{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:MD45NO7SH4IJUV5JLG7OO2AMFO","short_pith_number":"pith:MD45NO7S","schema_version":"1.0","canonical_sha256":"60f9d6bbf23f109a57a959bee7680c2b93a704fc7b8997bf96f864b3e4f83740","source":{"kind":"arxiv","id":"2606.11698","version":1},"attestation_state":"computed","paper":{"title":"T2S: A Rehearsal-Based Approach for Extraction-Resistant Model Watermarking","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ao Yao, Jian-Ping Mei, Jie Xiao, Tiantian Zhu, Weibin Zhang","submitted_at":"2026-06-10T06:22:40Z","abstract_excerpt":"Model watermarking safeguards AI model intellectual property by embedding distinctive knowledge that induces unique behavioral signatures. The primary technical challenge lies in ensuring watermark robustness against various post-processing attacks on the watermarked model. Model extraction attacks emerge as the most severe threat, where adversaries exploit prediction outputs to train surrogate models that illegally replicate the original model's functionality. In this work, we propose a rehearsal-based watermark embedding framework to enhance the robustness of model watermarks against model e"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2606.11698","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T06:22:40Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"ec7d1de320ae98f94918a40a10190dfb4b0b642660281896e962422f7274c43a","abstract_canon_sha256":"c46fd73abeb1393f81eb6dd0cd38c59fbbfcb41c43081fbcad4a932ae3568044"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-11T01:10:03.511405Z","signature_b64":"/XEcf/xjubbs8a/HireHETKolgBKuLvUuzofHYe53d7onxS4BrWatyhGRh22+PMQVX/Nm1glKY1yvcKsn24nBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"60f9d6bbf23f109a57a959bee7680c2b93a704fc7b8997bf96f864b3e4f83740","last_reissued_at":"2026-06-11T01:10:03.510637Z","signature_status":"signed_v1","first_computed_at":"2026-06-11T01:10:03.510637Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"T2S: A Rehearsal-Based Approach for Extraction-Resistant Model Watermarking","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ao Yao, Jian-Ping Mei, Jie Xiao, Tiantian Zhu, Weibin Zhang","submitted_at":"2026-06-10T06:22:40Z","abstract_excerpt":"Model watermarking safeguards AI model intellectual property by embedding distinctive knowledge that induces unique behavioral signatures. The primary technical challenge lies in ensuring watermark robustness against various post-processing attacks on the watermarked model. Model extraction attacks emerge as the most severe threat, where adversaries exploit prediction outputs to train surrogate models that illegally replicate the original model's functionality. In this work, we propose a rehearsal-based watermark embedding framework to enhance the robustness of model watermarks against model e"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.11698","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.11698/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2606.11698","created_at":"2026-06-11T01:10:03.510761+00:00"},{"alias_kind":"arxiv_version","alias_value":"2606.11698v1","created_at":"2026-06-11T01:10:03.510761+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.11698","created_at":"2026-06-11T01:10:03.510761+00:00"},{"alias_kind":"pith_short_12","alias_value":"MD45NO7SH4IJ","created_at":"2026-06-11T01:10:03.510761+00:00"},{"alias_kind":"pith_short_16","alias_value":"MD45NO7SH4IJUV5J","created_at":"2026-06-11T01:10:03.510761+00:00"},{"alias_kind":"pith_short_8","alias_value":"MD45NO7S","created_at":"2026-06-11T01:10:03.510761+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/MD45NO7SH4IJUV5JLG7OO2AMFO","json":"https://pith.science/pith/MD45NO7SH4IJUV5JLG7OO2AMFO.json","graph_json":"https://pith.science/api/pith-number/MD45NO7SH4IJUV5JLG7OO2AMFO/graph.json","events_json":"https://pith.science/api/pith-number/MD45NO7SH4IJUV5JLG7OO2AMFO/events.json","paper":"https://pith.science/paper/MD45NO7S"},"agent_actions":{"view_html":"https://pith.science/pith/MD45NO7SH4IJUV5JLG7OO2AMFO","download_json":"https://pith.science/pith/MD45NO7SH4IJUV5JLG7OO2AMFO.json","view_paper":"https://pith.science/paper/MD45NO7S","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2606.11698&json=true","fetch_graph":"https://pith.science/api/pith-number/MD45NO7SH4IJUV5JLG7OO2AMFO/graph.json","fetch_events":"https://pith.science/api/pith-number/MD45NO7SH4IJUV5JLG7OO2AMFO/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/MD45NO7SH4IJUV5JLG7OO2AMFO/action/timestamp_anchor","attest_storage":"https://pith.science/pith/MD45NO7SH4IJUV5JLG7OO2AMFO/action/storage_attestation","attest_author":"https://pith.science/pith/MD45NO7SH4IJUV5JLG7OO2AMFO/action/author_attestation","sign_citation":"https://pith.science/pith/MD45NO7SH4IJUV5JLG7OO2AMFO/action/citation_signature","submit_replication":"https://pith.science/pith/MD45NO7SH4IJUV5JLG7OO2AMFO/action/replication_record"}},"created_at":"2026-06-11T01:10:03.510761+00:00","updated_at":"2026-06-11T01:10:03.510761+00:00"}