{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:MO4GJAYPNZEXJ5Q4E34FAX35QX","short_pith_number":"pith:MO4GJAYP","canonical_record":{"source":{"id":"2606.03430","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T10:18:45Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"387972d1a23fce7ad9be60df594c41285adb8ef4f775ee7b24d1b482ea46b1c8","abstract_canon_sha256":"becb45dbdf41aaeef18d91c08b1c4dda53132a3e908256188df039f61567fff7"},"schema_version":"1.0"},"canonical_sha256":"63b864830f6e4974f61c26f8505f7d85f3d56eb0054a039b9b14b4faff52c958","source":{"kind":"arxiv","id":"2606.03430","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.03430","created_at":"2026-06-03T01:05:57Z"},{"alias_kind":"arxiv_version","alias_value":"2606.03430v1","created_at":"2026-06-03T01:05:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.03430","created_at":"2026-06-03T01:05:57Z"},{"alias_kind":"pith_short_12","alias_value":"MO4GJAYPNZEX","created_at":"2026-06-03T01:05:57Z"},{"alias_kind":"pith_short_16","alias_value":"MO4GJAYPNZEXJ5Q4","created_at":"2026-06-03T01:05:57Z"},{"alias_kind":"pith_short_8","alias_value":"MO4GJAYP","created_at":"2026-06-03T01:05:57Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:MO4GJAYPNZEXJ5Q4E34FAX35QX","target":"record","payload":{"canonical_record":{"source":{"id":"2606.03430","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T10:18:45Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"387972d1a23fce7ad9be60df594c41285adb8ef4f775ee7b24d1b482ea46b1c8","abstract_canon_sha256":"becb45dbdf41aaeef18d91c08b1c4dda53132a3e908256188df039f61567fff7"},"schema_version":"1.0"},"canonical_sha256":"63b864830f6e4974f61c26f8505f7d85f3d56eb0054a039b9b14b4faff52c958","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-03T01:05:57.615712Z","signature_b64":"zocXU+9W7b7/7U/eVgQddVkmeGC0Fr7RvbMvhWCm386vf0yIxFlqKNIKamzS01M+9IQlXHaDfXF/Eo3HPsLZCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"63b864830f6e4974f61c26f8505f7d85f3d56eb0054a039b9b14b4faff52c958","last_reissued_at":"2026-06-03T01:05:57.615368Z","signature_status":"signed_v1","first_computed_at":"2026-06-03T01:05:57.615368Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.03430","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZaY5HC0CtHMF0i0dRUvYGaj5QvRqTtf7As2tREYODjriavLjis6CGlazPE+fGdMuqUziwCCClOGVu364de0ZBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T16:49:22.137245Z"},"content_sha256":"bb5feb6c9818c518c67c87db722e7836b8b56573bb6fd85c8f66e8775dca1f89","schema_version":"1.0","event_id":"sha256:bb5feb6c9818c518c67c87db722e7836b8b56573bb6fd85c8f66e8775dca1f89"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:MO4GJAYPNZEXJ5Q4E34FAX35QX","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"FlowGuard: Flow Matching for Identity-Independent Detection of Data-Free Model Stealing Attacks on Energy System Intrusion Detection Systems","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Johannes Loevenich, Laurin Holz, Maxime Schwarzer, Roberto Rigolin F. Lopes, Thies Moehlenhof, Tobias Huerten, Veit Hagenmeyer","submitted_at":"2026-06-02T10:18:45Z","abstract_excerpt":"Artificial Intelligence (AI)-based Intrusion Detection Systems (IDS) deployed in energy infrastructure are vulnerable to model theft attacks, which allow adversaries to create evasive traffic offline. Current defences against model extraction rely either on identity-bound query monitoring, which is ineffective against distributed attackers (Sybil), or on prediction poisoning through soft-label perturbation, which is inapplicable to hard-label IDS deployments. Therefore, we propose FlowGuard, an identity-independent defence based on flow matching that classifies incoming queries as out-of-distr"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.03430","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.03430/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"J+kXdtkB8eJyCgFNEvPpXn8l2+T0NZKV2L2M3Wq051RVvarfXhbuCBClqn/zkZx5a6ofgNrS+oHw4MNwl+zMCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T16:49:22.137620Z"},"content_sha256":"4fc3aa69cde3d18dcc96c1b1322e2ec174a3f7f083145b1affa42d349f80742d","schema_version":"1.0","event_id":"sha256:4fc3aa69cde3d18dcc96c1b1322e2ec174a3f7f083145b1affa42d349f80742d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/MO4GJAYPNZEXJ5Q4E34FAX35QX/bundle.json","state_url":"https://pith.science/pith/MO4GJAYPNZEXJ5Q4E34FAX35QX/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/MO4GJAYPNZEXJ5Q4E34FAX35QX/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-28T16:49:22Z","links":{"resolver":"https://pith.science/pith/MO4GJAYPNZEXJ5Q4E34FAX35QX","bundle":"https://pith.science/pith/MO4GJAYPNZEXJ5Q4E34FAX35QX/bundle.json","state":"https://pith.science/pith/MO4GJAYPNZEXJ5Q4E34FAX35QX/state.json","well_known_bundle":"https://pith.science/.well-known/pith/MO4GJAYPNZEXJ5Q4E34FAX35QX/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:MO4GJAYPNZEXJ5Q4E34FAX35QX","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"becb45dbdf41aaeef18d91c08b1c4dda53132a3e908256188df039f61567fff7","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T10:18:45Z","title_canon_sha256":"387972d1a23fce7ad9be60df594c41285adb8ef4f775ee7b24d1b482ea46b1c8"},"schema_version":"1.0","source":{"id":"2606.03430","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.03430","created_at":"2026-06-03T01:05:57Z"},{"alias_kind":"arxiv_version","alias_value":"2606.03430v1","created_at":"2026-06-03T01:05:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.03430","created_at":"2026-06-03T01:05:57Z"},{"alias_kind":"pith_short_12","alias_value":"MO4GJAYPNZEX","created_at":"2026-06-03T01:05:57Z"},{"alias_kind":"pith_short_16","alias_value":"MO4GJAYPNZEXJ5Q4","created_at":"2026-06-03T01:05:57Z"},{"alias_kind":"pith_short_8","alias_value":"MO4GJAYP","created_at":"2026-06-03T01:05:57Z"}],"graph_snapshots":[{"event_id":"sha256:4fc3aa69cde3d18dcc96c1b1322e2ec174a3f7f083145b1affa42d349f80742d","target":"graph","created_at":"2026-06-03T01:05:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.03430/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Artificial Intelligence (AI)-based Intrusion Detection Systems (IDS) deployed in energy infrastructure are vulnerable to model theft attacks, which allow adversaries to create evasive traffic offline. Current defences against model extraction rely either on identity-bound query monitoring, which is ineffective against distributed attackers (Sybil), or on prediction poisoning through soft-label perturbation, which is inapplicable to hard-label IDS deployments. Therefore, we propose FlowGuard, an identity-independent defence based on flow matching that classifies incoming queries as out-of-distr","authors_text":"Johannes Loevenich, Laurin Holz, Maxime Schwarzer, Roberto Rigolin F. Lopes, Thies Moehlenhof, Tobias Huerten, Veit Hagenmeyer","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T10:18:45Z","title":"FlowGuard: Flow Matching for Identity-Independent Detection of Data-Free Model Stealing Attacks on Energy System Intrusion Detection Systems"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.03430","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:bb5feb6c9818c518c67c87db722e7836b8b56573bb6fd85c8f66e8775dca1f89","target":"record","created_at":"2026-06-03T01:05:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"becb45dbdf41aaeef18d91c08b1c4dda53132a3e908256188df039f61567fff7","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T10:18:45Z","title_canon_sha256":"387972d1a23fce7ad9be60df594c41285adb8ef4f775ee7b24d1b482ea46b1c8"},"schema_version":"1.0","source":{"id":"2606.03430","kind":"arxiv","version":1}},"canonical_sha256":"63b864830f6e4974f61c26f8505f7d85f3d56eb0054a039b9b14b4faff52c958","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"63b864830f6e4974f61c26f8505f7d85f3d56eb0054a039b9b14b4faff52c958","first_computed_at":"2026-06-03T01:05:57.615368Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-03T01:05:57.615368Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"zocXU+9W7b7/7U/eVgQddVkmeGC0Fr7RvbMvhWCm386vf0yIxFlqKNIKamzS01M+9IQlXHaDfXF/Eo3HPsLZCA==","signature_status":"signed_v1","signed_at":"2026-06-03T01:05:57.615712Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.03430","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:bb5feb6c9818c518c67c87db722e7836b8b56573bb6fd85c8f66e8775dca1f89","sha256:4fc3aa69cde3d18dcc96c1b1322e2ec174a3f7f083145b1affa42d349f80742d"],"state_sha256":"fb06f1c6767e2963b2ca6c1d14a8b696f68ed83a58c84ee2177af1dba2b650c2"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"f1qLuF+3eUvQqiVqThA7+BRkaaZZril0A1nitTQNNhVKAdeElfThr0HfmX3zAlV7LtPm80rAXl3NFFfXe5KUCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-28T16:49:22.139592Z","bundle_sha256":"e8cd940e0c2d09d52b9719e4238593f33adc31196d7e81d16c9fef5cebbd31e7"}}