{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:TFXJMZOYKSWUZHGJV3JTGTRKX7","short_pith_number":"pith:TFXJMZOY","canonical_record":{"source":{"id":"2606.03381","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T09:25:29Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"02873b45f292880db4888fd8d7107add8ad6e8737f2afd7fe7cfc0d3140ba7b5","abstract_canon_sha256":"828aaabc752dc67bcf2d2f71e0bdb9adcc875dc26b42098796fa1ad5e625a2a9"},"schema_version":"1.0"},"canonical_sha256":"996e9665d854ad4c9cc9aed3334e2abfc0e292b14e5f55e8bddca253368a6085","source":{"kind":"arxiv","id":"2606.03381","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.03381","created_at":"2026-06-03T01:05:56Z"},{"alias_kind":"arxiv_version","alias_value":"2606.03381v1","created_at":"2026-06-03T01:05:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.03381","created_at":"2026-06-03T01:05:56Z"},{"alias_kind":"pith_short_12","alias_value":"TFXJMZOYKSWU","created_at":"2026-06-03T01:05:56Z"},{"alias_kind":"pith_short_16","alias_value":"TFXJMZOYKSWUZHGJ","created_at":"2026-06-03T01:05:56Z"},{"alias_kind":"pith_short_8","alias_value":"TFXJMZOY","created_at":"2026-06-03T01:05:56Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:TFXJMZOYKSWUZHGJV3JTGTRKX7","target":"record","payload":{"canonical_record":{"source":{"id":"2606.03381","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T09:25:29Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"02873b45f292880db4888fd8d7107add8ad6e8737f2afd7fe7cfc0d3140ba7b5","abstract_canon_sha256":"828aaabc752dc67bcf2d2f71e0bdb9adcc875dc26b42098796fa1ad5e625a2a9"},"schema_version":"1.0"},"canonical_sha256":"996e9665d854ad4c9cc9aed3334e2abfc0e292b14e5f55e8bddca253368a6085","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-03T01:05:56.433866Z","signature_b64":"PHq0CDu8jyKX4TgIkycqJCiASGasSbtzdXt2nsaE6NT7wyFTpSc/s2+qPArn4om84lMQ2NIA8qMoO3+tiC7KDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"996e9665d854ad4c9cc9aed3334e2abfc0e292b14e5f55e8bddca253368a6085","last_reissued_at":"2026-06-03T01:05:56.433477Z","signature_status":"signed_v1","first_computed_at":"2026-06-03T01:05:56.433477Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.03381","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"tTs+Fm+qUpz/UFB91Wds1P9/dVGigANQVgbpvfsujP1/nJ7uGA743F6eFO1CHSHnhhOK3i4TjtSYmuHfrQ/IBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-29T08:10:27.717865Z"},"content_sha256":"5da8ddf6bb1e22583b5bce13e8efb9a21fb09d9fcc21dd985a3d1f3d357a87a6","schema_version":"1.0","event_id":"sha256:5da8ddf6bb1e22583b5bce13e8efb9a21fb09d9fcc21dd985a3d1f3d357a87a6"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:TFXJMZOYKSWUZHGJV3JTGTRKX7","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"AI Model Extraction Attacks: Bypassing Single-Client Assumptions in Defenses","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Gustavo S\\'anchez, Johannes F. Loevenich, Laurin Holz, Maxime Schwarzer, Roberto Rigolin F. Lopes, Thies M\\\"ohlenhof, Tobias H\\\"urten, Veit Hagenmeyer","submitted_at":"2026-06-02T09:25:29Z","abstract_excerpt":"Ensuring the protection of Artificial Intelligence (AI) models deployed in military Command and Control (C2) systems and critical infrastructure is essential for maintaining information superiority. Model Extraction Attacks (MEAs) pose a significant threat, as they enable adversaries to replicate proprietary models, compromise protected information, and prepare offline adversarial attacks. However, current defense strategies predominantly rely on the Single Client Assumption (SCA), which is the implicit assumption that attacks originate from isolated identities. This work systematically demons"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.03381","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.03381/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wlr66Y5pMennYm5euLgQzWun90gg0n+94Nu+Pmi+s3BdgC+KwfAulqMQgmBxz6FXRf+cWbsbCB/oElVoiLu1Aw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-29T08:10:27.718231Z"},"content_sha256":"314a936aa59d470ead65a3c3d1a73cb756526d37dba73883ded738b01c21c69c","schema_version":"1.0","event_id":"sha256:314a936aa59d470ead65a3c3d1a73cb756526d37dba73883ded738b01c21c69c"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7/bundle.json","state_url":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-29T08:10:27Z","links":{"resolver":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7","bundle":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7/bundle.json","state":"https://pith.science/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7/state.json","well_known_bundle":"https://pith.science/.well-known/pith/TFXJMZOYKSWUZHGJV3JTGTRKX7/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:TFXJMZOYKSWUZHGJV3JTGTRKX7","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"828aaabc752dc67bcf2d2f71e0bdb9adcc875dc26b42098796fa1ad5e625a2a9","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T09:25:29Z","title_canon_sha256":"02873b45f292880db4888fd8d7107add8ad6e8737f2afd7fe7cfc0d3140ba7b5"},"schema_version":"1.0","source":{"id":"2606.03381","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.03381","created_at":"2026-06-03T01:05:56Z"},{"alias_kind":"arxiv_version","alias_value":"2606.03381v1","created_at":"2026-06-03T01:05:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.03381","created_at":"2026-06-03T01:05:56Z"},{"alias_kind":"pith_short_12","alias_value":"TFXJMZOYKSWU","created_at":"2026-06-03T01:05:56Z"},{"alias_kind":"pith_short_16","alias_value":"TFXJMZOYKSWUZHGJ","created_at":"2026-06-03T01:05:56Z"},{"alias_kind":"pith_short_8","alias_value":"TFXJMZOY","created_at":"2026-06-03T01:05:56Z"}],"graph_snapshots":[{"event_id":"sha256:314a936aa59d470ead65a3c3d1a73cb756526d37dba73883ded738b01c21c69c","target":"graph","created_at":"2026-06-03T01:05:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.03381/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Ensuring the protection of Artificial Intelligence (AI) models deployed in military Command and Control (C2) systems and critical infrastructure is essential for maintaining information superiority. Model Extraction Attacks (MEAs) pose a significant threat, as they enable adversaries to replicate proprietary models, compromise protected information, and prepare offline adversarial attacks. However, current defense strategies predominantly rely on the Single Client Assumption (SCA), which is the implicit assumption that attacks originate from isolated identities. This work systematically demons","authors_text":"Gustavo S\\'anchez, Johannes F. Loevenich, Laurin Holz, Maxime Schwarzer, Roberto Rigolin F. Lopes, Thies M\\\"ohlenhof, Tobias H\\\"urten, Veit Hagenmeyer","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T09:25:29Z","title":"AI Model Extraction Attacks: Bypassing Single-Client Assumptions in Defenses"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.03381","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5da8ddf6bb1e22583b5bce13e8efb9a21fb09d9fcc21dd985a3d1f3d357a87a6","target":"record","created_at":"2026-06-03T01:05:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"828aaabc752dc67bcf2d2f71e0bdb9adcc875dc26b42098796fa1ad5e625a2a9","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T09:25:29Z","title_canon_sha256":"02873b45f292880db4888fd8d7107add8ad6e8737f2afd7fe7cfc0d3140ba7b5"},"schema_version":"1.0","source":{"id":"2606.03381","kind":"arxiv","version":1}},"canonical_sha256":"996e9665d854ad4c9cc9aed3334e2abfc0e292b14e5f55e8bddca253368a6085","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"996e9665d854ad4c9cc9aed3334e2abfc0e292b14e5f55e8bddca253368a6085","first_computed_at":"2026-06-03T01:05:56.433477Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-03T01:05:56.433477Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"PHq0CDu8jyKX4TgIkycqJCiASGasSbtzdXt2nsaE6NT7wyFTpSc/s2+qPArn4om84lMQ2NIA8qMoO3+tiC7KDQ==","signature_status":"signed_v1","signed_at":"2026-06-03T01:05:56.433866Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.03381","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:5da8ddf6bb1e22583b5bce13e8efb9a21fb09d9fcc21dd985a3d1f3d357a87a6","sha256:314a936aa59d470ead65a3c3d1a73cb756526d37dba73883ded738b01c21c69c"],"state_sha256":"4840ed6e5ee9ae7e911bf246327000adc8a97f80d99e5fb3eeefb65a11252a9b"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"0USnsNQj8ggCH0Vzx2EwAHYlPmvuVX1JUCfgXX5CnKM0FKfN7XBE+CGRJEUA5PGMmrSnZRSymIgsaPaf/ghsDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-29T08:10:27.720311Z","bundle_sha256":"34f34e350b176c0b9fe2f5eb69ed2e5ada792aec2a934e7c056b3bebaa3c3e80"}}