{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2017:LWZODFKBKBVKIAOYIKEF7L2B4Z","short_pith_number":"pith:LWZODFKB","canonical_record":{"source":{"id":"1711.07221","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-11-20T09:33:45Z","cross_cats_sorted":["cs.CR","cs.DC"],"title_canon_sha256":"e9424a3dcb906a254295447af714c45a7b3ffbd792436d78a3ff9fcdec516156","abstract_canon_sha256":"2e143c84e344a10ebbcdd59f5188905aa51eb2e2b8fd4f3a609e3a60b81cebd2"},"schema_version":"1.0"},"canonical_sha256":"5db2e19541506aa401d842885faf41e674d5945a29d7dd807edd93ddc0ef4b0a","source":{"kind":"arxiv","id":"1711.07221","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1711.07221","created_at":"2026-05-18T00:30:10Z"},{"alias_kind":"arxiv_version","alias_value":"1711.07221v1","created_at":"2026-05-18T00:30:10Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1711.07221","created_at":"2026-05-18T00:30:10Z"},{"alias_kind":"pith_short_12","alias_value":"LWZODFKBKBVK","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_16","alias_value":"LWZODFKBKBVKIAOY","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_8","alias_value":"LWZODFKB","created_at":"2026-05-18T12:31:28Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2017:LWZODFKBKBVKIAOYIKEF7L2B4Z","target":"record","payload":{"canonical_record":{"source":{"id":"1711.07221","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-11-20T09:33:45Z","cross_cats_sorted":["cs.CR","cs.DC"],"title_canon_sha256":"e9424a3dcb906a254295447af714c45a7b3ffbd792436d78a3ff9fcdec516156","abstract_canon_sha256":"2e143c84e344a10ebbcdd59f5188905aa51eb2e2b8fd4f3a609e3a60b81cebd2"},"schema_version":"1.0"},"canonical_sha256":"5db2e19541506aa401d842885faf41e674d5945a29d7dd807edd93ddc0ef4b0a","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:30:10.852574Z","signature_b64":"usS9YtVZnsm6BZrIW2Z1aXObC/cDwVaZSzyzq6BH+J1UfI6OifjtxVKVuLFSKGt5DiRFd4Tp8JXF+L1WAgJkBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5db2e19541506aa401d842885faf41e674d5945a29d7dd807edd93ddc0ef4b0a","last_reissued_at":"2026-05-18T00:30:10.851802Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:30:10.851802Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1711.07221","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:30:10Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wdSCKzdZwq2rIHzqtIR3LllvC6S0VgwHxsCH8xDcdjhsFjRj88sBV9KqqU+f+dWc7ALxEP5p1z8pI0WE2TyTBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T23:35:11.533418Z"},"content_sha256":"179725553ce5b7ae06b10c52c76d70ebdc9825f2e8760e200b545ca861667408","schema_version":"1.0","event_id":"sha256:179725553ce5b7ae06b10c52c76d70ebdc9825f2e8760e200b545ca861667408"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2017:LWZODFKBKBVKIAOYIKEF7L2B4Z","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Model Extraction Warning in MLaaS Paradigm","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.DC"],"primary_cat":"cs.LG","authors_text":"Bhaskar Mukhoty, Manish Kesarwani, Sameep Mehta, Vijay Arya","submitted_at":"2017-11-20T09:33:45Z","abstract_excerpt":"Cloud vendors are increasingly offering machine learning services as part of their platform and services portfolios. These services enable the deployment of machine learning models on the cloud that are offered on a pay-per-query basis to application developers and end users. However recent work has shown that the hosted models are susceptible to extraction attacks. Adversaries may launch queries to steal the model and compromise future query payments or privacy of the training data. In this work, we present a cloud-based extraction monitor that can quantify the extraction status of models by "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1711.07221","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:30:10Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"l8/HpetaHfoSLHFdzDt5uJFQXI9SlOcUmcCMe0CXMe4w57u/FMzv0HVh9r7K7F/Ol3sr68SjlmMl8JD+S72iBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T23:35:11.534031Z"},"content_sha256":"f50b4d078d0628e4097c03bd23cd56b7ae82fea92acd6755bfcab56b4d26166b","schema_version":"1.0","event_id":"sha256:f50b4d078d0628e4097c03bd23cd56b7ae82fea92acd6755bfcab56b4d26166b"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/LWZODFKBKBVKIAOYIKEF7L2B4Z/bundle.json","state_url":"https://pith.science/pith/LWZODFKBKBVKIAOYIKEF7L2B4Z/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/LWZODFKBKBVKIAOYIKEF7L2B4Z/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-10T23:35:11Z","links":{"resolver":"https://pith.science/pith/LWZODFKBKBVKIAOYIKEF7L2B4Z","bundle":"https://pith.science/pith/LWZODFKBKBVKIAOYIKEF7L2B4Z/bundle.json","state":"https://pith.science/pith/LWZODFKBKBVKIAOYIKEF7L2B4Z/state.json","well_known_bundle":"https://pith.science/.well-known/pith/LWZODFKBKBVKIAOYIKEF7L2B4Z/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2017:LWZODFKBKBVKIAOYIKEF7L2B4Z","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"2e143c84e344a10ebbcdd59f5188905aa51eb2e2b8fd4f3a609e3a60b81cebd2","cross_cats_sorted":["cs.CR","cs.DC"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-11-20T09:33:45Z","title_canon_sha256":"e9424a3dcb906a254295447af714c45a7b3ffbd792436d78a3ff9fcdec516156"},"schema_version":"1.0","source":{"id":"1711.07221","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1711.07221","created_at":"2026-05-18T00:30:10Z"},{"alias_kind":"arxiv_version","alias_value":"1711.07221v1","created_at":"2026-05-18T00:30:10Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1711.07221","created_at":"2026-05-18T00:30:10Z"},{"alias_kind":"pith_short_12","alias_value":"LWZODFKBKBVK","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_16","alias_value":"LWZODFKBKBVKIAOY","created_at":"2026-05-18T12:31:28Z"},{"alias_kind":"pith_short_8","alias_value":"LWZODFKB","created_at":"2026-05-18T12:31:28Z"}],"graph_snapshots":[{"event_id":"sha256:f50b4d078d0628e4097c03bd23cd56b7ae82fea92acd6755bfcab56b4d26166b","target":"graph","created_at":"2026-05-18T00:30:10Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Cloud vendors are increasingly offering machine learning services as part of their platform and services portfolios. These services enable the deployment of machine learning models on the cloud that are offered on a pay-per-query basis to application developers and end users. However recent work has shown that the hosted models are susceptible to extraction attacks. Adversaries may launch queries to steal the model and compromise future query payments or privacy of the training data. In this work, we present a cloud-based extraction monitor that can quantify the extraction status of models by ","authors_text":"Bhaskar Mukhoty, Manish Kesarwani, Sameep Mehta, Vijay Arya","cross_cats":["cs.CR","cs.DC"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-11-20T09:33:45Z","title":"Model Extraction Warning in MLaaS Paradigm"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1711.07221","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:179725553ce5b7ae06b10c52c76d70ebdc9825f2e8760e200b545ca861667408","target":"record","created_at":"2026-05-18T00:30:10Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"2e143c84e344a10ebbcdd59f5188905aa51eb2e2b8fd4f3a609e3a60b81cebd2","cross_cats_sorted":["cs.CR","cs.DC"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2017-11-20T09:33:45Z","title_canon_sha256":"e9424a3dcb906a254295447af714c45a7b3ffbd792436d78a3ff9fcdec516156"},"schema_version":"1.0","source":{"id":"1711.07221","kind":"arxiv","version":1}},"canonical_sha256":"5db2e19541506aa401d842885faf41e674d5945a29d7dd807edd93ddc0ef4b0a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"5db2e19541506aa401d842885faf41e674d5945a29d7dd807edd93ddc0ef4b0a","first_computed_at":"2026-05-18T00:30:10.851802Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:30:10.851802Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"usS9YtVZnsm6BZrIW2Z1aXObC/cDwVaZSzyzq6BH+J1UfI6OifjtxVKVuLFSKGt5DiRFd4Tp8JXF+L1WAgJkBQ==","signature_status":"signed_v1","signed_at":"2026-05-18T00:30:10.852574Z","signed_message":"canonical_sha256_bytes"},"source_id":"1711.07221","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:179725553ce5b7ae06b10c52c76d70ebdc9825f2e8760e200b545ca861667408","sha256:f50b4d078d0628e4097c03bd23cd56b7ae82fea92acd6755bfcab56b4d26166b"],"state_sha256":"98261e6177582c1f49697aa0582dec99d8b34afa6f1e9531d43842be0ec8d7a8"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8eMl6OOqklLmEFGx8FIjn1QzduIjN60h+D+8ybRb2cSjQon+CfJqwdqTPsgGLWrA4VoBHrR5qsFsMreaypdTDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-10T23:35:11.537560Z","bundle_sha256":"0ea1eb17b838e7dd21c390024620ed92dadea857b88c3d2f2bc90b4d7292ff17"}}