigm has been proposed to address the limitations of traditional recommender systems, which often struggle to handle cold start users or items with new IDs. Despite its effectiveness, this study uncovers that LLM empowered recommender systems are vulnerable to reconstruction attacks that can expose both system and user privacy. To examine this threat, we present the first systematic study on inversion attacks targeting LLM empowered recommender systems, where adversaries attempt to reconstruct original prompts that contain personal pref"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2508.03703","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.IR","submitted_at":"2025-07-20T05:03:02Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"dfbfa7274ccb63fbcd72d1e87826bfb1a553ae2a1097e3727585eae6d9aea4d0","abstract_canon_sha256":"125c4f83292f417c7f3344c7de856b3a156c7b07f5e0a84fe70827fb27a271db"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T12:09:45.678516Z","signature_b64":"Q12mxHjWzDXiLhwbTxhFOjwsSjg6clybWfGFj0vBME964eWsddQxnc2KUfGGcaIPUqrR/MbRhg2hrSuGvznOAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5845e6edd741273b169856a0f38f48f99b8b874f99e10d00d71ee57aba6c88d5","last_reissued_at":"2026-07-05T12:09:45.678025Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T12:09:45.678025Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Privacy Risks of LLM-Empowered Recommender Systems: An Inversion Attack Perspective","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.IR","authors_text":"Min Tang, Nuo Shen, Shujie Cui, Weiqing Wang, Yubo Wang","submitted_at":"2025-07-20T05:03:02Z","abstract_excerpt":"The large language model (LLM) powered recommendation paradigm has been proposed to address the limitations of traditional recommender systems, which often struggle to handle cold start users or items with new IDs. Despite its effectiveness, this study uncovers that LLM empowered recommender systems are vulnerable to reconstruction attacks that can expose both system and user privacy. To examine this threat, we present the first systematic study on inversion attacks targeting LLM empowered recommender systems, where adversaries attempt to reconstruct original prompts that contain personal pref"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.03703","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2508.03703/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2508.03703","created_at":"2026-07-05T12:09:45.678080+00:00"},{"alias_kind":"arxiv_version","alias_value":"2508.03703v2","created_at":"2026-07-05T12:09:45.678080+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.03703","created_at":"2026-07-05T12:09:45.678080+00:00"},{"alias_kind":"pith_short_12","alias_value":"LBC6N3OXIETT","created_at":"2026-07-05T12:09:45.678080+00:00"},{"alias_kind":"pith_short_16","alias_value":"LBC6N3OXIETTWFUY","created_at":"2026-07-05T12:09:45.678080+00:00"},{"alias_kind":"pith_short_8","alias_value":"LBC6N3OX","created_at":"2026-07-05T12:09:45.678080+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2608.03272","citing_title":"Attacking and Defending Multi-Agent Collaborative Filtering Systems Through Connectivity","ref_index":51,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/LBC6N3OXIETTWFUYK2QPHD2I7G","json":"https://pith.science/pith/LBC6N3OXIETTWFUYK2QPHD2I7G.json","graph_json":"https://pith.science/api/pith-number/LBC6N3OXIETTWFUYK2QPHD2I7G/graph.json","events_json":"https://pith.science/api/pith-number/LBC6N3OXIETTWFUYK2QPHD2I7G/events.json","paper":"https://pith.science/paper/LBC6N3OX"},"agent_actions":{"view_html":"https://pith.science/pith/LBC6N3OXIETTWFUYK2QPHD2I7G","download_json":"https://pith.science/pith/LBC6N3OXIETTWFUYK2QPHD2I7G.json","view_paper":"https://pith.science/paper/LBC6N3OX","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2508.03703&json=true","fetch_graph":"https://pith.science/api/pith-number/LBC6N3OXIETTWFUYK2QPHD2I7G/graph.json","fetch_events":"https://pith.science/api/pith-number/LBC6N3OXIETTWFUYK2QPHD2I7G/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/LBC6N3OXIETTWFUYK2QPHD2I7G/action/timestamp_anchor","attest_storage":"https://pith.science/pith/LBC6N3OXIETTWFUYK2QPHD2I7G/action/storage_attestation","attest_author":"https://pith.science/pith/LBC6N3OXIETTWFUYK2QPHD2I7G/action/author_attestation","sign_citation":"https://pith.science/pith/LBC6N3OXIETTWFUYK2QPHD2I7G/action/citation_signature","submit_replication":"https://pith.science/pith/LBC6N3OXIETTWFUYK2QPHD2I7G/action/replication_record"}},"created_at":"2026-07-05T12:09:45.678080+00:00","updated_at":"2026-07-05T12:09:45.678080+00:00"}