{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:UKJLUPEADC2NHQEJGG6AAPA7W4","short_pith_number":"pith:UKJLUPEA","schema_version":"1.0","canonical_sha256":"a292ba3c8018b4d3c08931bc003c1fb716e02c803af97e79b8f92599b7eff04a","source":{"kind":"arxiv","id":"2502.16086","version":1},"attestation_state":"computed","paper":{"title":"Stealing Training Data from Large Language Models in Decentralized Training through Activation Inversion Attack","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chenxi Dai, Lin Lu, Pan Zhou","submitted_at":"2025-02-22T05:19:20Z","abstract_excerpt":"Decentralized training has become a resource-efficient framework to democratize the training of large language models (LLMs). However, the privacy risks associated with this framework, particularly due to the potential inclusion of sensitive data in training datasets, remain unexplored. This paper identifies a novel and realistic attack surface: the privacy leakage from training data in decentralized training, and proposes \\textit{activation inversion attack} (AIA) for the first time. AIA first constructs a shadow dataset comprising text labels and corresponding activations using public datase"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2502.16086","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-02-22T05:19:20Z","cross_cats_sorted":[],"title_canon_sha256":"a08da4692aa0574b772122327a041794bbee010754d7ffa324cf2675ba971e7d","abstract_canon_sha256":"fb4d793bc3d6f3108e64fb6d885c03ae5928f49f81ac6c40122c3c3658e7c105"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:18:20.799924Z","signature_b64":"AEVmS44qGq/yxXs0GNEdb0lE3jcHJ1f2WVPqqYnYiJ3K4Tr9iTGpWqiZTdWXEb00qvsAZbhOaNYX9YPo9IRoAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a292ba3c8018b4d3c08931bc003c1fb716e02c803af97e79b8f92599b7eff04a","last_reissued_at":"2026-07-05T10:18:20.799444Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:18:20.799444Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Stealing Training Data from Large Language Models in Decentralized Training through Activation Inversion Attack","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chenxi Dai, Lin Lu, Pan Zhou","submitted_at":"2025-02-22T05:19:20Z","abstract_excerpt":"Decentralized training has become a resource-efficient framework to democratize the training of large language models (LLMs). However, the privacy risks associated with this framework, particularly due to the potential inclusion of sensitive data in training datasets, remain unexplored. This paper identifies a novel and realistic attack surface: the privacy leakage from training data in decentralized training, and proposes \\textit{activation inversion attack} (AIA) for the first time. AIA first constructs a shadow dataset comprising text labels and corresponding activations using public datase"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2502.16086","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2502.16086/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2502.16086","created_at":"2026-07-05T10:18:20.799503+00:00"},{"alias_kind":"arxiv_version","alias_value":"2502.16086v1","created_at":"2026-07-05T10:18:20.799503+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2502.16086","created_at":"2026-07-05T10:18:20.799503+00:00"},{"alias_kind":"pith_short_12","alias_value":"UKJLUPEADC2N","created_at":"2026-07-05T10:18:20.799503+00:00"},{"alias_kind":"pith_short_16","alias_value":"UKJLUPEADC2NHQEJ","created_at":"2026-07-05T10:18:20.799503+00:00"},{"alias_kind":"pith_short_8","alias_value":"UKJLUPEA","created_at":"2026-07-05T10:18:20.799503+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2506.22521","citing_title":"A Survey on Model Extraction Attacks and Defenses for Large Language Models","ref_index":11,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/UKJLUPEADC2NHQEJGG6AAPA7W4","json":"https://pith.science/pith/UKJLUPEADC2NHQEJGG6AAPA7W4.json","graph_json":"https://pith.science/api/pith-number/UKJLUPEADC2NHQEJGG6AAPA7W4/graph.json","events_json":"https://pith.science/api/pith-number/UKJLUPEADC2NHQEJGG6AAPA7W4/events.json","paper":"https://pith.science/paper/UKJLUPEA"},"agent_actions":{"view_html":"https://pith.science/pith/UKJLUPEADC2NHQEJGG6AAPA7W4","download_json":"https://pith.science/pith/UKJLUPEADC2NHQEJGG6AAPA7W4.json","view_paper":"https://pith.science/paper/UKJLUPEA","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2502.16086&json=true","fetch_graph":"https://pith.science/api/pith-number/UKJLUPEADC2NHQEJGG6AAPA7W4/graph.json","fetch_events":"https://pith.science/api/pith-number/UKJLUPEADC2NHQEJGG6AAPA7W4/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/UKJLUPEADC2NHQEJGG6AAPA7W4/action/timestamp_anchor","attest_storage":"https://pith.science/pith/UKJLUPEADC2NHQEJGG6AAPA7W4/action/storage_attestation","attest_author":"https://pith.science/pith/UKJLUPEADC2NHQEJGG6AAPA7W4/action/author_attestation","sign_citation":"https://pith.science/pith/UKJLUPEADC2NHQEJGG6AAPA7W4/action/citation_signature","submit_replication":"https://pith.science/pith/UKJLUPEADC2NHQEJGG6AAPA7W4/action/replication_record"}},"created_at":"2026-07-05T10:18:20.799503+00:00","updated_at":"2026-07-05T10:18:20.799503+00:00"}