{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:OLJXW6H3DWE4F5SBASD7OEULZS","short_pith_number":"pith:OLJXW6H3","canonical_record":{"source":{"id":"2506.15412","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.IT","submitted_at":"2025-06-18T12:33:01Z","cross_cats_sorted":["math.IT"],"title_canon_sha256":"fd20b990e495ad00ad0fc5a1307cced838213aedaf8e8ba719c02b92b06ace54","abstract_canon_sha256":"75eb147e55062566d38070306e22501da7146c4545b1c564d144970ceb9a872f"},"schema_version":"1.0"},"canonical_sha256":"72d37b78fb1d89c2f6410487f7128bcc88e99910ce04338526e1ea4c7c62c505","source":{"kind":"arxiv","id":"2506.15412","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2506.15412","created_at":"2026-05-21T01:04:14Z"},{"alias_kind":"arxiv_version","alias_value":"2506.15412v3","created_at":"2026-05-21T01:04:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2506.15412","created_at":"2026-05-21T01:04:14Z"},{"alias_kind":"pith_short_12","alias_value":"OLJXW6H3DWE4","created_at":"2026-05-21T01:04:14Z"},{"alias_kind":"pith_short_16","alias_value":"OLJXW6H3DWE4F5SB","created_at":"2026-05-21T01:04:14Z"},{"alias_kind":"pith_short_8","alias_value":"OLJXW6H3","created_at":"2026-05-21T01:04:14Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:OLJXW6H3DWE4F5SBASD7OEULZS","target":"record","payload":{"canonical_record":{"source":{"id":"2506.15412","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.IT","submitted_at":"2025-06-18T12:33:01Z","cross_cats_sorted":["math.IT"],"title_canon_sha256":"fd20b990e495ad00ad0fc5a1307cced838213aedaf8e8ba719c02b92b06ace54","abstract_canon_sha256":"75eb147e55062566d38070306e22501da7146c4545b1c564d144970ceb9a872f"},"schema_version":"1.0"},"canonical_sha256":"72d37b78fb1d89c2f6410487f7128bcc88e99910ce04338526e1ea4c7c62c505","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-21T01:04:14.663835Z","signature_b64":"xMNLBbghAJkyY5eBIZShcsEHuQ9kIkVxyhTlWPBqbXToiGVvQSlGv4vEjnHObCD9Q3e1pT41LEvzlObfM/KTBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"72d37b78fb1d89c2f6410487f7128bcc88e99910ce04338526e1ea4c7c62c505","last_reissued_at":"2026-05-21T01:04:14.662960Z","signature_status":"signed_v1","first_computed_at":"2026-05-21T01:04:14.662960Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2506.15412","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T01:04:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ioseDdxfnrQFnofG7Ti+mU3zOWUISjL5yHC7P+IiESn09B8y0zV425RDRjHOKm8EIEumIYv4t6fbQXMWlqC8Cw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T20:01:20.554096Z"},"content_sha256":"905980334bcb8ab9a0b75da4a87f9b2e1c694e3ad8d87036c776be47faade416","schema_version":"1.0","event_id":"sha256:905980334bcb8ab9a0b75da4a87f9b2e1c694e3ad8d87036c776be47faade416"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:OLJXW6H3DWE4F5SBASD7OEULZS","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Partitioning for Intrinsic Model Inversion Resistance in Collaborative Inference","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["math.IT"],"primary_cat":"cs.IT","authors_text":"Dong Wang, Lei Zhou, Rongke Liu, Xianglong Zhang, Youwen Zhu","submitted_at":"2025-06-18T12:33:01Z","abstract_excerpt":"In collaborative inference (CI), transmitting intermediate representations $Z$ from edge devices enables model inversion attacks (MIA) that reconstruct the original inputs $X$, while existing defenses mainly perturb shallow-layer $Z$ at the cost of utility. We instead ask where an edge-cloud model should be partitioned to obtain intrinsic resistance to MIA. We challenge the intuition that depth is the driver of MIA resistance, and show that depth is sufficient only insofar as it enables a representational transition; this transition is necessary for intrinsic resistance and is marked by an abr"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2506.15412","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2506.15412/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-21T01:04:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"XQPXIkQGvqk/NgeStTUUnyrxpq/Lk4vXrpq3u7CiB2kg9zae1NgQgo22CPb3DYYexUZ0sYy07nr+95qGD2cgBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T20:01:20.554548Z"},"content_sha256":"b097a8b48a72c2b77424be8b98f26b6bda4ad6c16549fca9dc70c35ef3543bc2","schema_version":"1.0","event_id":"sha256:b097a8b48a72c2b77424be8b98f26b6bda4ad6c16549fca9dc70c35ef3543bc2"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/OLJXW6H3DWE4F5SBASD7OEULZS/bundle.json","state_url":"https://pith.science/pith/OLJXW6H3DWE4F5SBASD7OEULZS/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/OLJXW6H3DWE4F5SBASD7OEULZS/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T20:01:20Z","links":{"resolver":"https://pith.science/pith/OLJXW6H3DWE4F5SBASD7OEULZS","bundle":"https://pith.science/pith/OLJXW6H3DWE4F5SBASD7OEULZS/bundle.json","state":"https://pith.science/pith/OLJXW6H3DWE4F5SBASD7OEULZS/state.json","well_known_bundle":"https://pith.science/.well-known/pith/OLJXW6H3DWE4F5SBASD7OEULZS/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:OLJXW6H3DWE4F5SBASD7OEULZS","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"75eb147e55062566d38070306e22501da7146c4545b1c564d144970ceb9a872f","cross_cats_sorted":["math.IT"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.IT","submitted_at":"2025-06-18T12:33:01Z","title_canon_sha256":"fd20b990e495ad00ad0fc5a1307cced838213aedaf8e8ba719c02b92b06ace54"},"schema_version":"1.0","source":{"id":"2506.15412","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2506.15412","created_at":"2026-05-21T01:04:14Z"},{"alias_kind":"arxiv_version","alias_value":"2506.15412v3","created_at":"2026-05-21T01:04:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2506.15412","created_at":"2026-05-21T01:04:14Z"},{"alias_kind":"pith_short_12","alias_value":"OLJXW6H3DWE4","created_at":"2026-05-21T01:04:14Z"},{"alias_kind":"pith_short_16","alias_value":"OLJXW6H3DWE4F5SB","created_at":"2026-05-21T01:04:14Z"},{"alias_kind":"pith_short_8","alias_value":"OLJXW6H3","created_at":"2026-05-21T01:04:14Z"}],"graph_snapshots":[{"event_id":"sha256:b097a8b48a72c2b77424be8b98f26b6bda4ad6c16549fca9dc70c35ef3543bc2","target":"graph","created_at":"2026-05-21T01:04:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2506.15412/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"In collaborative inference (CI), transmitting intermediate representations $Z$ from edge devices enables model inversion attacks (MIA) that reconstruct the original inputs $X$, while existing defenses mainly perturb shallow-layer $Z$ at the cost of utility. We instead ask where an edge-cloud model should be partitioned to obtain intrinsic resistance to MIA. We challenge the intuition that depth is the driver of MIA resistance, and show that depth is sufficient only insofar as it enables a representational transition; this transition is necessary for intrinsic resistance and is marked by an abr","authors_text":"Dong Wang, Lei Zhou, Rongke Liu, Xianglong Zhang, Youwen Zhu","cross_cats":["math.IT"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.IT","submitted_at":"2025-06-18T12:33:01Z","title":"Partitioning for Intrinsic Model Inversion Resistance in Collaborative Inference"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2506.15412","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:905980334bcb8ab9a0b75da4a87f9b2e1c694e3ad8d87036c776be47faade416","target":"record","created_at":"2026-05-21T01:04:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"75eb147e55062566d38070306e22501da7146c4545b1c564d144970ceb9a872f","cross_cats_sorted":["math.IT"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.IT","submitted_at":"2025-06-18T12:33:01Z","title_canon_sha256":"fd20b990e495ad00ad0fc5a1307cced838213aedaf8e8ba719c02b92b06ace54"},"schema_version":"1.0","source":{"id":"2506.15412","kind":"arxiv","version":3}},"canonical_sha256":"72d37b78fb1d89c2f6410487f7128bcc88e99910ce04338526e1ea4c7c62c505","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"72d37b78fb1d89c2f6410487f7128bcc88e99910ce04338526e1ea4c7c62c505","first_computed_at":"2026-05-21T01:04:14.662960Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-21T01:04:14.662960Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"xMNLBbghAJkyY5eBIZShcsEHuQ9kIkVxyhTlWPBqbXToiGVvQSlGv4vEjnHObCD9Q3e1pT41LEvzlObfM/KTBw==","signature_status":"signed_v1","signed_at":"2026-05-21T01:04:14.663835Z","signed_message":"canonical_sha256_bytes"},"source_id":"2506.15412","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:905980334bcb8ab9a0b75da4a87f9b2e1c694e3ad8d87036c776be47faade416","sha256:b097a8b48a72c2b77424be8b98f26b6bda4ad6c16549fca9dc70c35ef3543bc2"],"state_sha256":"c0be6f2bed9aa25e11a5425e334ca3ec8bad7ef782832469d8dbbba90a6e56ef"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"OSU+hRMRuJALwppWS5qMa9MlH9ISxh8Ybf/nhxyQFDcuDd2YmwSSJ6RjJnVLUUf0t9DLTyd/LN41NRlvcrpfDA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T20:01:20.558608Z","bundle_sha256":"676ef80f99735981a1ac9b6410b80680aaf200f4ddf2b564d6d4a195eaf7e315"}}