{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:TDDVIHE7UT7SCIW4O3R3TRIKW6","short_pith_number":"pith:TDDVIHE7","schema_version":"1.0","canonical_sha256":"98c7541c9fa4ff2122dc76e3b9c50ab7bd74f2575ab81a54139f1a7c3238e0c3","source":{"kind":"arxiv","id":"2311.07389","version":2},"attestation_state":"computed","paper":{"title":"Transpose Attack: Stealing Datasets with Bidirectional Training","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Guy Amit, Mosh Levy, Yisroel Mirsky","submitted_at":"2023-11-13T15:14:50Z","abstract_excerpt":"Deep neural networks are normally executed in the forward direction. However, in this work, we identify a vulnerability that enables models to be trained in both directions and on different tasks. Adversaries can exploit this capability to hide rogue models within seemingly legitimate models. In addition, in this work we show that neural networks can be taught to systematically memorize and retrieve specific samples from datasets. Together, these findings expose a novel method in which adversaries can exfiltrate datasets from protected learning environments under the guise of legitimate models"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2311.07389","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2023-11-13T15:14:50Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"dadf29e610dc4b514677da7ee5f300310de09dfce424530ac883dcf6e752c3b6","abstract_canon_sha256":"6290c6588e1831eb387c7da677e6e4abf54189fb0e4f31aa4976c37f3a494187"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:20:08.606585Z","signature_b64":"m0Wl0jnahTQh95mBCs3V++qCIeyUEKAHiNHwG8i5NEB4iWoYn5OFqAwGrWOESXA6GXR6SXwAi2MzSx7uglZHCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"98c7541c9fa4ff2122dc76e3b9c50ab7bd74f2575ab81a54139f1a7c3238e0c3","last_reissued_at":"2026-07-05T08:20:08.606044Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:20:08.606044Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Transpose Attack: Stealing Datasets with Bidirectional Training","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Guy Amit, Mosh Levy, Yisroel Mirsky","submitted_at":"2023-11-13T15:14:50Z","abstract_excerpt":"Deep neural networks are normally executed in the forward direction. However, in this work, we identify a vulnerability that enables models to be trained in both directions and on different tasks. Adversaries can exploit this capability to hide rogue models within seemingly legitimate models. In addition, in this work we show that neural networks can be taught to systematically memorize and retrieve specific samples from datasets. Together, these findings expose a novel method in which adversaries can exfiltrate datasets from protected learning environments under the guise of legitimate models"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2311.07389","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2311.07389/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2311.07389","created_at":"2026-07-05T08:20:08.606106+00:00"},{"alias_kind":"arxiv_version","alias_value":"2311.07389v2","created_at":"2026-07-05T08:20:08.606106+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2311.07389","created_at":"2026-07-05T08:20:08.606106+00:00"},{"alias_kind":"pith_short_12","alias_value":"TDDVIHE7UT7S","created_at":"2026-07-05T08:20:08.606106+00:00"},{"alias_kind":"pith_short_16","alias_value":"TDDVIHE7UT7SCIW4","created_at":"2026-07-05T08:20:08.606106+00:00"},{"alias_kind":"pith_short_8","alias_value":"TDDVIHE7","created_at":"2026-07-05T08:20:08.606106+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2509.00027","citing_title":"Mitigating Data Exfiltration Attacks through Layer-Wise Learning Rate Decay Fine-Tuning","ref_index":9,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/TDDVIHE7UT7SCIW4O3R3TRIKW6","json":"https://pith.science/pith/TDDVIHE7UT7SCIW4O3R3TRIKW6.json","graph_json":"https://pith.science/api/pith-number/TDDVIHE7UT7SCIW4O3R3TRIKW6/graph.json","events_json":"https://pith.science/api/pith-number/TDDVIHE7UT7SCIW4O3R3TRIKW6/events.json","paper":"https://pith.science/paper/TDDVIHE7"},"agent_actions":{"view_html":"https://pith.science/pith/TDDVIHE7UT7SCIW4O3R3TRIKW6","download_json":"https://pith.science/pith/TDDVIHE7UT7SCIW4O3R3TRIKW6.json","view_paper":"https://pith.science/paper/TDDVIHE7","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2311.07389&json=true","fetch_graph":"https://pith.science/api/pith-number/TDDVIHE7UT7SCIW4O3R3TRIKW6/graph.json","fetch_events":"https://pith.science/api/pith-number/TDDVIHE7UT7SCIW4O3R3TRIKW6/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/TDDVIHE7UT7SCIW4O3R3TRIKW6/action/timestamp_anchor","attest_storage":"https://pith.science/pith/TDDVIHE7UT7SCIW4O3R3TRIKW6/action/storage_attestation","attest_author":"https://pith.science/pith/TDDVIHE7UT7SCIW4O3R3TRIKW6/action/author_attestation","sign_citation":"https://pith.science/pith/TDDVIHE7UT7SCIW4O3R3TRIKW6/action/citation_signature","submit_replication":"https://pith.science/pith/TDDVIHE7UT7SCIW4O3R3TRIKW6/action/replication_record"}},"created_at":"2026-07-05T08:20:08.606106+00:00","updated_at":"2026-07-05T08:20:08.606106+00:00"}