{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:RANDFUSCA74YOCS4F4DGYSYPA3","short_pith_number":"pith:RANDFUSC","schema_version":"1.0","canonical_sha256":"881a32d24207f9870a5c2f066c4b0f06cdcc1b40264a85101e6457b81bf6a507","source":{"kind":"arxiv","id":"2305.09684","version":1},"attestation_state":"computed","paper":{"title":"Decision-based iterative fragile watermarking for model integrity verification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Hang Su, Heng Yin, Xinpeng Zhang, Zhaoxia Yin, Zhenzhe Gao","submitted_at":"2023-05-13T10:36:11Z","abstract_excerpt":"Typically, foundation models are hosted on cloud servers to meet the high demand for their services. However, this exposes them to security risks, as attackers can modify them after uploading to the cloud or transferring from a local system. To address this issue, we propose an iterative decision-based fragile watermarking algorithm that transforms normal training samples into fragile samples that are sensitive to model changes. We then compare the output of sensitive samples from the original model to that of the compromised model during validation to assess the model's completeness.The propo"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2305.09684","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2023-05-13T10:36:11Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"a6ec014be375dbd5f7cb8704e62e38b4fe977b5cb9ab16f28de8286272f552dd","abstract_canon_sha256":"d062fcf96e6a784839d8f0687ffa6e4c7ecf37a3bf66880862e2e1583cbcde3f"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:10:52.658216Z","signature_b64":"12/NhIVXPZMg2yXBVh9sMQoVj+A1D4LT1Q2r7QvRn7EZZkE7/4F9A8o3/E0T84jsRDYnXP7HwjBLgSioNyVhDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"881a32d24207f9870a5c2f066c4b0f06cdcc1b40264a85101e6457b81bf6a507","last_reissued_at":"2026-07-05T06:10:52.657796Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:10:52.657796Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Decision-based iterative fragile watermarking for model integrity verification","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Hang Su, Heng Yin, Xinpeng Zhang, Zhaoxia Yin, Zhenzhe Gao","submitted_at":"2023-05-13T10:36:11Z","abstract_excerpt":"Typically, foundation models are hosted on cloud servers to meet the high demand for their services. However, this exposes them to security risks, as attackers can modify them after uploading to the cloud or transferring from a local system. To address this issue, we propose an iterative decision-based fragile watermarking algorithm that transforms normal training samples into fragile samples that are sensitive to model changes. We then compare the output of sensitive samples from the original model to that of the compromised model during validation to assess the model's completeness.The propo"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2305.09684","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2305.09684/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2305.09684","created_at":"2026-07-05T06:10:52.657854+00:00"},{"alias_kind":"arxiv_version","alias_value":"2305.09684v1","created_at":"2026-07-05T06:10:52.657854+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2305.09684","created_at":"2026-07-05T06:10:52.657854+00:00"},{"alias_kind":"pith_short_12","alias_value":"RANDFUSCA74Y","created_at":"2026-07-05T06:10:52.657854+00:00"},{"alias_kind":"pith_short_16","alias_value":"RANDFUSCA74YOCS4","created_at":"2026-07-05T06:10:52.657854+00:00"},{"alias_kind":"pith_short_8","alias_value":"RANDFUSC","created_at":"2026-07-05T06:10:52.657854+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2412.16257","citing_title":"PromptLA: Towards Integrity Verification of Black-box Text-to-Image Diffusion Models","ref_index":44,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/RANDFUSCA74YOCS4F4DGYSYPA3","json":"https://pith.science/pith/RANDFUSCA74YOCS4F4DGYSYPA3.json","graph_json":"https://pith.science/api/pith-number/RANDFUSCA74YOCS4F4DGYSYPA3/graph.json","events_json":"https://pith.science/api/pith-number/RANDFUSCA74YOCS4F4DGYSYPA3/events.json","paper":"https://pith.science/paper/RANDFUSC"},"agent_actions":{"view_html":"https://pith.science/pith/RANDFUSCA74YOCS4F4DGYSYPA3","download_json":"https://pith.science/pith/RANDFUSCA74YOCS4F4DGYSYPA3.json","view_paper":"https://pith.science/paper/RANDFUSC","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2305.09684&json=true","fetch_graph":"https://pith.science/api/pith-number/RANDFUSCA74YOCS4F4DGYSYPA3/graph.json","fetch_events":"https://pith.science/api/pith-number/RANDFUSCA74YOCS4F4DGYSYPA3/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/RANDFUSCA74YOCS4F4DGYSYPA3/action/timestamp_anchor","attest_storage":"https://pith.science/pith/RANDFUSCA74YOCS4F4DGYSYPA3/action/storage_attestation","attest_author":"https://pith.science/pith/RANDFUSCA74YOCS4F4DGYSYPA3/action/author_attestation","sign_citation":"https://pith.science/pith/RANDFUSCA74YOCS4F4DGYSYPA3/action/citation_signature","submit_replication":"https://pith.science/pith/RANDFUSCA74YOCS4F4DGYSYPA3/action/replication_record"}},"created_at":"2026-07-05T06:10:52.657854+00:00","updated_at":"2026-07-05T06:10:52.657854+00:00"}