{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2022:O3RP5WZJIBF2O3NFPMFQLBB5M6","short_pith_number":"pith:O3RP5WZJ","canonical_record":{"source":{"id":"2209.10119","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2022-09-21T04:39:49Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"718ec372f872acbb413226090a2c278051a7e0da44da351e8a94799c5d9e2fad","abstract_canon_sha256":"506452d2db91315689d7434fb09b0d0d30f5d5193c010e25063eda3edcd6b5c7"},"schema_version":"1.0"},"canonical_sha256":"76e2fedb29404ba76da57b0b05843d679ad9627778125d42cbcd1a9c2dbd1f51","source":{"kind":"arxiv","id":"2209.10119","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2209.10119","created_at":"2026-07-05T04:59:45Z"},{"alias_kind":"arxiv_version","alias_value":"2209.10119v1","created_at":"2026-07-05T04:59:45Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2209.10119","created_at":"2026-07-05T04:59:45Z"},{"alias_kind":"pith_short_12","alias_value":"O3RP5WZJIBF2","created_at":"2026-07-05T04:59:45Z"},{"alias_kind":"pith_short_16","alias_value":"O3RP5WZJIBF2O3NF","created_at":"2026-07-05T04:59:45Z"},{"alias_kind":"pith_short_8","alias_value":"O3RP5WZJ","created_at":"2026-07-05T04:59:45Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2022:O3RP5WZJIBF2O3NFPMFQLBB5M6","target":"record","payload":{"canonical_record":{"source":{"id":"2209.10119","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2022-09-21T04:39:49Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"718ec372f872acbb413226090a2c278051a7e0da44da351e8a94799c5d9e2fad","abstract_canon_sha256":"506452d2db91315689d7434fb09b0d0d30f5d5193c010e25063eda3edcd6b5c7"},"schema_version":"1.0"},"canonical_sha256":"76e2fedb29404ba76da57b0b05843d679ad9627778125d42cbcd1a9c2dbd1f51","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T04:59:45.310300Z","signature_b64":"ZVP+lTnFUEW6Voi6elMiqoHCmLwRQpnJPiqb3fRPBrWmqTe+bnFVZgYKd97UnB2FKcGjChSbVqKPg1J3VRy8Dw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"76e2fedb29404ba76da57b0b05843d679ad9627778125d42cbcd1a9c2dbd1f51","last_reissued_at":"2026-07-05T04:59:45.309847Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T04:59:45.309847Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2209.10119","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T04:59:45Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"UgyHpyZoLR9++aDdIBk3EMVSh1kHKMEPm5fhMepy6zX/MiPg/uXcE8b4p05A9cEAE9/RZ2QrJ7Z4mkyvafE6Aw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-05T14:30:55.940092Z"},"content_sha256":"e9e3a040529b35e03c7fe85a5a1ca8cbb26bbe3f69fe7ea93256943634178d76","schema_version":"1.0","event_id":"sha256:e9e3a040529b35e03c7fe85a5a1ca8cbb26bbe3f69fe7ea93256943634178d76"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2022:O3RP5WZJIBF2O3NFPMFQLBB5M6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Measuring and Controlling Split Layer Privacy Leakage Using Fisher Information","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Chuan Guo, Edward Suh, Kiwan Maeng, Sanjay Kariyappa","submitted_at":"2022-09-21T04:39:49Z","abstract_excerpt":"Split learning and inference propose to run training/inference of a large model that is split across client devices and the cloud. However, such a model splitting imposes privacy concerns, because the activation flowing through the split layer may leak information about the clients' private input data. There is currently no good way to quantify how much private information is being leaked through the split layer, nor a good way to improve privacy up to the desired level.\n  In this work, we propose to use Fisher information as a privacy metric to measure and control the information leakage. We "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2209.10119","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2209.10119/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T04:59:45Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"QrS3O1SROMqxZeY2iXLco7qJ6RrjqyHJKRhs+E1xwlKMcp4+//fZzv4Caz/E5Dg78zHO8G6s26Yy7EsQIfbiBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-05T14:30:55.940929Z"},"content_sha256":"b57a81e0c8fb150f388ea53d2eb06a2c12a701240d88e39dbbbf827b6fc276b7","schema_version":"1.0","event_id":"sha256:b57a81e0c8fb150f388ea53d2eb06a2c12a701240d88e39dbbbf827b6fc276b7"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/O3RP5WZJIBF2O3NFPMFQLBB5M6/bundle.json","state_url":"https://pith.science/pith/O3RP5WZJIBF2O3NFPMFQLBB5M6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/O3RP5WZJIBF2O3NFPMFQLBB5M6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-05T14:30:55Z","links":{"resolver":"https://pith.science/pith/O3RP5WZJIBF2O3NFPMFQLBB5M6","bundle":"https://pith.science/pith/O3RP5WZJIBF2O3NFPMFQLBB5M6/bundle.json","state":"https://pith.science/pith/O3RP5WZJIBF2O3NFPMFQLBB5M6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/O3RP5WZJIBF2O3NFPMFQLBB5M6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2022:O3RP5WZJIBF2O3NFPMFQLBB5M6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"506452d2db91315689d7434fb09b0d0d30f5d5193c010e25063eda3edcd6b5c7","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2022-09-21T04:39:49Z","title_canon_sha256":"718ec372f872acbb413226090a2c278051a7e0da44da351e8a94799c5d9e2fad"},"schema_version":"1.0","source":{"id":"2209.10119","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2209.10119","created_at":"2026-07-05T04:59:45Z"},{"alias_kind":"arxiv_version","alias_value":"2209.10119v1","created_at":"2026-07-05T04:59:45Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2209.10119","created_at":"2026-07-05T04:59:45Z"},{"alias_kind":"pith_short_12","alias_value":"O3RP5WZJIBF2","created_at":"2026-07-05T04:59:45Z"},{"alias_kind":"pith_short_16","alias_value":"O3RP5WZJIBF2O3NF","created_at":"2026-07-05T04:59:45Z"},{"alias_kind":"pith_short_8","alias_value":"O3RP5WZJ","created_at":"2026-07-05T04:59:45Z"}],"graph_snapshots":[{"event_id":"sha256:b57a81e0c8fb150f388ea53d2eb06a2c12a701240d88e39dbbbf827b6fc276b7","target":"graph","created_at":"2026-07-05T04:59:45Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2209.10119/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Split learning and inference propose to run training/inference of a large model that is split across client devices and the cloud. However, such a model splitting imposes privacy concerns, because the activation flowing through the split layer may leak information about the clients' private input data. There is currently no good way to quantify how much private information is being leaked through the split layer, nor a good way to improve privacy up to the desired level.\n  In this work, we propose to use Fisher information as a privacy metric to measure and control the information leakage. We ","authors_text":"Chuan Guo, Edward Suh, Kiwan Maeng, Sanjay Kariyappa","cross_cats":["cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2022-09-21T04:39:49Z","title":"Measuring and Controlling Split Layer Privacy Leakage Using Fisher Information"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2209.10119","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e9e3a040529b35e03c7fe85a5a1ca8cbb26bbe3f69fe7ea93256943634178d76","target":"record","created_at":"2026-07-05T04:59:45Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"506452d2db91315689d7434fb09b0d0d30f5d5193c010e25063eda3edcd6b5c7","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2022-09-21T04:39:49Z","title_canon_sha256":"718ec372f872acbb413226090a2c278051a7e0da44da351e8a94799c5d9e2fad"},"schema_version":"1.0","source":{"id":"2209.10119","kind":"arxiv","version":1}},"canonical_sha256":"76e2fedb29404ba76da57b0b05843d679ad9627778125d42cbcd1a9c2dbd1f51","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"76e2fedb29404ba76da57b0b05843d679ad9627778125d42cbcd1a9c2dbd1f51","first_computed_at":"2026-07-05T04:59:45.309847Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T04:59:45.309847Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"ZVP+lTnFUEW6Voi6elMiqoHCmLwRQpnJPiqb3fRPBrWmqTe+bnFVZgYKd97UnB2FKcGjChSbVqKPg1J3VRy8Dw==","signature_status":"signed_v1","signed_at":"2026-07-05T04:59:45.310300Z","signed_message":"canonical_sha256_bytes"},"source_id":"2209.10119","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e9e3a040529b35e03c7fe85a5a1ca8cbb26bbe3f69fe7ea93256943634178d76","sha256:b57a81e0c8fb150f388ea53d2eb06a2c12a701240d88e39dbbbf827b6fc276b7"],"state_sha256":"a5ec62f95033d3c304f5d8effac49e3ea016c0e1a7009f02c5890fdcbf6aaf52"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZfG80Mzru7Pyin3G0TQtuxWzxklj9+N0WUnHtsqK8im2OIw7qeiDFUpb07yhqVklG2KrYvj+JsleFnCT1S5dBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-05T14:30:55.945271Z","bundle_sha256":"9915fcfead79509a872a36aee96802d12a373bc01900951c5ae9f2e51d682c3b"}}