{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:MVLDUXLER5EHTR2E2RTWU6J6SZ","short_pith_number":"pith:MVLDUXLE","schema_version":"1.0","canonical_sha256":"65563a5d648f4879c744d4676a793e965f65e38c3db407b283bfe4c4588da631","source":{"kind":"arxiv","id":"2605.24312","version":1},"attestation_state":"computed","paper":{"title":"Five Queries Are Enough: Query-Efficient and Surrogate-Free Membership Inference Attacks on RAG via Entailment","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Alsharif Abuadbba, Jun Zhang, Minghong Fang, Nguyen Linh Bao Nguyen, Viet Vo, Wanlun Ma, Yang Xiang","submitted_at":"2026-05-23T00:38:59Z","abstract_excerpt":"Retrieval-augmented generation (RAG) has become central to large language model (LLM) deployments, grounding responses in enterprise or proprietary data to reduce hallucinations. However, this design introduces a new privacy risk: model outputs may signal the presence of specific documents in the retrieval corpus, enabling membership inference attacks (MIAs) that leak sensitive information. Existing MIAs are feasible, but they often rely on easily detected templated queries or require many non-templated yet costly and repetitive queries, limiting practicality. We ask: Can an adversary launch a"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2605.24312","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-23T00:38:59Z","cross_cats_sorted":[],"title_canon_sha256":"bc5e1a8879cfc8e63acb8b7ffe8e76698ad708393e2703d35469a77d8c260ab1","abstract_canon_sha256":"3ff33bc8c867e4788e195b345590139e9ea89b3317fdbf0e5cc292a4189732a1"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T01:02:59.218675Z","signature_b64":"o2lsUhxvPow28lR7HrOmW0aVLnjjE+WFTKsnkrQP/F6Mhh5Fkr79+Cc7ID38o/BiVpa5yljgRZqwQsVPe3PBDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"65563a5d648f4879c744d4676a793e965f65e38c3db407b283bfe4c4588da631","last_reissued_at":"2026-05-26T01:02:59.217903Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T01:02:59.217903Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Five Queries Are Enough: Query-Efficient and Surrogate-Free Membership Inference Attacks on RAG via Entailment","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Alsharif Abuadbba, Jun Zhang, Minghong Fang, Nguyen Linh Bao Nguyen, Viet Vo, Wanlun Ma, Yang Xiang","submitted_at":"2026-05-23T00:38:59Z","abstract_excerpt":"Retrieval-augmented generation (RAG) has become central to large language model (LLM) deployments, grounding responses in enterprise or proprietary data to reduce hallucinations. However, this design introduces a new privacy risk: model outputs may signal the presence of specific documents in the retrieval corpus, enabling membership inference attacks (MIAs) that leak sensitive information. Existing MIAs are feasible, but they often rely on easily detected templated queries or require many non-templated yet costly and repetitive queries, limiting practicality. We ask: Can an adversary launch a"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.24312","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.24312/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2605.24312","created_at":"2026-05-26T01:02:59.218038+00:00"},{"alias_kind":"arxiv_version","alias_value":"2605.24312v1","created_at":"2026-05-26T01:02:59.218038+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.24312","created_at":"2026-05-26T01:02:59.218038+00:00"},{"alias_kind":"pith_short_12","alias_value":"MVLDUXLER5EH","created_at":"2026-05-26T01:02:59.218038+00:00"},{"alias_kind":"pith_short_16","alias_value":"MVLDUXLER5EHTR2E","created_at":"2026-05-26T01:02:59.218038+00:00"},{"alias_kind":"pith_short_8","alias_value":"MVLDUXLE","created_at":"2026-05-26T01:02:59.218038+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/MVLDUXLER5EHTR2E2RTWU6J6SZ","json":"https://pith.science/pith/MVLDUXLER5EHTR2E2RTWU6J6SZ.json","graph_json":"https://pith.science/api/pith-number/MVLDUXLER5EHTR2E2RTWU6J6SZ/graph.json","events_json":"https://pith.science/api/pith-number/MVLDUXLER5EHTR2E2RTWU6J6SZ/events.json","paper":"https://pith.science/paper/MVLDUXLE"},"agent_actions":{"view_html":"https://pith.science/pith/MVLDUXLER5EHTR2E2RTWU6J6SZ","download_json":"https://pith.science/pith/MVLDUXLER5EHTR2E2RTWU6J6SZ.json","view_paper":"https://pith.science/paper/MVLDUXLE","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2605.24312&json=true","fetch_graph":"https://pith.science/api/pith-number/MVLDUXLER5EHTR2E2RTWU6J6SZ/graph.json","fetch_events":"https://pith.science/api/pith-number/MVLDUXLER5EHTR2E2RTWU6J6SZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/MVLDUXLER5EHTR2E2RTWU6J6SZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/MVLDUXLER5EHTR2E2RTWU6J6SZ/action/storage_attestation","attest_author":"https://pith.science/pith/MVLDUXLER5EHTR2E2RTWU6J6SZ/action/author_attestation","sign_citation":"https://pith.science/pith/MVLDUXLER5EHTR2E2RTWU6J6SZ/action/citation_signature","submit_replication":"https://pith.science/pith/MVLDUXLER5EHTR2E2RTWU6J6SZ/action/replication_record"}},"created_at":"2026-05-26T01:02:59.218038+00:00","updated_at":"2026-05-26T01:02:59.218038+00:00"}