{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:QVAHOLOXP6IHMWADN7NKPQEGWY","short_pith_number":"pith:QVAHOLOX","canonical_record":{"source":{"id":"2605.14591","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-14T09:00:56Z","cross_cats_sorted":[],"title_canon_sha256":"f167fe6ef3384c314a11a62991c561d41535b09f2959bdb115cf728b57fc03f5","abstract_canon_sha256":"e53acc1dd614bf9c0717dd6af39dbd7ca40be8b5b470bce5751d9d3d8e00446d"},"schema_version":"1.0"},"canonical_sha256":"8540772dd77f907658036fdaa7c086b6120083413dabdba3fda5f7b427ba6add","source":{"kind":"arxiv","id":"2605.14591","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.14591","created_at":"2026-05-17T23:39:05Z"},{"alias_kind":"arxiv_version","alias_value":"2605.14591v1","created_at":"2026-05-17T23:39:05Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.14591","created_at":"2026-05-17T23:39:05Z"},{"alias_kind":"pith_short_12","alias_value":"QVAHOLOXP6IH","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"QVAHOLOXP6IHMWAD","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"QVAHOLOX","created_at":"2026-05-18T12:33:37Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:QVAHOLOXP6IHMWADN7NKPQEGWY","target":"record","payload":{"canonical_record":{"source":{"id":"2605.14591","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-14T09:00:56Z","cross_cats_sorted":[],"title_canon_sha256":"f167fe6ef3384c314a11a62991c561d41535b09f2959bdb115cf728b57fc03f5","abstract_canon_sha256":"e53acc1dd614bf9c0717dd6af39dbd7ca40be8b5b470bce5751d9d3d8e00446d"},"schema_version":"1.0"},"canonical_sha256":"8540772dd77f907658036fdaa7c086b6120083413dabdba3fda5f7b427ba6add","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:39:05.243498Z","signature_b64":"sOU179WpUQO3C/RXWrfJXx+mZp3tmtzlkj0L2xh0DkANJpwMbkOLw1S8yTNRmu88aQ/ym17MDaF9o6j9tLtAAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8540772dd77f907658036fdaa7c086b6120083413dabdba3fda5f7b427ba6add","last_reissued_at":"2026-05-17T23:39:05.242961Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:39:05.242961Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.14591","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:39:05Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"tJmQV8BU015jf+4nZ+VepBpuEA+p0O0rvn18Ve9KsqgyMvP6/mCZWIdgTpGD+UmWjmzaFTyLE8Dv7avK9YUFBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T14:24:40.920902Z"},"content_sha256":"cfb47fb6535e6e36ebab19738a023e74e5d987df41392d4266845c4f03cd99ee","schema_version":"1.0","event_id":"sha256:cfb47fb6535e6e36ebab19738a023e74e5d987df41392d4266845c4f03cd99ee"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:QVAHOLOXP6IHMWADN7NKPQEGWY","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Privacy Auditing with Zero (0) Training Run","license":"http://creativecommons.org/licenses/by/4.0/","headline":"Zero-Run privacy auditing yields valid differential privacy bounds from fixed member and non-member datasets without any model retraining.","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Aur\\'elien Bellet, Linus Bleistein, Mathieu Even, Tudor Cebere","submitted_at":"2026-05-14T09:00:56Z","abstract_excerpt":"Privacy auditing provides empirical lower bounds on the differential privacy parameters of learning algorithms. Existing methods, however, require interventional access to the training pipeline, either to retrain multiple times or to randomize data inclusion. This is often infeasible for large deployed systems such as foundation models. We introduce Zero-Run privacy auditing, a post-hoc framework for auditing models using two fixed datasets: examples known to be training-set members and examples known to be non-members. In this observational regime, membership is no longer randomized; instead,"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"We introduce Zero-Run privacy auditing, a post-hoc framework for auditing models using two fixed datasets... propose two complementary corrections that yield valid privacy audits.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the distribution shift between member and non-member sets can be isolated from algorithmic leakage via the proposed adaptive-composition or pointwise-conditioning corrections without residual bias.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Zero-Run auditing supplies valid lower bounds on differential privacy parameters from fixed member and non-member datasets by modeling and correcting distribution-shift confounding via causal-inference techniques.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Zero-Run privacy auditing yields valid differential privacy bounds from fixed member and non-member datasets without any model retraining.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"a7764b4968568c4fce029c5e997f9967fb4a08f5d7dcb929dc4354f5a5a5cf13"},"source":{"id":"2605.14591","kind":"arxiv","version":1},"verdict":{"id":"667bd983-e8a7-4227-a31d-140ec081c67a","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-15T01:24:02.414081Z","strongest_claim":"We introduce Zero-Run privacy auditing, a post-hoc framework for auditing models using two fixed datasets... propose two complementary corrections that yield valid privacy audits.","one_line_summary":"Zero-Run auditing supplies valid lower bounds on differential privacy parameters from fixed member and non-member datasets by modeling and correcting distribution-shift confounding via causal-inference techniques.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the distribution shift between member and non-member sets can be isolated from algorithmic leakage via the proposed adaptive-composition or pointwise-conditioning corrections without residual bias.","pith_extraction_headline":"Zero-Run privacy auditing yields valid differential privacy bounds from fixed member and non-member datasets without any model retraining."},"references":{"count":42,"sample":[{"doi":"","year":2025,"title":"The hitchhiker’s guide to efficient, end-to-end, and tight dp auditing","work_id":"aab8c523-1506-462e-9db1-af6944f76fe3","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2019,"title":"The secret sharer: Evaluating and testing unintended memorization in neural networks","work_id":"8485e476-8a9d-42a8-b7fb-eab7384ce699","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2021,"title":"Extracting training data from large language models","work_id":"7d8cfcbb-971a-4428-b03b-ffbb0bef1530","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2023,"title":"Quantifying Memorization Across Neural Language Models","work_id":"35487ec1-b90b-4ace-95bd-1bce30064b2e","ref_index":4,"cited_arxiv_id":"2202.07646","is_internal_anchor":true},{"doi":"","year":2025,"title":"Tighter Privacy Auditing of DP-SGD in the Hidden State Threat Model","work_id":"500bea0e-4b14-4804-a5bf-5a19e92f71cd","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":42,"snapshot_sha256":"2a58e0129e9d1a0183de33a0c3581d98fb8658285c21cc8bc95bcd1c877142ef","internal_anchors":7},"formal_canon":{"evidence_count":2,"snapshot_sha256":"739fba2d185eb54c33c9b178164e382de38d944c0dbcfe1b9cb33d159c78e34c"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"667bd983-e8a7-4227-a31d-140ec081c67a"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:39:05Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"IKOYkpAyilaAUyF9x5wRL1awZR7GMdpgUewwbhSgCZ59dMVRdjJR5OPeRyfwMvEqBbbkLL3LI4tPDYJV7l0FBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T14:24:40.921575Z"},"content_sha256":"63c368ccbbb521a0bee3dd0df64c871dffd9221b4eaba9ae0276520c66bdfc92","schema_version":"1.0","event_id":"sha256:63c368ccbbb521a0bee3dd0df64c871dffd9221b4eaba9ae0276520c66bdfc92"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/QVAHOLOXP6IHMWADN7NKPQEGWY/bundle.json","state_url":"https://pith.science/pith/QVAHOLOXP6IHMWADN7NKPQEGWY/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/QVAHOLOXP6IHMWADN7NKPQEGWY/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-03T14:24:40Z","links":{"resolver":"https://pith.science/pith/QVAHOLOXP6IHMWADN7NKPQEGWY","bundle":"https://pith.science/pith/QVAHOLOXP6IHMWADN7NKPQEGWY/bundle.json","state":"https://pith.science/pith/QVAHOLOXP6IHMWADN7NKPQEGWY/state.json","well_known_bundle":"https://pith.science/.well-known/pith/QVAHOLOXP6IHMWADN7NKPQEGWY/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:QVAHOLOXP6IHMWADN7NKPQEGWY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e53acc1dd614bf9c0717dd6af39dbd7ca40be8b5b470bce5751d9d3d8e00446d","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-14T09:00:56Z","title_canon_sha256":"f167fe6ef3384c314a11a62991c561d41535b09f2959bdb115cf728b57fc03f5"},"schema_version":"1.0","source":{"id":"2605.14591","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.14591","created_at":"2026-05-17T23:39:05Z"},{"alias_kind":"arxiv_version","alias_value":"2605.14591v1","created_at":"2026-05-17T23:39:05Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.14591","created_at":"2026-05-17T23:39:05Z"},{"alias_kind":"pith_short_12","alias_value":"QVAHOLOXP6IH","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"QVAHOLOXP6IHMWAD","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"QVAHOLOX","created_at":"2026-05-18T12:33:37Z"}],"graph_snapshots":[{"event_id":"sha256:63c368ccbbb521a0bee3dd0df64c871dffd9221b4eaba9ae0276520c66bdfc92","target":"graph","created_at":"2026-05-17T23:39:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"We introduce Zero-Run privacy auditing, a post-hoc framework for auditing models using two fixed datasets... propose two complementary corrections that yield valid privacy audits."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That the distribution shift between member and non-member sets can be isolated from algorithmic leakage via the proposed adaptive-composition or pointwise-conditioning corrections without residual bias."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"Zero-Run auditing supplies valid lower bounds on differential privacy parameters from fixed member and non-member datasets by modeling and correcting distribution-shift confounding via causal-inference techniques."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Zero-Run privacy auditing yields valid differential privacy bounds from fixed member and non-member datasets without any model retraining."}],"snapshot_sha256":"a7764b4968568c4fce029c5e997f9967fb4a08f5d7dcb929dc4354f5a5a5cf13"},"formal_canon":{"evidence_count":2,"snapshot_sha256":"739fba2d185eb54c33c9b178164e382de38d944c0dbcfe1b9cb33d159c78e34c"},"paper":{"abstract_excerpt":"Privacy auditing provides empirical lower bounds on the differential privacy parameters of learning algorithms. Existing methods, however, require interventional access to the training pipeline, either to retrain multiple times or to randomize data inclusion. This is often infeasible for large deployed systems such as foundation models. We introduce Zero-Run privacy auditing, a post-hoc framework for auditing models using two fixed datasets: examples known to be training-set members and examples known to be non-members. In this observational regime, membership is no longer randomized; instead,","authors_text":"Aur\\'elien Bellet, Linus Bleistein, Mathieu Even, Tudor Cebere","cross_cats":[],"headline":"Zero-Run privacy auditing yields valid differential privacy bounds from fixed member and non-member datasets without any model retraining.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-14T09:00:56Z","title":"Privacy Auditing with Zero (0) Training Run"},"references":{"count":42,"internal_anchors":7,"resolved_work":42,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"The hitchhiker’s guide to efficient, end-to-end, and tight dp auditing","work_id":"aab8c523-1506-462e-9db1-af6944f76fe3","year":2025},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"The secret sharer: Evaluating and testing unintended memorization in neural networks","work_id":"8485e476-8a9d-42a8-b7fb-eab7384ce699","year":2019},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"Extracting training data from large language models","work_id":"7d8cfcbb-971a-4428-b03b-ffbb0bef1530","year":2021},{"cited_arxiv_id":"2202.07646","doi":"","is_internal_anchor":true,"ref_index":4,"title":"Quantifying Memorization Across Neural Language Models","work_id":"35487ec1-b90b-4ace-95bd-1bce30064b2e","year":2023},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Tighter Privacy Auditing of DP-SGD in the Hidden State Threat Model","work_id":"500bea0e-4b14-4804-a5bf-5a19e92f71cd","year":2025}],"snapshot_sha256":"2a58e0129e9d1a0183de33a0c3581d98fb8658285c21cc8bc95bcd1c877142ef"},"source":{"id":"2605.14591","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-15T01:24:02.414081Z","id":"667bd983-e8a7-4227-a31d-140ec081c67a","model_set":{"reader":"grok-4.3"},"one_line_summary":"Zero-Run auditing supplies valid lower bounds on differential privacy parameters from fixed member and non-member datasets by modeling and correcting distribution-shift confounding via causal-inference techniques.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Zero-Run privacy auditing yields valid differential privacy bounds from fixed member and non-member datasets without any model retraining.","strongest_claim":"We introduce Zero-Run privacy auditing, a post-hoc framework for auditing models using two fixed datasets... propose two complementary corrections that yield valid privacy audits.","weakest_assumption":"That the distribution shift between member and non-member sets can be isolated from algorithmic leakage via the proposed adaptive-composition or pointwise-conditioning corrections without residual bias."}},"verdict_id":"667bd983-e8a7-4227-a31d-140ec081c67a"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:cfb47fb6535e6e36ebab19738a023e74e5d987df41392d4266845c4f03cd99ee","target":"record","created_at":"2026-05-17T23:39:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e53acc1dd614bf9c0717dd6af39dbd7ca40be8b5b470bce5751d9d3d8e00446d","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-14T09:00:56Z","title_canon_sha256":"f167fe6ef3384c314a11a62991c561d41535b09f2959bdb115cf728b57fc03f5"},"schema_version":"1.0","source":{"id":"2605.14591","kind":"arxiv","version":1}},"canonical_sha256":"8540772dd77f907658036fdaa7c086b6120083413dabdba3fda5f7b427ba6add","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"8540772dd77f907658036fdaa7c086b6120083413dabdba3fda5f7b427ba6add","first_computed_at":"2026-05-17T23:39:05.242961Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:39:05.242961Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"sOU179WpUQO3C/RXWrfJXx+mZp3tmtzlkj0L2xh0DkANJpwMbkOLw1S8yTNRmu88aQ/ym17MDaF9o6j9tLtAAg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:39:05.243498Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.14591","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:cfb47fb6535e6e36ebab19738a023e74e5d987df41392d4266845c4f03cd99ee","sha256:63c368ccbbb521a0bee3dd0df64c871dffd9221b4eaba9ae0276520c66bdfc92"],"state_sha256":"63bb3826df16d90b24ce3e2fba9be425ddd0adabe1480cbebaaab2f5ca436b20"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/9eqEoxQtX6jrKzAtlT6pf7+c1CUnOtpAdE31wbh2/0wOhCrHnsOTltUElmkllPZIAKOchv/QKd0PsixNIy5Bg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-03T14:24:40.924197Z","bundle_sha256":"2e060d08cb002a4a1c885de29c3c80d80faf6ab6d9f86d9156615069a470d7a0"}}