{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:WHZ3IQCFC5D6DZLKIGXBG4CIR6","short_pith_number":"pith:WHZ3IQCF","canonical_record":{"source":{"id":"1812.00535","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-03T03:12:39Z","cross_cats_sorted":["cs.CR","cs.CV"],"title_canon_sha256":"fdb1c79168964aa13f4f44e96951ca2ed4db1a20493985ac47439b6f38195206","abstract_canon_sha256":"e7f4400642c023bbf0d135373e44a798a425c56f0d3fb8392d08fa6a4e60897e"},"schema_version":"1.0"},"canonical_sha256":"b1f3b440451747e1e56a41ae1370488fb0a29d16ba5b1d95b9d44120c217285a","source":{"kind":"arxiv","id":"1812.00535","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.00535","created_at":"2026-05-17T23:59:01Z"},{"alias_kind":"arxiv_version","alias_value":"1812.00535v3","created_at":"2026-05-17T23:59:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.00535","created_at":"2026-05-17T23:59:01Z"},{"alias_kind":"pith_short_12","alias_value":"WHZ3IQCFC5D6","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_16","alias_value":"WHZ3IQCFC5D6DZLK","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_8","alias_value":"WHZ3IQCF","created_at":"2026-05-18T12:32:59Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:WHZ3IQCFC5D6DZLKIGXBG4CIR6","target":"record","payload":{"canonical_record":{"source":{"id":"1812.00535","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-03T03:12:39Z","cross_cats_sorted":["cs.CR","cs.CV"],"title_canon_sha256":"fdb1c79168964aa13f4f44e96951ca2ed4db1a20493985ac47439b6f38195206","abstract_canon_sha256":"e7f4400642c023bbf0d135373e44a798a425c56f0d3fb8392d08fa6a4e60897e"},"schema_version":"1.0"},"canonical_sha256":"b1f3b440451747e1e56a41ae1370488fb0a29d16ba5b1d95b9d44120c217285a","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:59:01.138428Z","signature_b64":"pKbcps6kLYEgDzYb3EreHzN2ZTv/jFHhSeLSix/fU4FJH68QONQewg4BVFzaOAvlYTC+955gDXMaiQC3I9HFDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b1f3b440451747e1e56a41ae1370488fb0a29d16ba5b1d95b9d44120c217285a","last_reissued_at":"2026-05-17T23:59:01.138007Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:59:01.138007Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1812.00535","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"LUsnOoV+h2ihLmx55tBRBYS3fbQ9XpCcMV5WokjDpxibzJWVIPYggIwTTuDoEeU/fE/EcJ4owt7caJ7LRADQBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T21:28:50.161039Z"},"content_sha256":"0c606a7a7d4e5d03ab8157316e92712b582c5a2889545b624482446904a92658","schema_version":"1.0","event_id":"sha256:0c606a7a7d4e5d03ab8157316e92712b582c5a2889545b624482446904a92658"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:WHZ3IQCFC5D6DZLKIGXBG4CIR6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Beyond Inferring Class Representatives: User-Level Privacy Leakage From Federated Learning","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR","cs.CV"],"primary_cat":"cs.LG","authors_text":"Hairong Qi, Mengkai Song, Qian Wang, Yang Song, Zhibo Wang, Zhifei Zhang","submitted_at":"2018-12-03T03:12:39Z","abstract_excerpt":"Federated learning, i.e., a mobile edge computing framework for deep learning, is a recent advance in privacy-preserving machine learning, where the model is trained in a decentralized manner by the clients, i.e., data curators, preventing the server from directly accessing those private data from the clients. This learning mechanism significantly challenges the attack from the server side. Although the state-of-the-art attacking techniques that incorporated the advance of Generative adversarial networks (GANs) could construct class representatives of the global data distribution among all cli"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.00535","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:59:01Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wOUifs2ZQgkryGGhwSKMWDDGgGEhRQ23ShVAtvzYQRtXlk1AyinueWTy+FilHQ/bmVwkcLMznJkXHOOlnb/SCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T21:28:50.161857Z"},"content_sha256":"7e34faebb34a41a5c61841bc16f2eeceef847d836deffdc0d406f7dc5d4a696c","schema_version":"1.0","event_id":"sha256:7e34faebb34a41a5c61841bc16f2eeceef847d836deffdc0d406f7dc5d4a696c"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/WHZ3IQCFC5D6DZLKIGXBG4CIR6/bundle.json","state_url":"https://pith.science/pith/WHZ3IQCFC5D6DZLKIGXBG4CIR6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/WHZ3IQCFC5D6DZLKIGXBG4CIR6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T21:28:50Z","links":{"resolver":"https://pith.science/pith/WHZ3IQCFC5D6DZLKIGXBG4CIR6","bundle":"https://pith.science/pith/WHZ3IQCFC5D6DZLKIGXBG4CIR6/bundle.json","state":"https://pith.science/pith/WHZ3IQCFC5D6DZLKIGXBG4CIR6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/WHZ3IQCFC5D6DZLKIGXBG4CIR6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:WHZ3IQCFC5D6DZLKIGXBG4CIR6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e7f4400642c023bbf0d135373e44a798a425c56f0d3fb8392d08fa6a4e60897e","cross_cats_sorted":["cs.CR","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-03T03:12:39Z","title_canon_sha256":"fdb1c79168964aa13f4f44e96951ca2ed4db1a20493985ac47439b6f38195206"},"schema_version":"1.0","source":{"id":"1812.00535","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1812.00535","created_at":"2026-05-17T23:59:01Z"},{"alias_kind":"arxiv_version","alias_value":"1812.00535v3","created_at":"2026-05-17T23:59:01Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1812.00535","created_at":"2026-05-17T23:59:01Z"},{"alias_kind":"pith_short_12","alias_value":"WHZ3IQCFC5D6","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_16","alias_value":"WHZ3IQCFC5D6DZLK","created_at":"2026-05-18T12:32:59Z"},{"alias_kind":"pith_short_8","alias_value":"WHZ3IQCF","created_at":"2026-05-18T12:32:59Z"}],"graph_snapshots":[{"event_id":"sha256:7e34faebb34a41a5c61841bc16f2eeceef847d836deffdc0d406f7dc5d4a696c","target":"graph","created_at":"2026-05-17T23:59:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"Federated learning, i.e., a mobile edge computing framework for deep learning, is a recent advance in privacy-preserving machine learning, where the model is trained in a decentralized manner by the clients, i.e., data curators, preventing the server from directly accessing those private data from the clients. This learning mechanism significantly challenges the attack from the server side. Although the state-of-the-art attacking techniques that incorporated the advance of Generative adversarial networks (GANs) could construct class representatives of the global data distribution among all cli","authors_text":"Hairong Qi, Mengkai Song, Qian Wang, Yang Song, Zhibo Wang, Zhifei Zhang","cross_cats":["cs.CR","cs.CV"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-03T03:12:39Z","title":"Beyond Inferring Class Representatives: User-Level Privacy Leakage From Federated Learning"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1812.00535","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:0c606a7a7d4e5d03ab8157316e92712b582c5a2889545b624482446904a92658","target":"record","created_at":"2026-05-17T23:59:01Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e7f4400642c023bbf0d135373e44a798a425c56f0d3fb8392d08fa6a4e60897e","cross_cats_sorted":["cs.CR","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2018-12-03T03:12:39Z","title_canon_sha256":"fdb1c79168964aa13f4f44e96951ca2ed4db1a20493985ac47439b6f38195206"},"schema_version":"1.0","source":{"id":"1812.00535","kind":"arxiv","version":3}},"canonical_sha256":"b1f3b440451747e1e56a41ae1370488fb0a29d16ba5b1d95b9d44120c217285a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b1f3b440451747e1e56a41ae1370488fb0a29d16ba5b1d95b9d44120c217285a","first_computed_at":"2026-05-17T23:59:01.138007Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:59:01.138007Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"pKbcps6kLYEgDzYb3EreHzN2ZTv/jFHhSeLSix/fU4FJH68QONQewg4BVFzaOAvlYTC+955gDXMaiQC3I9HFDQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:59:01.138428Z","signed_message":"canonical_sha256_bytes"},"source_id":"1812.00535","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:0c606a7a7d4e5d03ab8157316e92712b582c5a2889545b624482446904a92658","sha256:7e34faebb34a41a5c61841bc16f2eeceef847d836deffdc0d406f7dc5d4a696c"],"state_sha256":"1ad9ca8d9200db5e7d3e5773f37d91491d637aab16d663fea252c3f1d1936a50"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"n4gDS/3GxSxADjHr0wxU5g781d+MNWNltf9F/I3968fEC9nRQGwWhZMU+TSvpYjgIu36fIeVmGo4B+UCLerAAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T21:28:50.165758Z","bundle_sha256":"b59c0a2930b200f5c263378bfb0854a987103e8b3b9ac55d45578b722607b80b"}}