{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:WCEE7YYFDOZOOLKJHREESX2N4S","short_pith_number":"pith:WCEE7YYF","schema_version":"1.0","canonical_sha256":"b0884fe3051bb2e72d493c48495f4de4a6c3db02d17c91163667b145f0f299e0","source":{"kind":"arxiv","id":"1906.10908","version":2},"attestation_state":"computed","paper":{"title":"Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Bernt Schiele, Mario Fritz, Tribhuvanesh Orekondy","submitted_at":"2019-06-26T08:32:37Z","abstract_excerpt":"High-performance Deep Neural Networks (DNNs) are increasingly deployed in many real-world applications e.g., cloud prediction APIs. Recent advances in model functionality stealing attacks via black-box access (i.e., inputs in, predictions out) threaten the business model of such applications, which require a lot of time, money, and effort to develop. Existing defenses take a passive role against stealing attacks, such as by truncating predicted information. We find such passive defenses ineffective against DNN stealing attacks. In this paper, we propose the first defense which actively perturb"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1906.10908","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2019-06-26T08:32:37Z","cross_cats_sorted":["cs.CR","cs.CV","stat.ML"],"title_canon_sha256":"02bdbe7177f834bd8c562d966913bece5d9c835ab236f429842cc54be7e377f5","abstract_canon_sha256":"f9a5bef14ba868e636ce9ec31a07e931a448dba24c6c7ebacab76a5a66f3248a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:45:06.482469Z","signature_b64":"xpC6nS0fsXzd1KpEQxDWmUAABQApIwUZD9AYfJNGhTs+m7fd4RCh69Cx3YJjkBSb2Y5qpoh5uYqzkMVd66pICg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b0884fe3051bb2e72d493c48495f4de4a6c3db02d17c91163667b145f0f299e0","last_reissued_at":"2026-07-05T00:45:06.481926Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:45:06.481926Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.CR","cs.CV","stat.ML"],"primary_cat":"cs.LG","authors_text":"Bernt Schiele, Mario Fritz, Tribhuvanesh Orekondy","submitted_at":"2019-06-26T08:32:37Z","abstract_excerpt":"High-performance Deep Neural Networks (DNNs) are increasingly deployed in many real-world applications e.g., cloud prediction APIs. Recent advances in model functionality stealing attacks via black-box access (i.e., inputs in, predictions out) threaten the business model of such applications, which require a lot of time, money, and effort to develop. Existing defenses take a passive role against stealing attacks, such as by truncating predicted information. We find such passive defenses ineffective against DNN stealing attacks. In this paper, we propose the first defense which actively perturb"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.10908","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1906.10908/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1906.10908","created_at":"2026-07-05T00:45:06.481994+00:00"},{"alias_kind":"arxiv_version","alias_value":"1906.10908v2","created_at":"2026-07-05T00:45:06.481994+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.10908","created_at":"2026-07-05T00:45:06.481994+00:00"},{"alias_kind":"pith_short_12","alias_value":"WCEE7YYFDOZO","created_at":"2026-07-05T00:45:06.481994+00:00"},{"alias_kind":"pith_short_16","alias_value":"WCEE7YYFDOZOOLKJ","created_at":"2026-07-05T00:45:06.481994+00:00"},{"alias_kind":"pith_short_8","alias_value":"WCEE7YYF","created_at":"2026-07-05T00:45:06.481994+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.18829","citing_title":"Lossless Anti-Distillation Sampling","ref_index":106,"is_internal_anchor":false},{"citing_arxiv_id":"2605.04901","citing_title":"On the (In-)Security of the Shuffling Defense in the Transformer Secure Inference","ref_index":170,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/WCEE7YYFDOZOOLKJHREESX2N4S","json":"https://pith.science/pith/WCEE7YYFDOZOOLKJHREESX2N4S.json","graph_json":"https://pith.science/api/pith-number/WCEE7YYFDOZOOLKJHREESX2N4S/graph.json","events_json":"https://pith.science/api/pith-number/WCEE7YYFDOZOOLKJHREESX2N4S/events.json","paper":"https://pith.science/paper/WCEE7YYF"},"agent_actions":{"view_html":"https://pith.science/pith/WCEE7YYFDOZOOLKJHREESX2N4S","download_json":"https://pith.science/pith/WCEE7YYFDOZOOLKJHREESX2N4S.json","view_paper":"https://pith.science/paper/WCEE7YYF","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1906.10908&json=true","fetch_graph":"https://pith.science/api/pith-number/WCEE7YYFDOZOOLKJHREESX2N4S/graph.json","fetch_events":"https://pith.science/api/pith-number/WCEE7YYFDOZOOLKJHREESX2N4S/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/WCEE7YYFDOZOOLKJHREESX2N4S/action/timestamp_anchor","attest_storage":"https://pith.science/pith/WCEE7YYFDOZOOLKJHREESX2N4S/action/storage_attestation","attest_author":"https://pith.science/pith/WCEE7YYFDOZOOLKJHREESX2N4S/action/author_attestation","sign_citation":"https://pith.science/pith/WCEE7YYFDOZOOLKJHREESX2N4S/action/citation_signature","submit_replication":"https://pith.science/pith/WCEE7YYFDOZOOLKJHREESX2N4S/action/replication_record"}},"created_at":"2026-07-05T00:45:06.481994+00:00","updated_at":"2026-07-05T00:45:06.481994+00:00"}