{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:LESCISH6LWVR5FFQLNT2QJNF4Z","short_pith_number":"pith:LESCISH6","canonical_record":{"source":{"id":"2605.17341","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/publicdomain/zero/1.0/","primary_cat":"cs.CV","submitted_at":"2026-05-17T09:21:11Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"dbbff53f3c71e1d5ac7f2e4b7eca3cdf443f78af57ee6bcb85cde2f30ae1edae","abstract_canon_sha256":"19a64aedfecadbf22ef6d19d9d6c9d9548803d1287e681991713d6150262effd"},"schema_version":"1.0"},"canonical_sha256":"59242448fe5dab1e94b05b67a825a5e6677095d7e138f30fcb61a4cd457f2a8a","source":{"kind":"arxiv","id":"2605.17341","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.17341","created_at":"2026-05-20T00:03:53Z"},{"alias_kind":"arxiv_version","alias_value":"2605.17341v1","created_at":"2026-05-20T00:03:53Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.17341","created_at":"2026-05-20T00:03:53Z"},{"alias_kind":"pith_short_12","alias_value":"LESCISH6LWVR","created_at":"2026-05-20T00:03:53Z"},{"alias_kind":"pith_short_16","alias_value":"LESCISH6LWVR5FFQ","created_at":"2026-05-20T00:03:53Z"},{"alias_kind":"pith_short_8","alias_value":"LESCISH6","created_at":"2026-05-20T00:03:53Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:LESCISH6LWVR5FFQLNT2QJNF4Z","target":"record","payload":{"canonical_record":{"source":{"id":"2605.17341","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/publicdomain/zero/1.0/","primary_cat":"cs.CV","submitted_at":"2026-05-17T09:21:11Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"dbbff53f3c71e1d5ac7f2e4b7eca3cdf443f78af57ee6bcb85cde2f30ae1edae","abstract_canon_sha256":"19a64aedfecadbf22ef6d19d9d6c9d9548803d1287e681991713d6150262effd"},"schema_version":"1.0"},"canonical_sha256":"59242448fe5dab1e94b05b67a825a5e6677095d7e138f30fcb61a4cd457f2a8a","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-20T00:03:53.138903Z","signature_b64":"ZCuRu7Qr6LFsIlvLD+Cfisulj51rnvebOrH57R/sdHbYJRJmEL4W7CBmErXrqXeH+krBPiU1xuQiStiGNSiGCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"59242448fe5dab1e94b05b67a825a5e6677095d7e138f30fcb61a4cd457f2a8a","last_reissued_at":"2026-05-20T00:03:53.138035Z","signature_status":"signed_v1","first_computed_at":"2026-05-20T00:03:53.138035Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.17341","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:03:53Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"BpBGDhTpZMq7mH5GJ+rOIIbtCDWljqb1TJrAnGySl3PjtSwsh+bG304YpBNLuiK0TyIdjvZdquNg+kH6+84lBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-21T09:31:54.433950Z"},"content_sha256":"8696ee2063b60002b7fe24c7e6c3216c8f6321c88cb74dbb663befa021a63a35","schema_version":"1.0","event_id":"sha256:8696ee2063b60002b7fe24c7e6c3216c8f6321c88cb74dbb663befa021a63a35"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:LESCISH6LWVR5FFQLNT2QJNF4Z","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Single-Sample Black-Box Membership Inference Attack against Vision-Language Models via Cross-modal Semantic Alignment","license":"http://creativecommons.org/publicdomain/zero/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CV","authors_text":"Chao Liang, Gang Wu, Jiaqing Li, Xiaochuan Shi, Yajuan Lu, Zhongyuan Wang","submitted_at":"2026-05-17T09:21:11Z","abstract_excerpt":"Vision-Language Models (VLMs) have achieved remarkable success, yet their reliance on massive datasets and unintended memorization of training data raise significant data security risk. Membership Inference Attacks (MIAs) aim to assess these risks by determining whether a data sample was included in a model's training set. However, existing MIA methods against VLMs face critical bottlenecks: gray-box method relies on internal logits that are typically restricted in real-world Application Programming Interfaces (APIs), while black-box method depends on large-scale statistical distributions, whi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.17341","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.17341/integrity.json","findings":[],"available":true,"detectors_run":[{"name":"claim_evidence","ran_at":"2026-05-19T21:41:57.801749Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"ai_meta_artifact","ran_at":"2026-05-19T21:33:23.737277Z","status":"skipped","version":"1.0.0","findings_count":0}],"snapshot_sha256":"d9a3d5f9b21a1d244a2730fb5de82d036ff535201907bb6c8e266d6b3d2a712b"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:03:53Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jtL2IHKjyOx5MWNXvyZ5pWEOMtaNlXOGb6uqh4orMBqIzuRuTzPrv2y0uNiNSntF3TLm5RHXizCuXf6pqTFLDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-21T09:31:54.434670Z"},"content_sha256":"51353dc0630b082f561826dff665145f15401b54c06442925ab0d36522caff46","schema_version":"1.0","event_id":"sha256:51353dc0630b082f561826dff665145f15401b54c06442925ab0d36522caff46"},{"event_type":"integrity_finding","subject_pith_number":"pith:2026:LESCISH6LWVR5FFQLNT2QJNF4Z","target":"integrity","payload":{"note":"Identifier '10.5555/3495724.3495883' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","snippet":"Tom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah, Jared Kaplan, Prafulla Dhariwal, Arvind Neelakantan, Pranav Shyam, Girish Sastry, Amanda Askell, Sandhini Agarwal, Ariel Herbert-V oss, Gretchen Krueger, Tom Henighan, Rewon Child, A","arxiv_id":"2605.17341","detector":"doi_compliance","evidence":{"doi":"10.5555/3495724.3495883","arxiv_id":null,"ref_index":5,"raw_excerpt":"Tom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah, Jared Kaplan, Prafulla Dhariwal, Arvind Neelakantan, Pranav Shyam, Girish Sastry, Amanda Askell, Sandhini Agarwal, Ariel Herbert-V oss, Gretchen Krueger, Tom Henighan, Rewon Child, Aditya Ramesh, Daniel M. Ziegler, Jeffrey Wu, Clemens Winter, Christo- pher Hesse, Mark Chen, Eric Sigler, Mateusz Litwin, Scott Gray, Benjamin Chess, Jack Clark","verdict_class":"cross_source","checked_sources":["crossref_by_doi","openalex_by_doi","doi_org_head"]},"severity":"critical","ref_index":5,"audited_at":"2026-05-20T14:12:39.819099Z","event_type":"pith.integrity.v1","detected_doi":"10.5555/3495724.3495883","detector_url":"https://pith.science/pith-integrity-protocol#doi_compliance","external_url":null,"finding_type":"unresolvable_identifier","evidence_hash":"0011b336864d71fa94f5638bd4abbb0deac42ef68eba71ad10e986724a965ca1","paper_version":1,"verdict_class":"cross_source","resolved_title":null,"detector_version":"1.0.0","detected_arxiv_id":null,"integrity_event_id":5197,"payload_sha256":"707ec28e432827a39aff69298aef6822c203e512fc6b6504a394434bfdcefe25","signature_b64":"0We8LNh4tSvnEeUWKz18Z7O3gQuLqF9OJBBcllhF2YSBZTgWeYpCVlDaMBy4ADu96OzNNg/mMa7UKoit4tKIBg==","signing_key_id":"pith-v1-2026-05"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T14:13:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"l2lFN+SCUmKrm5ISqNqnFRu5aBPbA4VK30O6fxb+QE0YCRJIu65A1xzikMLQtP9YnOwWSbU0Nqv/lMxciX81CQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-21T09:31:54.435897Z"},"content_sha256":"a4e47bb916f289b7abfbbdbe5c06950fa223094d499b06a6eb2fb1989b8f1cbe","schema_version":"1.0","event_id":"sha256:a4e47bb916f289b7abfbbdbe5c06950fa223094d499b06a6eb2fb1989b8f1cbe"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/LESCISH6LWVR5FFQLNT2QJNF4Z/bundle.json","state_url":"https://pith.science/pith/LESCISH6LWVR5FFQLNT2QJNF4Z/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/LESCISH6LWVR5FFQLNT2QJNF4Z/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-21T09:31:54Z","links":{"resolver":"https://pith.science/pith/LESCISH6LWVR5FFQLNT2QJNF4Z","bundle":"https://pith.science/pith/LESCISH6LWVR5FFQLNT2QJNF4Z/bundle.json","state":"https://pith.science/pith/LESCISH6LWVR5FFQLNT2QJNF4Z/state.json","well_known_bundle":"https://pith.science/.well-known/pith/LESCISH6LWVR5FFQLNT2QJNF4Z/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:LESCISH6LWVR5FFQLNT2QJNF4Z","merge_version":"pith-open-graph-merge-v1","event_count":3,"valid_event_count":3,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"19a64aedfecadbf22ef6d19d9d6c9d9548803d1287e681991713d6150262effd","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/publicdomain/zero/1.0/","primary_cat":"cs.CV","submitted_at":"2026-05-17T09:21:11Z","title_canon_sha256":"dbbff53f3c71e1d5ac7f2e4b7eca3cdf443f78af57ee6bcb85cde2f30ae1edae"},"schema_version":"1.0","source":{"id":"2605.17341","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.17341","created_at":"2026-05-20T00:03:53Z"},{"alias_kind":"arxiv_version","alias_value":"2605.17341v1","created_at":"2026-05-20T00:03:53Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.17341","created_at":"2026-05-20T00:03:53Z"},{"alias_kind":"pith_short_12","alias_value":"LESCISH6LWVR","created_at":"2026-05-20T00:03:53Z"},{"alias_kind":"pith_short_16","alias_value":"LESCISH6LWVR5FFQ","created_at":"2026-05-20T00:03:53Z"},{"alias_kind":"pith_short_8","alias_value":"LESCISH6","created_at":"2026-05-20T00:03:53Z"}],"graph_snapshots":[{"event_id":"sha256:51353dc0630b082f561826dff665145f15401b54c06442925ab0d36522caff46","target":"graph","created_at":"2026-05-20T00:03:53Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"claim_evidence","ran_at":"2026-05-19T21:41:57.801749Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"ai_meta_artifact","ran_at":"2026-05-19T21:33:23.737277Z","status":"skipped","version":"1.0.0"}],"endpoint":"/pith/2605.17341/integrity.json","findings":[],"snapshot_sha256":"d9a3d5f9b21a1d244a2730fb5de82d036ff535201907bb6c8e266d6b3d2a712b","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Vision-Language Models (VLMs) have achieved remarkable success, yet their reliance on massive datasets and unintended memorization of training data raise significant data security risk. Membership Inference Attacks (MIAs) aim to assess these risks by determining whether a data sample was included in a model's training set. However, existing MIA methods against VLMs face critical bottlenecks: gray-box method relies on internal logits that are typically restricted in real-world Application Programming Interfaces (APIs), while black-box method depends on large-scale statistical distributions, whi","authors_text":"Chao Liang, Gang Wu, Jiaqing Li, Xiaochuan Shi, Yajuan Lu, Zhongyuan Wang","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/publicdomain/zero/1.0/","primary_cat":"cs.CV","submitted_at":"2026-05-17T09:21:11Z","title":"Single-Sample Black-Box Membership Inference Attack against Vision-Language Models via Cross-modal Semantic Alignment"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.17341","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8696ee2063b60002b7fe24c7e6c3216c8f6321c88cb74dbb663befa021a63a35","target":"record","created_at":"2026-05-20T00:03:53Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"19a64aedfecadbf22ef6d19d9d6c9d9548803d1287e681991713d6150262effd","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/publicdomain/zero/1.0/","primary_cat":"cs.CV","submitted_at":"2026-05-17T09:21:11Z","title_canon_sha256":"dbbff53f3c71e1d5ac7f2e4b7eca3cdf443f78af57ee6bcb85cde2f30ae1edae"},"schema_version":"1.0","source":{"id":"2605.17341","kind":"arxiv","version":1}},"canonical_sha256":"59242448fe5dab1e94b05b67a825a5e6677095d7e138f30fcb61a4cd457f2a8a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"59242448fe5dab1e94b05b67a825a5e6677095d7e138f30fcb61a4cd457f2a8a","first_computed_at":"2026-05-20T00:03:53.138035Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:03:53.138035Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"ZCuRu7Qr6LFsIlvLD+Cfisulj51rnvebOrH57R/sdHbYJRJmEL4W7CBmErXrqXeH+krBPiU1xuQiStiGNSiGCA==","signature_status":"signed_v1","signed_at":"2026-05-20T00:03:53.138903Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.17341","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8696ee2063b60002b7fe24c7e6c3216c8f6321c88cb74dbb663befa021a63a35","sha256:51353dc0630b082f561826dff665145f15401b54c06442925ab0d36522caff46","sha256:a4e47bb916f289b7abfbbdbe5c06950fa223094d499b06a6eb2fb1989b8f1cbe"],"state_sha256":"b9c7c6f3c0ba2908b0fbdfe741c5a385c9d6dcd920bf7a47501fe508225b13d7"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"oq0BB9U/s7+pFFjuB5sFRu2xKju7aHbmePF41UTUD/LggMDzpfulkrBTr3xKrEyrf3EjPdzrAjmr3+ZuTKOeAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-21T09:31:54.438969Z","bundle_sha256":"060c35dc8f3fe1bc28b5d5ba6d78067554e0ed81275abc0c665af7217bd4ccaf"}}