{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:MQB2XUF2N7GH5GOMCZBVGVGCPA","short_pith_number":"pith:MQB2XUF2","schema_version":"1.0","canonical_sha256":"6403abd0ba6fcc7e99cc16435354c2783006a832cb9f145f687c8e63a84fefa9","source":{"kind":"arxiv","id":"2605.06505","version":2},"attestation_state":"computed","paper":{"title":"PACZero: PAC-Private Fine-Tuning of Language Models via Sign Quantization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"PACZero achieves usable fine-tuning performance for large language models at zero mutual information privacy by using sign quantization to create unanimous gradient updates.","cross_cats":["cs.AI","cs.CR"],"primary_cat":"cs.LG","authors_text":"Marten van Dijk, Murat Bilgehan Ertan, Phuong Ha Nguyen, Srinivas Devadas, Xiaochen Zhu","submitted_at":"2026-05-07T16:20:20Z","abstract_excerpt":"We introduce PACZero, a family of PAC-private zeroth-order mechanisms for fine-tuning large language models that delivers usable utility at $I(S^*; Y_{1:T})=0$. This privacy regime bounds the membership-inference attack (MIA) posterior success rate at the prior, an MIA-resistance level the DP framework matches only at $\\varepsilon=0$ and infinite noise. All DP-ZO comparisons below are matched at the MIA posterior level. The key insight is that PAC Privacy charges mutual information only when the release depends on which candidate subset is the secret. Sign-quantizing subset-aggregated zeroth-o"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2605.06505","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-07T16:20:20Z","cross_cats_sorted":["cs.AI","cs.CR"],"title_canon_sha256":"4afda9e9e538af6078b31b61b06534fd7fd1fe29c57341832d6b815c2db4a9aa","abstract_canon_sha256":"10ea4d6835e476e66b872d0bd2e2c77dc0b4de83eeb0609c1f40fcf168c2e341"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T02:04:12.315230Z","signature_b64":"P2tM7ikvpIHQzAe9KWoVV9alC89uFlfOVRsUH7j/pjcZ0EsqxhV7JcSz6lchd78tJ4C5SO+TguhtqeJyuoBvAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"6403abd0ba6fcc7e99cc16435354c2783006a832cb9f145f687c8e63a84fefa9","last_reissued_at":"2026-05-26T02:04:12.314302Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T02:04:12.314302Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"PACZero: PAC-Private Fine-Tuning of Language Models via Sign Quantization","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"PACZero achieves usable fine-tuning performance for large language models at zero mutual information privacy by using sign quantization to create unanimous gradient updates.","cross_cats":["cs.AI","cs.CR"],"primary_cat":"cs.LG","authors_text":"Marten van Dijk, Murat Bilgehan Ertan, Phuong Ha Nguyen, Srinivas Devadas, Xiaochen Zhu","submitted_at":"2026-05-07T16:20:20Z","abstract_excerpt":"We introduce PACZero, a family of PAC-private zeroth-order mechanisms for fine-tuning large language models that delivers usable utility at $I(S^*; Y_{1:T})=0$. This privacy regime bounds the membership-inference attack (MIA) posterior success rate at the prior, an MIA-resistance level the DP framework matches only at $\\varepsilon=0$ and infinite noise. All DP-ZO comparisons below are matched at the MIA posterior level. The key insight is that PAC Privacy charges mutual information only when the release depends on which candidate subset is the secret. Sign-quantizing subset-aggregated zeroth-o"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"On SST-2 OPT-1.3B full fine-tuning at I=0, PACZero-ZPL reaches 88.99±0.91, within 2.1pp of the non-private MeZO baseline (91.1 FT). No prior method produces usable utility in the high-privacy regime ε<1.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That sign-quantizing subset-aggregated zeroth-order gradients creates frequent unanimity steps at which every candidate subset agrees on the update direction, making the released sign cost zero conditional mutual information.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"PACZero achieves zero mutual information privacy for LLM fine-tuning via sign-quantized zeroth-order gradients, delivering near-non-private accuracy on SST-2 and SQuAD at I=0.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"PACZero achieves usable fine-tuning performance for large language models at zero mutual information privacy by using sign quantization to create unanimous gradient updates.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"e48685c789795cb576312de5fcf62e65d4da0271d35ef76403a47d9bd87c5464"},"source":{"id":"2605.06505","kind":"arxiv","version":2},"verdict":{"id":"9c9c5dd6-be0f-479b-ab2f-009676bfbbb9","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-08T12:28:28.804139Z","strongest_claim":"On SST-2 OPT-1.3B full fine-tuning at I=0, PACZero-ZPL reaches 88.99±0.91, within 2.1pp of the non-private MeZO baseline (91.1 FT). No prior method produces usable utility in the high-privacy regime ε<1.","one_line_summary":"PACZero achieves zero mutual information privacy for LLM fine-tuning via sign-quantized zeroth-order gradients, delivering near-non-private accuracy on SST-2 and SQuAD at I=0.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That sign-quantizing subset-aggregated zeroth-order gradients creates frequent unanimity steps at which every candidate subset agrees on the update direction, making the released sign cost zero conditional mutual information.","pith_extraction_headline":"PACZero achieves usable fine-tuning performance for large language models at zero mutual information privacy by using sign quantization to create unanimous gradient updates."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.06505/integrity.json","findings":[],"available":true,"detectors_run":[{"name":"claim_evidence","ran_at":"2026-05-20T12:22:03.887029Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"ai_meta_artifact","ran_at":"2026-05-20T07:40:48.446880Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"doi_title_agreement","ran_at":"2026-05-19T18:01:19.717780Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"doi_compliance","ran_at":"2026-05-19T12:36:37.949463Z","status":"completed","version":"1.0.0","findings_count":0}],"snapshot_sha256":"c629ea23f9ac34fc3b64f2e30a9aea81b7e8b22bf91b3851205e8f62803609f2"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2605.06505","created_at":"2026-05-26T02:04:12.314444+00:00"},{"alias_kind":"arxiv_version","alias_value":"2605.06505v2","created_at":"2026-05-26T02:04:12.314444+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.06505","created_at":"2026-05-26T02:04:12.314444+00:00"},{"alias_kind":"pith_short_12","alias_value":"MQB2XUF2N7GH","created_at":"2026-05-26T02:04:12.314444+00:00"},{"alias_kind":"pith_short_16","alias_value":"MQB2XUF2N7GH5GOM","created_at":"2026-05-26T02:04:12.314444+00:00"},{"alias_kind":"pith_short_8","alias_value":"MQB2XUF2","created_at":"2026-05-26T02:04:12.314444+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/MQB2XUF2N7GH5GOMCZBVGVGCPA","json":"https://pith.science/pith/MQB2XUF2N7GH5GOMCZBVGVGCPA.json","graph_json":"https://pith.science/api/pith-number/MQB2XUF2N7GH5GOMCZBVGVGCPA/graph.json","events_json":"https://pith.science/api/pith-number/MQB2XUF2N7GH5GOMCZBVGVGCPA/events.json","paper":"https://pith.science/paper/MQB2XUF2"},"agent_actions":{"view_html":"https://pith.science/pith/MQB2XUF2N7GH5GOMCZBVGVGCPA","download_json":"https://pith.science/pith/MQB2XUF2N7GH5GOMCZBVGVGCPA.json","view_paper":"https://pith.science/paper/MQB2XUF2","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2605.06505&json=true","fetch_graph":"https://pith.science/api/pith-number/MQB2XUF2N7GH5GOMCZBVGVGCPA/graph.json","fetch_events":"https://pith.science/api/pith-number/MQB2XUF2N7GH5GOMCZBVGVGCPA/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/MQB2XUF2N7GH5GOMCZBVGVGCPA/action/timestamp_anchor","attest_storage":"https://pith.science/pith/MQB2XUF2N7GH5GOMCZBVGVGCPA/action/storage_attestation","attest_author":"https://pith.science/pith/MQB2XUF2N7GH5GOMCZBVGVGCPA/action/author_attestation","sign_citation":"https://pith.science/pith/MQB2XUF2N7GH5GOMCZBVGVGCPA/action/citation_signature","submit_replication":"https://pith.science/pith/MQB2XUF2N7GH5GOMCZBVGVGCPA/action/replication_record"}},"created_at":"2026-05-26T02:04:12.314444+00:00","updated_at":"2026-05-26T02:04:12.314444+00:00"}