{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:ML6USHAUOFI3NLW5BCCAYJ5ATT","short_pith_number":"pith:ML6USHAU","canonical_record":{"source":{"id":"1812.05725","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-12-13T23:06:39Z","cross_cats_sorted":[],"title_canon_sha256":"9ab9d8ad3a8ca1cb8648c7914eb026548d7d1f8bfbd9dee443fdc015d7da9220","abstract_canon_sha256":"603b346f35edb244d51ecd6a7fd1a399b1a877e723c4e1f97fc7e977da8f57c2"},"schema_version":"1.0"},"canonical_sha256":"62fd491c147151b6aedd08840c27a09cdf41ba07e883d883b3624ddad41eaf24","source":{"kind":"arxiv","id":"1812.05725","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.05725","created_at":"2026-05-17T23:58:18Z"},{"alias_kind":"arxiv_version","alias_value":"1812.05725v1","created_at":"2026-05-17T23:58:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.05725","created_at":"2026-05-17T23:58:18Z"},{"alias_kind":"pith_short_12","alias_value":"ML6USHAUOFI3","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_16","alias_value":"ML6USHAUOFI3NLW5","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_8","alias_value":"ML6USHAU","created_at":"2026-05-18T12:32:37Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:ML6USHAUOFI3NLW5BCCAYJ5ATT","target":"record","payload":{"canonical_record":{"source":{"id":"1812.05725","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-12-13T23:06:39Z","cross_cats_sorted":[],"title_canon_sha256":"9ab9d8ad3a8ca1cb8648c7914eb026548d7d1f8bfbd9dee443fdc015d7da9220","abstract_canon_sha256":"603b346f35edb244d51ecd6a7fd1a399b1a877e723c4e1f97fc7e977da8f57c2"},"schema_version":"1.0"},"canonical_sha256":"62fd491c147151b6aedd08840c27a09cdf41ba07e883d883b3624ddad41eaf24","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:58:18.424602Z","signature_b64":"B3AurGZWZo7P+D5sMcm+02e4UXd4o0zen3Iskl+AiwZNKtsbpJ9pM/FNh+XeC/olATN2ccbkkCdSO/+buqkLCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"62fd491c147151b6aedd08840c27a09cdf41ba07e883d883b3624ddad41eaf24","last_reissued_at":"2026-05-17T23:58:18.423961Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:58:18.423961Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1812.05725","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:58:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"aIPTVluuSV0/OWgRmvaw2qLtzYWTZ1mzyqIWQd/D4Psd4jYxzCZ8GmzGDIuZoIahWCAy0GNsE4WjInY5MAmZCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T23:38:35.438517Z"},"content_sha256":"a1391074379239992f766b482278efaf8edddd6f09729b3d32116e1ca4a9d2e7","schema_version":"1.0","event_id":"sha256:a1391074379239992f766b482278efaf8edddd6f09729b3d32116e1ca4a9d2e7"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:ML6USHAUOFI3NLW5BCCAYJ5ATT","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Training Set Camouflage","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Ara Vartanian, Ayon Sen, Scott Alfeld, Xiaojin Zhu, Xuezhou Zhang, Yuzhe Ma","submitted_at":"2018-12-13T23:06:39Z","abstract_excerpt":"We introduce a form of steganography in the domain of machine learning which we call training set camouflage. Imagine Alice has a training set on an illicit machine learning classification task. Alice wants Bob (a machine learning system) to learn the task. However, sending either the training set or the trained model to Bob can raise suspicion if the communication is monitored. Training set camouflage allows Alice to compute a second training set on a completely different -- and seemingly benign -- classification task. By construction, sending the second training set will not raise suspicion."},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.05725","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:58:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"tzu9LQhXFPberNQ7e6REPDStQH3XBRVOwOzjcLZk1RnPtwudE/qf3Xh0cPjydodMugZ1vlS9/Tn/sFDqhc6EDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-01T23:38:35.438866Z"},"content_sha256":"54b29e8029307b67768a431dfb853e6ac6e0ec4d62c3e7c17167e84f6a165007","schema_version":"1.0","event_id":"sha256:54b29e8029307b67768a431dfb853e6ac6e0ec4d62c3e7c17167e84f6a165007"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/ML6USHAUOFI3NLW5BCCAYJ5ATT/bundle.json","state_url":"https://pith.science/pith/ML6USHAUOFI3NLW5BCCAYJ5ATT/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/ML6USHAUOFI3NLW5BCCAYJ5ATT/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-01T23:38:35Z","links":{"resolver":"https://pith.science/pith/ML6USHAUOFI3NLW5BCCAYJ5ATT","bundle":"https://pith.science/pith/ML6USHAUOFI3NLW5BCCAYJ5ATT/bundle.json","state":"https://pith.science/pith/ML6USHAUOFI3NLW5BCCAYJ5ATT/state.json","well_known_bundle":"https://pith.science/.well-known/pith/ML6USHAUOFI3NLW5BCCAYJ5ATT/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:ML6USHAUOFI3NLW5BCCAYJ5ATT","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"603b346f35edb244d51ecd6a7fd1a399b1a877e723c4e1f97fc7e977da8f57c2","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-12-13T23:06:39Z","title_canon_sha256":"9ab9d8ad3a8ca1cb8648c7914eb026548d7d1f8bfbd9dee443fdc015d7da9220"},"schema_version":"1.0","source":{"id":"1812.05725","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.05725","created_at":"2026-05-17T23:58:18Z"},{"alias_kind":"arxiv_version","alias_value":"1812.05725v1","created_at":"2026-05-17T23:58:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.05725","created_at":"2026-05-17T23:58:18Z"},{"alias_kind":"pith_short_12","alias_value":"ML6USHAUOFI3","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_16","alias_value":"ML6USHAUOFI3NLW5","created_at":"2026-05-18T12:32:37Z"},{"alias_kind":"pith_short_8","alias_value":"ML6USHAU","created_at":"2026-05-18T12:32:37Z"}],"graph_snapshots":[{"event_id":"sha256:54b29e8029307b67768a431dfb853e6ac6e0ec4d62c3e7c17167e84f6a165007","target":"graph","created_at":"2026-05-17T23:58:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We introduce a form of steganography in the domain of machine learning which we call training set camouflage. Imagine Alice has a training set on an illicit machine learning classification task. Alice wants Bob (a machine learning system) to learn the task. However, sending either the training set or the trained model to Bob can raise suspicion if the communication is monitored. Training set camouflage allows Alice to compute a second training set on a completely different -- and seemingly benign -- classification task. By construction, sending the second training set will not raise suspicion.","authors_text":"Ara Vartanian, Ayon Sen, Scott Alfeld, Xiaojin Zhu, Xuezhou Zhang, Yuzhe Ma","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-12-13T23:06:39Z","title":"Training Set Camouflage"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.05725","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:a1391074379239992f766b482278efaf8edddd6f09729b3d32116e1ca4a9d2e7","target":"record","created_at":"2026-05-17T23:58:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"603b346f35edb244d51ecd6a7fd1a399b1a877e723c4e1f97fc7e977da8f57c2","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-12-13T23:06:39Z","title_canon_sha256":"9ab9d8ad3a8ca1cb8648c7914eb026548d7d1f8bfbd9dee443fdc015d7da9220"},"schema_version":"1.0","source":{"id":"1812.05725","kind":"arxiv","version":1}},"canonical_sha256":"62fd491c147151b6aedd08840c27a09cdf41ba07e883d883b3624ddad41eaf24","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"62fd491c147151b6aedd08840c27a09cdf41ba07e883d883b3624ddad41eaf24","first_computed_at":"2026-05-17T23:58:18.423961Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:58:18.423961Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"B3AurGZWZo7P+D5sMcm+02e4UXd4o0zen3Iskl+AiwZNKtsbpJ9pM/FNh+XeC/olATN2ccbkkCdSO/+buqkLCA==","signature_status":"signed_v1","signed_at":"2026-05-17T23:58:18.424602Z","signed_message":"canonical_sha256_bytes"},"source_id":"1812.05725","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:a1391074379239992f766b482278efaf8edddd6f09729b3d32116e1ca4a9d2e7","sha256:54b29e8029307b67768a431dfb853e6ac6e0ec4d62c3e7c17167e84f6a165007"],"state_sha256":"285d24c8c02951d9d64afbd972e785e410a837c1e9aafafe0c35a1b4c45f188a"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2ZQPS14YrNymFi4avYf8zDv9rd0hakDRERyl9wUOk3OiDSiNwQTDo9Dux+81caddl1J7QiJU/S0cv+p7pNRJAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-01T23:38:35.440829Z","bundle_sha256":"096e74ea9f963f663423aa029ee1ca40f9d9791d2ad410f9d27855289ce607eb"}}