{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:QSCMUGVZTQVYDUN5YIK5D66CTN","short_pith_number":"pith:QSCMUGVZ","schema_version":"1.0","canonical_sha256":"8484ca1ab99c2b81d1bdc215d1fbc29b602683bdd2a240832d5b60a265faadec","source":{"kind":"arxiv","id":"2506.05867","version":1},"attestation_state":"computed","paper":{"title":"Stealix: Model Stealing via Prompt Evolution","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Hui-Po Wang, Maria-Irina Nicolae, Mario Fritz, Zhixiong Zhuang","submitted_at":"2025-06-06T08:34:00Z","abstract_excerpt":"Model stealing poses a significant security risk in machine learning by enabling attackers to replicate a black-box model without access to its training data, thus jeopardizing intellectual property and exposing sensitive information. Recent methods that use pre-trained diffusion models for data synthesis improve efficiency and performance but rely heavily on manually crafted prompts, limiting automation and scalability, especially for attackers with little expertise. To assess the risks posed by open-source pre-trained models, we propose a more realistic threat model that eliminates the need "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2506.05867","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2025-06-06T08:34:00Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"4dd732d205db2854da493b5ce1d4467729738323f9974179213acd0a2f6b9870","abstract_canon_sha256":"916dfbae6b6df03b2371d66fa53e336e97f7ac26fbb2febcb1eb5b597f2b8f8b"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:17:11.676644Z","signature_b64":"TJtsMZ98u245/gz5uvv6Q/iFbQ0xER2pIn/MdO6U1xTqw6hJv4Oi8Jugpo+NjsPIuPV9iPBnKVbeLGJY+iqoBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8484ca1ab99c2b81d1bdc215d1fbc29b602683bdd2a240832d5b60a265faadec","last_reissued_at":"2026-07-05T11:17:11.676134Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:17:11.676134Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Stealix: Model Stealing via Prompt Evolution","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Hui-Po Wang, Maria-Irina Nicolae, Mario Fritz, Zhixiong Zhuang","submitted_at":"2025-06-06T08:34:00Z","abstract_excerpt":"Model stealing poses a significant security risk in machine learning by enabling attackers to replicate a black-box model without access to its training data, thus jeopardizing intellectual property and exposing sensitive information. Recent methods that use pre-trained diffusion models for data synthesis improve efficiency and performance but rely heavily on manually crafted prompts, limiting automation and scalability, especially for attackers with little expertise. To assess the risks posed by open-source pre-trained models, we propose a more realistic threat model that eliminates the need "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2506.05867","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2506.05867/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2506.05867","created_at":"2026-07-05T11:17:11.676189+00:00"},{"alias_kind":"arxiv_version","alias_value":"2506.05867v1","created_at":"2026-07-05T11:17:11.676189+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2506.05867","created_at":"2026-07-05T11:17:11.676189+00:00"},{"alias_kind":"pith_short_12","alias_value":"QSCMUGVZTQVY","created_at":"2026-07-05T11:17:11.676189+00:00"},{"alias_kind":"pith_short_16","alias_value":"QSCMUGVZTQVYDUN5","created_at":"2026-07-05T11:17:11.676189+00:00"},{"alias_kind":"pith_short_8","alias_value":"QSCMUGVZ","created_at":"2026-07-05T11:17:11.676189+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/QSCMUGVZTQVYDUN5YIK5D66CTN","json":"https://pith.science/pith/QSCMUGVZTQVYDUN5YIK5D66CTN.json","graph_json":"https://pith.science/api/pith-number/QSCMUGVZTQVYDUN5YIK5D66CTN/graph.json","events_json":"https://pith.science/api/pith-number/QSCMUGVZTQVYDUN5YIK5D66CTN/events.json","paper":"https://pith.science/paper/QSCMUGVZ"},"agent_actions":{"view_html":"https://pith.science/pith/QSCMUGVZTQVYDUN5YIK5D66CTN","download_json":"https://pith.science/pith/QSCMUGVZTQVYDUN5YIK5D66CTN.json","view_paper":"https://pith.science/paper/QSCMUGVZ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2506.05867&json=true","fetch_graph":"https://pith.science/api/pith-number/QSCMUGVZTQVYDUN5YIK5D66CTN/graph.json","fetch_events":"https://pith.science/api/pith-number/QSCMUGVZTQVYDUN5YIK5D66CTN/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/QSCMUGVZTQVYDUN5YIK5D66CTN/action/timestamp_anchor","attest_storage":"https://pith.science/pith/QSCMUGVZTQVYDUN5YIK5D66CTN/action/storage_attestation","attest_author":"https://pith.science/pith/QSCMUGVZTQVYDUN5YIK5D66CTN/action/author_attestation","sign_citation":"https://pith.science/pith/QSCMUGVZTQVYDUN5YIK5D66CTN/action/citation_signature","submit_replication":"https://pith.science/pith/QSCMUGVZTQVYDUN5YIK5D66CTN/action/replication_record"}},"created_at":"2026-07-05T11:17:11.676189+00:00","updated_at":"2026-07-05T11:17:11.676189+00:00"}