{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:M25WMBBR7XNFSM4FWYQLX7HM7L","short_pith_number":"pith:M25WMBBR","schema_version":"1.0","canonical_sha256":"66bb660431fdda593385b620bbfcecfaf876200551a1a8a0f4d5a0be92e7f19a","source":{"kind":"arxiv","id":"2109.06024","version":6},"attestation_state":"computed","paper":{"title":"Formalizing and Estimating Distribution Inference Risks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR"],"primary_cat":"cs.LG","authors_text":"Anshuman Suri, David Evans","submitted_at":"2021-09-13T14:54:39Z","abstract_excerpt":"Distribution inference, sometimes called property inference, infers statistical properties about a training set from access to a model trained on that data. Distribution inference attacks can pose serious risks when models are trained on private data, but are difficult to distinguish from the intrinsic purpose of statistical machine learning -- namely, to produce models that capture statistical properties about a distribution. Motivated by Yeom et al.'s membership inference framework, we propose a formal definition of distribution inference attacks that is general enough to describe a broad cl"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2109.06024","kind":"arxiv","version":6},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2021-09-13T14:54:39Z","cross_cats_sorted":["cs.AI","cs.CR"],"title_canon_sha256":"a30fc642c31aed7d8ce46a02bcd577be880ec933f355ffeb5e4641ebfef69721","abstract_canon_sha256":"ce122edafdefbf65aadf9a5b3b77ff0d53a8d9e77cefd905ae9c0504880b9c67"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T04:37:18.409490Z","signature_b64":"nEDGl361lFlCyE4Xjb8Vjc8p+5KEwz5clI1hrqBqJzcNG3N8n/BkBtR/hxAwk1JdB5+CkVjmawkO3sFXMgR6AQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"66bb660431fdda593385b620bbfcecfaf876200551a1a8a0f4d5a0be92e7f19a","last_reissued_at":"2026-07-05T04:37:18.408996Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T04:37:18.408996Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Formalizing and Estimating Distribution Inference Risks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR"],"primary_cat":"cs.LG","authors_text":"Anshuman Suri, David Evans","submitted_at":"2021-09-13T14:54:39Z","abstract_excerpt":"Distribution inference, sometimes called property inference, infers statistical properties about a training set from access to a model trained on that data. Distribution inference attacks can pose serious risks when models are trained on private data, but are difficult to distinguish from the intrinsic purpose of statistical machine learning -- namely, to produce models that capture statistical properties about a distribution. Motivated by Yeom et al.'s membership inference framework, we propose a formal definition of distribution inference attacks that is general enough to describe a broad cl"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2109.06024","kind":"arxiv","version":6},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2109.06024/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2109.06024","created_at":"2026-07-05T04:37:18.409055+00:00"},{"alias_kind":"arxiv_version","alias_value":"2109.06024v6","created_at":"2026-07-05T04:37:18.409055+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2109.06024","created_at":"2026-07-05T04:37:18.409055+00:00"},{"alias_kind":"pith_short_12","alias_value":"M25WMBBR7XNF","created_at":"2026-07-05T04:37:18.409055+00:00"},{"alias_kind":"pith_short_16","alias_value":"M25WMBBR7XNFSM4F","created_at":"2026-07-05T04:37:18.409055+00:00"},{"alias_kind":"pith_short_8","alias_value":"M25WMBBR","created_at":"2026-07-05T04:37:18.409055+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.10217","citing_title":"Alignment Defends LLMs from Property Inference Attacks","ref_index":24,"is_internal_anchor":false},{"citing_arxiv_id":"2606.01719","citing_title":"Fair Finetuning Mitigates Distribution Inference Attacks","ref_index":62,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/M25WMBBR7XNFSM4FWYQLX7HM7L","json":"https://pith.science/pith/M25WMBBR7XNFSM4FWYQLX7HM7L.json","graph_json":"https://pith.science/api/pith-number/M25WMBBR7XNFSM4FWYQLX7HM7L/graph.json","events_json":"https://pith.science/api/pith-number/M25WMBBR7XNFSM4FWYQLX7HM7L/events.json","paper":"https://pith.science/paper/M25WMBBR"},"agent_actions":{"view_html":"https://pith.science/pith/M25WMBBR7XNFSM4FWYQLX7HM7L","download_json":"https://pith.science/pith/M25WMBBR7XNFSM4FWYQLX7HM7L.json","view_paper":"https://pith.science/paper/M25WMBBR","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2109.06024&json=true","fetch_graph":"https://pith.science/api/pith-number/M25WMBBR7XNFSM4FWYQLX7HM7L/graph.json","fetch_events":"https://pith.science/api/pith-number/M25WMBBR7XNFSM4FWYQLX7HM7L/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/M25WMBBR7XNFSM4FWYQLX7HM7L/action/timestamp_anchor","attest_storage":"https://pith.science/pith/M25WMBBR7XNFSM4FWYQLX7HM7L/action/storage_attestation","attest_author":"https://pith.science/pith/M25WMBBR7XNFSM4FWYQLX7HM7L/action/author_attestation","sign_citation":"https://pith.science/pith/M25WMBBR7XNFSM4FWYQLX7HM7L/action/citation_signature","submit_replication":"https://pith.science/pith/M25WMBBR7XNFSM4FWYQLX7HM7L/action/replication_record"}},"created_at":"2026-07-05T04:37:18.409055+00:00","updated_at":"2026-07-05T04:37:18.409055+00:00"}