{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:UL7T5KV6CEJQSLJSPFJ37EVUH3","short_pith_number":"pith:UL7T5KV6","canonical_record":{"source":{"id":"2508.03098","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2025-08-05T05:22:13Z","cross_cats_sorted":[],"title_canon_sha256":"9710fd7f213b5eead800205274a0512c34614c16609fddd442424123444cb17e","abstract_canon_sha256":"8dfb2cdee9114ddf2f63720eea174964b10bab5ddbe9dd041f84f568514d86c5"},"schema_version":"1.0"},"canonical_sha256":"a2ff3eaabe1113092d327953bf92b43eed24b29e448c4966cf7ba48680ca7037","source":{"kind":"arxiv","id":"2508.03098","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2508.03098","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"arxiv_version","alias_value":"2508.03098v2","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.03098","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"pith_short_12","alias_value":"UL7T5KV6CEJQ","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"pith_short_16","alias_value":"UL7T5KV6CEJQSLJS","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"pith_short_8","alias_value":"UL7T5KV6","created_at":"2026-06-03T01:05:05Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:UL7T5KV6CEJQSLJSPFJ37EVUH3","target":"record","payload":{"canonical_record":{"source":{"id":"2508.03098","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2025-08-05T05:22:13Z","cross_cats_sorted":[],"title_canon_sha256":"9710fd7f213b5eead800205274a0512c34614c16609fddd442424123444cb17e","abstract_canon_sha256":"8dfb2cdee9114ddf2f63720eea174964b10bab5ddbe9dd041f84f568514d86c5"},"schema_version":"1.0"},"canonical_sha256":"a2ff3eaabe1113092d327953bf92b43eed24b29e448c4966cf7ba48680ca7037","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-03T01:05:05.306130Z","signature_b64":"evNTt63CfyzTGul1BKZhns2c4kAi2On57kyOKx46sd434YgpYUoLb1MIoCRI2MsGN6u57nLLgqkBrxZ7foa0BA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a2ff3eaabe1113092d327953bf92b43eed24b29e448c4966cf7ba48680ca7037","last_reissued_at":"2026-06-03T01:05:05.305577Z","signature_status":"signed_v1","first_computed_at":"2026-06-03T01:05:05.305577Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2508.03098","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:05Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZvTOZPKWnC6PJV4Hpqc/qR6adn74BJKgfolfhQdx98om6mq7UOWUEF2hArn+Fa4rR9ZsXklxklTHXM3FvQHcBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T06:15:29.044673Z"},"content_sha256":"e5e9c902481b7c9f6487d911e08af0ce0008f0b275bb20b8269be684e41c8b1f","schema_version":"1.0","event_id":"sha256:e5e9c902481b7c9f6487d911e08af0ce0008f0b275bb20b8269be684e41c8b1f"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:UL7T5KV6CEJQSLJSPFJ37EVUH3","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Privacy-Aware Decoding: Mitigating Privacy Leakage of Large Language Models in Retrieval-Augmented Generation","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Baixiang Huang, Haoran Wang, Kai Shu, Xiongxiao Xu","submitted_at":"2025-08-05T05:22:13Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) enhances the factual accuracy of large language models (LLMs) by conditioning outputs on external knowledge sources. However, when retrieval involves private or sensitive data, RAG systems are susceptible to extraction attacks that can leak confidential information through generated responses. We propose Privacy-Aware Decoding (PAD), a lightweight, inference-time defense that adaptively injects calibrated Gaussian noise into token logits during generation. PAD integrates confidence-based screening to selectively protect high-risk tokens, efficient sensitivi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.03098","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2508.03098/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:05Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"bEiBJQX3E2X03fMiONvgN/nmPqGxDvtDj5AXjmIVMagej5GnTD0+BYT9FS+SH9iSojwdCGShQGNLsieMCYr5Cg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T06:15:29.045461Z"},"content_sha256":"431151fbed319af3f954f074246b7f1a1fd7202d34cb5270602baee6dd494a34","schema_version":"1.0","event_id":"sha256:431151fbed319af3f954f074246b7f1a1fd7202d34cb5270602baee6dd494a34"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/UL7T5KV6CEJQSLJSPFJ37EVUH3/bundle.json","state_url":"https://pith.science/pith/UL7T5KV6CEJQSLJSPFJ37EVUH3/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/UL7T5KV6CEJQSLJSPFJ37EVUH3/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-09T06:15:29Z","links":{"resolver":"https://pith.science/pith/UL7T5KV6CEJQSLJSPFJ37EVUH3","bundle":"https://pith.science/pith/UL7T5KV6CEJQSLJSPFJ37EVUH3/bundle.json","state":"https://pith.science/pith/UL7T5KV6CEJQSLJSPFJ37EVUH3/state.json","well_known_bundle":"https://pith.science/.well-known/pith/UL7T5KV6CEJQSLJSPFJ37EVUH3/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:UL7T5KV6CEJQSLJSPFJ37EVUH3","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"8dfb2cdee9114ddf2f63720eea174964b10bab5ddbe9dd041f84f568514d86c5","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2025-08-05T05:22:13Z","title_canon_sha256":"9710fd7f213b5eead800205274a0512c34614c16609fddd442424123444cb17e"},"schema_version":"1.0","source":{"id":"2508.03098","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2508.03098","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"arxiv_version","alias_value":"2508.03098v2","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.03098","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"pith_short_12","alias_value":"UL7T5KV6CEJQ","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"pith_short_16","alias_value":"UL7T5KV6CEJQSLJS","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"pith_short_8","alias_value":"UL7T5KV6","created_at":"2026-06-03T01:05:05Z"}],"graph_snapshots":[{"event_id":"sha256:431151fbed319af3f954f074246b7f1a1fd7202d34cb5270602baee6dd494a34","target":"graph","created_at":"2026-06-03T01:05:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2508.03098/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Retrieval-Augmented Generation (RAG) enhances the factual accuracy of large language models (LLMs) by conditioning outputs on external knowledge sources. However, when retrieval involves private or sensitive data, RAG systems are susceptible to extraction attacks that can leak confidential information through generated responses. We propose Privacy-Aware Decoding (PAD), a lightweight, inference-time defense that adaptively injects calibrated Gaussian noise into token logits during generation. PAD integrates confidence-based screening to selectively protect high-risk tokens, efficient sensitivi","authors_text":"Baixiang Huang, Haoran Wang, Kai Shu, Xiongxiao Xu","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2025-08-05T05:22:13Z","title":"Privacy-Aware Decoding: Mitigating Privacy Leakage of Large Language Models in Retrieval-Augmented Generation"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.03098","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e5e9c902481b7c9f6487d911e08af0ce0008f0b275bb20b8269be684e41c8b1f","target":"record","created_at":"2026-06-03T01:05:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"8dfb2cdee9114ddf2f63720eea174964b10bab5ddbe9dd041f84f568514d86c5","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2025-08-05T05:22:13Z","title_canon_sha256":"9710fd7f213b5eead800205274a0512c34614c16609fddd442424123444cb17e"},"schema_version":"1.0","source":{"id":"2508.03098","kind":"arxiv","version":2}},"canonical_sha256":"a2ff3eaabe1113092d327953bf92b43eed24b29e448c4966cf7ba48680ca7037","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a2ff3eaabe1113092d327953bf92b43eed24b29e448c4966cf7ba48680ca7037","first_computed_at":"2026-06-03T01:05:05.305577Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-03T01:05:05.305577Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"evNTt63CfyzTGul1BKZhns2c4kAi2On57kyOKx46sd434YgpYUoLb1MIoCRI2MsGN6u57nLLgqkBrxZ7foa0BA==","signature_status":"signed_v1","signed_at":"2026-06-03T01:05:05.306130Z","signed_message":"canonical_sha256_bytes"},"source_id":"2508.03098","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e5e9c902481b7c9f6487d911e08af0ce0008f0b275bb20b8269be684e41c8b1f","sha256:431151fbed319af3f954f074246b7f1a1fd7202d34cb5270602baee6dd494a34"],"state_sha256":"4ee562ff6ee6de2a1ea224f30568a149b8bed38c36e972fa3aeafeda67c58d96"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"nRzmf6DHZLQTCSVfzEngpsr8aptrCB2R/spfYNYJwf29vgyMOHULqxVBBSUpaOroionNu75cfh9RF48ttTWoCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-09T06:15:29.049333Z","bundle_sha256":"6f907f5a36fabb35d3eeb81499d55d1f4305be3f0efefaa2fafb8a466e7bed41"}}