{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:UGLNRESO7NZRPARK5Q2UYRVN2Z","short_pith_number":"pith:UGLNRESO","canonical_record":{"source":{"id":"2508.20424","kind":"arxiv","version":4},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-08-28T04:46:44Z","cross_cats_sorted":[],"title_canon_sha256":"9c974134ae12f45d705b772eda04ef27a180baca640b8fb975fba701de54eed0","abstract_canon_sha256":"d7fe0ab450bda2d85b8e8f817d4859b5b363eb0a85446ea9574844bff8cf7bf6"},"schema_version":"1.0"},"canonical_sha256":"a196d8924efb7317822aec354c46add652a2f2c8a1b743cdf65a284b94e396a0","source":{"kind":"arxiv","id":"2508.20424","version":4},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2508.20424","created_at":"2026-05-26T02:05:01Z"},{"alias_kind":"arxiv_version","alias_value":"2508.20424v4","created_at":"2026-05-26T02:05:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.20424","created_at":"2026-05-26T02:05:01Z"},{"alias_kind":"pith_short_12","alias_value":"UGLNRESO7NZR","created_at":"2026-05-26T02:05:01Z"},{"alias_kind":"pith_short_16","alias_value":"UGLNRESO7NZRPARK","created_at":"2026-05-26T02:05:01Z"},{"alias_kind":"pith_short_8","alias_value":"UGLNRESO","created_at":"2026-05-26T02:05:01Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:UGLNRESO7NZRPARK5Q2UYRVN2Z","target":"record","payload":{"canonical_record":{"source":{"id":"2508.20424","kind":"arxiv","version":4},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-08-28T04:46:44Z","cross_cats_sorted":[],"title_canon_sha256":"9c974134ae12f45d705b772eda04ef27a180baca640b8fb975fba701de54eed0","abstract_canon_sha256":"d7fe0ab450bda2d85b8e8f817d4859b5b363eb0a85446ea9574844bff8cf7bf6"},"schema_version":"1.0"},"canonical_sha256":"a196d8924efb7317822aec354c46add652a2f2c8a1b743cdf65a284b94e396a0","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T02:05:01.664642Z","signature_b64":"b9NBdU5HG9csksKo+SB9sdLgUU9vyafgUhNPG/HAgmNZgYWCEkO1Q9OqjMnrsDyk7OM4WQU84mfj1HNbKJGSDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a196d8924efb7317822aec354c46add652a2f2c8a1b743cdf65a284b94e396a0","last_reissued_at":"2026-05-26T02:05:01.663594Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T02:05:01.663594Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2508.20424","source_version":4,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T02:05:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"uesWPoB6HbHZBArq6A4rHk+SnhZvpXAgtmWUSYV00c2sGvXJiE60N1hO9GOsRT1BzwhBJHNTv87yGEa923r1Cw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T09:56:35.666065Z"},"content_sha256":"3b4302941fbd38578a351ca6e3305f2547ab4acea6290ad77565aa4220c51728","schema_version":"1.0","event_id":"sha256:3b4302941fbd38578a351ca6e3305f2547ab4acea6290ad77565aa4220c51728"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:UGLNRESO7NZRPARK5Q2UYRVN2Z","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Attacks on Approximate Caches in Text-to-Image Diffusion Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Desen Sun, Shuncheng Jie, Sihang Liu","submitted_at":"2025-08-28T04:46:44Z","abstract_excerpt":"Diffusion models are a powerful class of generative models that produce images and other content from user prompts, but they are computationally intensive. To mitigate this cost, recent academic and industry work has adopted approximate caching, which reuses intermediate states from similar prompts in a cache. While efficient, this optimization introduces new security risks by breaking isolation among users. This paper provides a comprehensive assessment of the security vulnerabilities introduced by approximate caching. First, we demonstrate a remote covert channel established with the approxi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.20424","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2508.20424/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T02:05:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"68xGX4hFGx4zY/sgBxt0tPRamsB9wKr7zUko0Ur4MCZ7ouO1rRS5tKETzMWTCP4ZYft0RuXPeK3wrMytyQaaDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T09:56:35.666679Z"},"content_sha256":"9d155be2c11483174dd3d749d755654bb860f6ca497cb577e0307c9dc1e080a2","schema_version":"1.0","event_id":"sha256:9d155be2c11483174dd3d749d755654bb860f6ca497cb577e0307c9dc1e080a2"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/UGLNRESO7NZRPARK5Q2UYRVN2Z/bundle.json","state_url":"https://pith.science/pith/UGLNRESO7NZRPARK5Q2UYRVN2Z/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/UGLNRESO7NZRPARK5Q2UYRVN2Z/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-27T09:56:35Z","links":{"resolver":"https://pith.science/pith/UGLNRESO7NZRPARK5Q2UYRVN2Z","bundle":"https://pith.science/pith/UGLNRESO7NZRPARK5Q2UYRVN2Z/bundle.json","state":"https://pith.science/pith/UGLNRESO7NZRPARK5Q2UYRVN2Z/state.json","well_known_bundle":"https://pith.science/.well-known/pith/UGLNRESO7NZRPARK5Q2UYRVN2Z/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:UGLNRESO7NZRPARK5Q2UYRVN2Z","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"d7fe0ab450bda2d85b8e8f817d4859b5b363eb0a85446ea9574844bff8cf7bf6","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-08-28T04:46:44Z","title_canon_sha256":"9c974134ae12f45d705b772eda04ef27a180baca640b8fb975fba701de54eed0"},"schema_version":"1.0","source":{"id":"2508.20424","kind":"arxiv","version":4}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2508.20424","created_at":"2026-05-26T02:05:01Z"},{"alias_kind":"arxiv_version","alias_value":"2508.20424v4","created_at":"2026-05-26T02:05:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.20424","created_at":"2026-05-26T02:05:01Z"},{"alias_kind":"pith_short_12","alias_value":"UGLNRESO7NZR","created_at":"2026-05-26T02:05:01Z"},{"alias_kind":"pith_short_16","alias_value":"UGLNRESO7NZRPARK","created_at":"2026-05-26T02:05:01Z"},{"alias_kind":"pith_short_8","alias_value":"UGLNRESO","created_at":"2026-05-26T02:05:01Z"}],"graph_snapshots":[{"event_id":"sha256:9d155be2c11483174dd3d749d755654bb860f6ca497cb577e0307c9dc1e080a2","target":"graph","created_at":"2026-05-26T02:05:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2508.20424/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Diffusion models are a powerful class of generative models that produce images and other content from user prompts, but they are computationally intensive. To mitigate this cost, recent academic and industry work has adopted approximate caching, which reuses intermediate states from similar prompts in a cache. While efficient, this optimization introduces new security risks by breaking isolation among users. This paper provides a comprehensive assessment of the security vulnerabilities introduced by approximate caching. First, we demonstrate a remote covert channel established with the approxi","authors_text":"Desen Sun, Shuncheng Jie, Sihang Liu","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-08-28T04:46:44Z","title":"Attacks on Approximate Caches in Text-to-Image Diffusion Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.20424","kind":"arxiv","version":4},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:3b4302941fbd38578a351ca6e3305f2547ab4acea6290ad77565aa4220c51728","target":"record","created_at":"2026-05-26T02:05:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"d7fe0ab450bda2d85b8e8f817d4859b5b363eb0a85446ea9574844bff8cf7bf6","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-08-28T04:46:44Z","title_canon_sha256":"9c974134ae12f45d705b772eda04ef27a180baca640b8fb975fba701de54eed0"},"schema_version":"1.0","source":{"id":"2508.20424","kind":"arxiv","version":4}},"canonical_sha256":"a196d8924efb7317822aec354c46add652a2f2c8a1b743cdf65a284b94e396a0","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a196d8924efb7317822aec354c46add652a2f2c8a1b743cdf65a284b94e396a0","first_computed_at":"2026-05-26T02:05:01.663594Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-26T02:05:01.663594Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"b9NBdU5HG9csksKo+SB9sdLgUU9vyafgUhNPG/HAgmNZgYWCEkO1Q9OqjMnrsDyk7OM4WQU84mfj1HNbKJGSDQ==","signature_status":"signed_v1","signed_at":"2026-05-26T02:05:01.664642Z","signed_message":"canonical_sha256_bytes"},"source_id":"2508.20424","source_kind":"arxiv","source_version":4}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:3b4302941fbd38578a351ca6e3305f2547ab4acea6290ad77565aa4220c51728","sha256:9d155be2c11483174dd3d749d755654bb860f6ca497cb577e0307c9dc1e080a2"],"state_sha256":"5fc04666b1afdbf88c0243f4ddd3eac61a2c69d55983865288f5e3565abdb7d2"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"PV/ayU47XxQ60BRjeyo1Jg5ZJOOMIR3Ti3PWpWNrgckeS5AbzcLJ5TPsM/hCHyfpqV0KR1f5gSXn8pceyIh7Cg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-27T09:56:35.669517Z","bundle_sha256":"8c524297ef4541325609e8777fd81fbebad316095fa7f5c0936fb1e4bce6c36b"}}