{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:QOM2XVVZXLUFXG5BPI7AOONIOM","short_pith_number":"pith:QOM2XVVZ","schema_version":"1.0","canonical_sha256":"8399abd6b9bae85b9ba17a3e0739a8730450e084300920067e8287f527629d1b","source":{"kind":"arxiv","id":"2605.24420","version":1},"attestation_state":"computed","paper":{"title":"Batch Normalization Amplifies Memorization and Privacy Risks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.LG","authors_text":"Chongyan Gu, Ihsen Alouani, Ngoc Phu Doan","submitted_at":"2026-05-23T06:18:27Z","abstract_excerpt":"Batch Normalization (BN) is widely adopted to enable faster convergence and more stable training of deep neural networks. However, its impact on privacy and memorization has remained largely unexplored. In this work, we investigate the effect of BN layers on the memorization of atypical or outlier samples and its implications for privacy leakage. We conduct an extensive empirical study using three complementary approaches: (i) unintended memorization of out-of-distribution training samples, (ii) per-sample influence measured via gradient norms, and (iii) susceptibility to membership inference "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2605.24420","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-23T06:18:27Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"c236b1af58fc35e0b0a3598fca87692e4072e8626788d8a0ba7c72c070d42c47","abstract_canon_sha256":"7c9e68d0014b3a7a348d728553de6e89de6b3059d7d3b51c7ec9f6817ba917a2"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T01:03:38.841686Z","signature_b64":"WRQe/ieCCWrjrL+mf+dBYklEzd0oMtxHt9Tn4DyK/URrCkDLl1D9Su1bLYq7e8VgpmGGG3EwTJ7zT7pSRYDiDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8399abd6b9bae85b9ba17a3e0739a8730450e084300920067e8287f527629d1b","last_reissued_at":"2026-05-26T01:03:38.840910Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T01:03:38.840910Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Batch Normalization Amplifies Memorization and Privacy Risks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.LG","authors_text":"Chongyan Gu, Ihsen Alouani, Ngoc Phu Doan","submitted_at":"2026-05-23T06:18:27Z","abstract_excerpt":"Batch Normalization (BN) is widely adopted to enable faster convergence and more stable training of deep neural networks. However, its impact on privacy and memorization has remained largely unexplored. In this work, we investigate the effect of BN layers on the memorization of atypical or outlier samples and its implications for privacy leakage. We conduct an extensive empirical study using three complementary approaches: (i) unintended memorization of out-of-distribution training samples, (ii) per-sample influence measured via gradient norms, and (iii) susceptibility to membership inference "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.24420","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.24420/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2605.24420","created_at":"2026-05-26T01:03:38.841039+00:00"},{"alias_kind":"arxiv_version","alias_value":"2605.24420v1","created_at":"2026-05-26T01:03:38.841039+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.24420","created_at":"2026-05-26T01:03:38.841039+00:00"},{"alias_kind":"pith_short_12","alias_value":"QOM2XVVZXLUF","created_at":"2026-05-26T01:03:38.841039+00:00"},{"alias_kind":"pith_short_16","alias_value":"QOM2XVVZXLUFXG5B","created_at":"2026-05-26T01:03:38.841039+00:00"},{"alias_kind":"pith_short_8","alias_value":"QOM2XVVZ","created_at":"2026-05-26T01:03:38.841039+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/QOM2XVVZXLUFXG5BPI7AOONIOM","json":"https://pith.science/pith/QOM2XVVZXLUFXG5BPI7AOONIOM.json","graph_json":"https://pith.science/api/pith-number/QOM2XVVZXLUFXG5BPI7AOONIOM/graph.json","events_json":"https://pith.science/api/pith-number/QOM2XVVZXLUFXG5BPI7AOONIOM/events.json","paper":"https://pith.science/paper/QOM2XVVZ"},"agent_actions":{"view_html":"https://pith.science/pith/QOM2XVVZXLUFXG5BPI7AOONIOM","download_json":"https://pith.science/pith/QOM2XVVZXLUFXG5BPI7AOONIOM.json","view_paper":"https://pith.science/paper/QOM2XVVZ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2605.24420&json=true","fetch_graph":"https://pith.science/api/pith-number/QOM2XVVZXLUFXG5BPI7AOONIOM/graph.json","fetch_events":"https://pith.science/api/pith-number/QOM2XVVZXLUFXG5BPI7AOONIOM/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/QOM2XVVZXLUFXG5BPI7AOONIOM/action/timestamp_anchor","attest_storage":"https://pith.science/pith/QOM2XVVZXLUFXG5BPI7AOONIOM/action/storage_attestation","attest_author":"https://pith.science/pith/QOM2XVVZXLUFXG5BPI7AOONIOM/action/author_attestation","sign_citation":"https://pith.science/pith/QOM2XVVZXLUFXG5BPI7AOONIOM/action/citation_signature","submit_replication":"https://pith.science/pith/QOM2XVVZXLUFXG5BPI7AOONIOM/action/replication_record"}},"created_at":"2026-05-26T01:03:38.841039+00:00","updated_at":"2026-05-26T01:03:38.841039+00:00"}