{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:OD5USZVUBDCR76OLC446V7RSIQ","short_pith_number":"pith:OD5USZVU","schema_version":"1.0","canonical_sha256":"70fb4966b408c51ff9cb1739eafe324414a7fe4f10eef6e8a40323556f0bc8f5","source":{"kind":"arxiv","id":"2507.21412","version":3},"attestation_state":"computed","paper":{"title":"Cascading and Proxy Membership Inference Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Bruno Ribeiro, Hanshen Xiao, Jiacheng Li, Kaiyuan Zhang, Ninghui Li, Yuetian Chen, Yuntao Du, Zhizhen Yuan","submitted_at":"2025-07-29T00:46:09Z","abstract_excerpt":"A Membership Inference Attack (MIA) assesses how much a trained machine learning model reveals about its training data by determining whether specific query instances were included in the dataset. We classify existing MIAs into adaptive or non-adaptive, depending on whether the adversary is allowed to train shadow models on membership queries. In the adaptive setting, where the adversary can train shadow models after accessing query instances, we highlight the importance of exploiting membership dependencies between instances and propose an attack-agnostic framework called Cascading Membership"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2507.21412","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-07-29T00:46:09Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"0650efddbd893220ebe0635a97192a2820b4dde3f945fd102816faec0e861d50","abstract_canon_sha256":"65d6be07c7ce2394078fa2117d84fce98b555f9c6b09c34f3b8ccd6c8672a83e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T12:06:16.800204Z","signature_b64":"UYUUf6nbK7mHUK6msUrQUQ/EclmBO7IgdV6kxkuXlVmYf2VqVfFvZLrFjMinii1wPhFTjl8cosl1opTZXI79Cw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"70fb4966b408c51ff9cb1739eafe324414a7fe4f10eef6e8a40323556f0bc8f5","last_reissued_at":"2026-07-05T12:06:16.799656Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T12:06:16.799656Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Cascading and Proxy Membership Inference Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Bruno Ribeiro, Hanshen Xiao, Jiacheng Li, Kaiyuan Zhang, Ninghui Li, Yuetian Chen, Yuntao Du, Zhizhen Yuan","submitted_at":"2025-07-29T00:46:09Z","abstract_excerpt":"A Membership Inference Attack (MIA) assesses how much a trained machine learning model reveals about its training data by determining whether specific query instances were included in the dataset. We classify existing MIAs into adaptive or non-adaptive, depending on whether the adversary is allowed to train shadow models on membership queries. In the adaptive setting, where the adversary can train shadow models after accessing query instances, we highlight the importance of exploiting membership dependencies between instances and propose an attack-agnostic framework called Cascading Membership"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2507.21412","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2507.21412/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2507.21412","created_at":"2026-07-05T12:06:16.799713+00:00"},{"alias_kind":"arxiv_version","alias_value":"2507.21412v3","created_at":"2026-07-05T12:06:16.799713+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2507.21412","created_at":"2026-07-05T12:06:16.799713+00:00"},{"alias_kind":"pith_short_12","alias_value":"OD5USZVUBDCR","created_at":"2026-07-05T12:06:16.799713+00:00"},{"alias_kind":"pith_short_16","alias_value":"OD5USZVUBDCR76OL","created_at":"2026-07-05T12:06:16.799713+00:00"},{"alias_kind":"pith_short_8","alias_value":"OD5USZVU","created_at":"2026-07-05T12:06:16.799713+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.15648","citing_title":"Rethinking the Security of DP-SGD: A Corrected Analysis of Differentially Private Machine Learning","ref_index":13,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/OD5USZVUBDCR76OLC446V7RSIQ","json":"https://pith.science/pith/OD5USZVUBDCR76OLC446V7RSIQ.json","graph_json":"https://pith.science/api/pith-number/OD5USZVUBDCR76OLC446V7RSIQ/graph.json","events_json":"https://pith.science/api/pith-number/OD5USZVUBDCR76OLC446V7RSIQ/events.json","paper":"https://pith.science/paper/OD5USZVU"},"agent_actions":{"view_html":"https://pith.science/pith/OD5USZVUBDCR76OLC446V7RSIQ","download_json":"https://pith.science/pith/OD5USZVUBDCR76OLC446V7RSIQ.json","view_paper":"https://pith.science/paper/OD5USZVU","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2507.21412&json=true","fetch_graph":"https://pith.science/api/pith-number/OD5USZVUBDCR76OLC446V7RSIQ/graph.json","fetch_events":"https://pith.science/api/pith-number/OD5USZVUBDCR76OLC446V7RSIQ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/OD5USZVUBDCR76OLC446V7RSIQ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/OD5USZVUBDCR76OLC446V7RSIQ/action/storage_attestation","attest_author":"https://pith.science/pith/OD5USZVUBDCR76OLC446V7RSIQ/action/author_attestation","sign_citation":"https://pith.science/pith/OD5USZVUBDCR76OLC446V7RSIQ/action/citation_signature","submit_replication":"https://pith.science/pith/OD5USZVUBDCR76OLC446V7RSIQ/action/replication_record"}},"created_at":"2026-07-05T12:06:16.799713+00:00","updated_at":"2026-07-05T12:06:16.799713+00:00"}