{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:UL7T5KV6CEJQSLJSPFJ37EVUH3","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"8dfb2cdee9114ddf2f63720eea174964b10bab5ddbe9dd041f84f568514d86c5","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2025-08-05T05:22:13Z","title_canon_sha256":"9710fd7f213b5eead800205274a0512c34614c16609fddd442424123444cb17e"},"schema_version":"1.0","source":{"id":"2508.03098","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2508.03098","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"arxiv_version","alias_value":"2508.03098v2","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.03098","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"pith_short_12","alias_value":"UL7T5KV6CEJQ","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"pith_short_16","alias_value":"UL7T5KV6CEJQSLJS","created_at":"2026-06-03T01:05:05Z"},{"alias_kind":"pith_short_8","alias_value":"UL7T5KV6","created_at":"2026-06-03T01:05:05Z"}],"graph_snapshots":[{"event_id":"sha256:431151fbed319af3f954f074246b7f1a1fd7202d34cb5270602baee6dd494a34","target":"graph","created_at":"2026-06-03T01:05:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2508.03098/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Retrieval-Augmented Generation (RAG) enhances the factual accuracy of large language models (LLMs) by conditioning outputs on external knowledge sources. However, when retrieval involves private or sensitive data, RAG systems are susceptible to extraction attacks that can leak confidential information through generated responses. We propose Privacy-Aware Decoding (PAD), a lightweight, inference-time defense that adaptively injects calibrated Gaussian noise into token logits during generation. PAD integrates confidence-based screening to selectively protect high-risk tokens, efficient sensitivi","authors_text":"Baixiang Huang, Haoran Wang, Kai Shu, Xiongxiao Xu","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2025-08-05T05:22:13Z","title":"Privacy-Aware Decoding: Mitigating Privacy Leakage of Large Language Models in Retrieval-Augmented Generation"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.03098","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e5e9c902481b7c9f6487d911e08af0ce0008f0b275bb20b8269be684e41c8b1f","target":"record","created_at":"2026-06-03T01:05:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"8dfb2cdee9114ddf2f63720eea174964b10bab5ddbe9dd041f84f568514d86c5","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2025-08-05T05:22:13Z","title_canon_sha256":"9710fd7f213b5eead800205274a0512c34614c16609fddd442424123444cb17e"},"schema_version":"1.0","source":{"id":"2508.03098","kind":"arxiv","version":2}},"canonical_sha256":"a2ff3eaabe1113092d327953bf92b43eed24b29e448c4966cf7ba48680ca7037","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a2ff3eaabe1113092d327953bf92b43eed24b29e448c4966cf7ba48680ca7037","first_computed_at":"2026-06-03T01:05:05.305577Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-03T01:05:05.305577Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"evNTt63CfyzTGul1BKZhns2c4kAi2On57kyOKx46sd434YgpYUoLb1MIoCRI2MsGN6u57nLLgqkBrxZ7foa0BA==","signature_status":"signed_v1","signed_at":"2026-06-03T01:05:05.306130Z","signed_message":"canonical_sha256_bytes"},"source_id":"2508.03098","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e5e9c902481b7c9f6487d911e08af0ce0008f0b275bb20b8269be684e41c8b1f","sha256:431151fbed319af3f954f074246b7f1a1fd7202d34cb5270602baee6dd494a34"],"state_sha256":"4ee562ff6ee6de2a1ea224f30568a149b8bed38c36e972fa3aeafeda67c58d96"}