{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:PIYCCXLDLOBIU63YRRHOU2QWZH","short_pith_number":"pith:PIYCCXLD","schema_version":"1.0","canonical_sha256":"7a30215d635b828a7b788c4eea6a16c9e6a8b5217a76beda3a420dc4be515703","source":{"kind":"arxiv","id":"2104.10706","version":1},"attestation_state":"computed","paper":{"title":"Dataset Inference: Ownership Resolution in Machine Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG"],"primary_cat":"stat.ML","authors_text":"Mohammad Yaghini, Nicolas Papernot, Pratyush Maini","submitted_at":"2021-04-21T18:12:18Z","abstract_excerpt":"With increasingly more data and computation involved in their training, machine learning models constitute valuable intellectual property. This has spurred interest in model stealing, which is made more practical by advances in learning with partial, little, or no supervision. Existing defenses focus on inserting unique watermarks in a model's decision surface, but this is insufficient: the watermarks are not sampled from the training distribution and thus are not always preserved during model stealing. In this paper, we make the key observation that knowledge contained in the stolen model's t"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2104.10706","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"stat.ML","submitted_at":"2021-04-21T18:12:18Z","cross_cats_sorted":["cs.CR","cs.LG"],"title_canon_sha256":"12c57ce117aadfe46108ba28e63c1b6660a36bc3d2bbfce5a1671efd54c2653e","abstract_canon_sha256":"41a0f1c50b1957d64de69d441f7e46d9b9bc0e450e0b2b4c8fc6d69dd6eed7d3"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T02:34:13.632588Z","signature_b64":"3S20TjUt1IdUhsIjOd607OISExAP0ONikADJTMjBBWbnYR9RznWXu5Aq1HGJp6mh69IwqR3c9q/Ce/vLBg5gDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7a30215d635b828a7b788c4eea6a16c9e6a8b5217a76beda3a420dc4be515703","last_reissued_at":"2026-07-05T02:34:13.632160Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T02:34:13.632160Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Dataset Inference: Ownership Resolution in Machine Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.LG"],"primary_cat":"stat.ML","authors_text":"Mohammad Yaghini, Nicolas Papernot, Pratyush Maini","submitted_at":"2021-04-21T18:12:18Z","abstract_excerpt":"With increasingly more data and computation involved in their training, machine learning models constitute valuable intellectual property. This has spurred interest in model stealing, which is made more practical by advances in learning with partial, little, or no supervision. Existing defenses focus on inserting unique watermarks in a model's decision surface, but this is insufficient: the watermarks are not sampled from the training distribution and thus are not always preserved during model stealing. In this paper, we make the key observation that knowledge contained in the stolen model's t"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2104.10706","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2104.10706/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2104.10706","created_at":"2026-07-05T02:34:13.632215+00:00"},{"alias_kind":"arxiv_version","alias_value":"2104.10706v1","created_at":"2026-07-05T02:34:13.632215+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2104.10706","created_at":"2026-07-05T02:34:13.632215+00:00"},{"alias_kind":"pith_short_12","alias_value":"PIYCCXLDLOBI","created_at":"2026-07-05T02:34:13.632215+00:00"},{"alias_kind":"pith_short_16","alias_value":"PIYCCXLDLOBIU63Y","created_at":"2026-07-05T02:34:13.632215+00:00"},{"alias_kind":"pith_short_8","alias_value":"PIYCCXLD","created_at":"2026-07-05T02:34:13.632215+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.24408","citing_title":"Natural Identifiers for Privacy and Data Audits in Large Language Models","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2606.31991","citing_title":"Amplifying Membership Signal Through Chained Regeneration","ref_index":24,"is_internal_anchor":false},{"citing_arxiv_id":"2605.27148","citing_title":"Landseer: Exploring the Machine Learning Defense Landscape","ref_index":65,"is_internal_anchor":false},{"citing_arxiv_id":"2405.04108","citing_title":"A2-DIDM: Privacy-preserving Accumulator-enabled Auditing for Distributed Identity of DNN Model","ref_index":14,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/PIYCCXLDLOBIU63YRRHOU2QWZH","json":"https://pith.science/pith/PIYCCXLDLOBIU63YRRHOU2QWZH.json","graph_json":"https://pith.science/api/pith-number/PIYCCXLDLOBIU63YRRHOU2QWZH/graph.json","events_json":"https://pith.science/api/pith-number/PIYCCXLDLOBIU63YRRHOU2QWZH/events.json","paper":"https://pith.science/paper/PIYCCXLD"},"agent_actions":{"view_html":"https://pith.science/pith/PIYCCXLDLOBIU63YRRHOU2QWZH","download_json":"https://pith.science/pith/PIYCCXLDLOBIU63YRRHOU2QWZH.json","view_paper":"https://pith.science/paper/PIYCCXLD","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2104.10706&json=true","fetch_graph":"https://pith.science/api/pith-number/PIYCCXLDLOBIU63YRRHOU2QWZH/graph.json","fetch_events":"https://pith.science/api/pith-number/PIYCCXLDLOBIU63YRRHOU2QWZH/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/PIYCCXLDLOBIU63YRRHOU2QWZH/action/timestamp_anchor","attest_storage":"https://pith.science/pith/PIYCCXLDLOBIU63YRRHOU2QWZH/action/storage_attestation","attest_author":"https://pith.science/pith/PIYCCXLDLOBIU63YRRHOU2QWZH/action/author_attestation","sign_citation":"https://pith.science/pith/PIYCCXLDLOBIU63YRRHOU2QWZH/action/citation_signature","submit_replication":"https://pith.science/pith/PIYCCXLDLOBIU63YRRHOU2QWZH/action/replication_record"}},"created_at":"2026-07-05T02:34:13.632215+00:00","updated_at":"2026-07-05T02:34:13.632215+00:00"}