{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:WLIW3XE3CI3XIM3DALTMYIWX4M","short_pith_number":"pith:WLIW3XE3","canonical_record":{"source":{"id":"1808.00590","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-08-01T22:45:48Z","cross_cats_sorted":["cs.AI","cs.LG","stat.ML"],"title_canon_sha256":"72da018e554d9e7659527427d5ce4908013564bdf0deb806277777d061e250cf","abstract_canon_sha256":"9c114b1b05c8385d3e4b207f6e2c587c165fb5dc81d4afad0c5e18012ac7b4ab"},"schema_version":"1.0"},"canonical_sha256":"b2d16ddc9b123774336302e6cc22d7e33718f18f41b4ea69224c1353e83f2769","source":{"kind":"arxiv","id":"1808.00590","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1808.00590","created_at":"2026-05-17T23:54:39Z"},{"alias_kind":"arxiv_version","alias_value":"1808.00590v2","created_at":"2026-05-17T23:54:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1808.00590","created_at":"2026-05-17T23:54:39Z"},{"alias_kind":"pith_short_12","alias_value":"WLIW3XE3CI3X","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_16","alias_value":"WLIW3XE3CI3XIM3D","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_8","alias_value":"WLIW3XE3","created_at":"2026-05-18T12:33:01Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:WLIW3XE3CI3XIM3DALTMYIWX4M","target":"record","payload":{"canonical_record":{"source":{"id":"1808.00590","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-08-01T22:45:48Z","cross_cats_sorted":["cs.AI","cs.LG","stat.ML"],"title_canon_sha256":"72da018e554d9e7659527427d5ce4908013564bdf0deb806277777d061e250cf","abstract_canon_sha256":"9c114b1b05c8385d3e4b207f6e2c587c165fb5dc81d4afad0c5e18012ac7b4ab"},"schema_version":"1.0"},"canonical_sha256":"b2d16ddc9b123774336302e6cc22d7e33718f18f41b4ea69224c1353e83f2769","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:54:39.393040Z","signature_b64":"iDvJLMRKEN+FAmBmZ9rZc2Wa3UNzr6XDwOYuSOwnjaDr8JPbTwQCTUveVY9vbjfW7OZro3wv6GW7YFYK3bycBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b2d16ddc9b123774336302e6cc22d7e33718f18f41b4ea69224c1353e83f2769","last_reissued_at":"2026-05-17T23:54:39.392549Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:54:39.392549Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1808.00590","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:54:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"RXtnxyeDwPI1cIUzbc1dyF99Q2q2emJTdyVOpxxJ0iQWwwmKMJ6ZJUswzWIaT2wKPlHqiVsPj8ZOxnRCghFoDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T10:53:18.625643Z"},"content_sha256":"6019f87830c6938ee2fb9f99fe71663031b2e8796fae7d471e66f56557b50a5a","schema_version":"1.0","event_id":"sha256:6019f87830c6938ee2fb9f99fe71663031b2e8796fae7d471e66f56557b50a5a"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:WLIW3XE3CI3XIM3DALTMYIWX4M","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"MLCapsule: Guarded Offline Deployment of Machine Learning as a Service","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG","stat.ML"],"primary_cat":"cs.CR","authors_text":"Ahmed Salem, Kathrin Grosse, Lucjan Hanzlik, Mario Fritz, Max Augustin, Michael Backes, Yang Zhang","submitted_at":"2018-08-01T22:45:48Z","abstract_excerpt":"With the widespread use of machine learning (ML) techniques, ML as a service has become increasingly popular. In this setting, an ML model resides on a server and users can query it with their data via an API. However, if the user's input is sensitive, sending it to the server is undesirable and sometimes even legally not possible. Equally, the service provider does not want to share the model by sending it to the client for protecting its intellectual property and pay-per-query business model.\n  In this paper, we propose MLCapsule, a guarded offline deployment of machine learning as a service"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1808.00590","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:54:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4VU5ktrmUdvGIX4WWJAnKIQW1k7WF4gvFQ3FWhJ75aN79cOd6YkGz7DlTHgbRpeYuXvUqUG/JBtrx0cxDOJSCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T10:53:18.626308Z"},"content_sha256":"2ac72f08d2fc31c6671feb334474019ea00f0ac0670f2df91b60e245d3887092","schema_version":"1.0","event_id":"sha256:2ac72f08d2fc31c6671feb334474019ea00f0ac0670f2df91b60e245d3887092"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/WLIW3XE3CI3XIM3DALTMYIWX4M/bundle.json","state_url":"https://pith.science/pith/WLIW3XE3CI3XIM3DALTMYIWX4M/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/WLIW3XE3CI3XIM3DALTMYIWX4M/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-27T10:53:18Z","links":{"resolver":"https://pith.science/pith/WLIW3XE3CI3XIM3DALTMYIWX4M","bundle":"https://pith.science/pith/WLIW3XE3CI3XIM3DALTMYIWX4M/bundle.json","state":"https://pith.science/pith/WLIW3XE3CI3XIM3DALTMYIWX4M/state.json","well_known_bundle":"https://pith.science/.well-known/pith/WLIW3XE3CI3XIM3DALTMYIWX4M/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:WLIW3XE3CI3XIM3DALTMYIWX4M","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"9c114b1b05c8385d3e4b207f6e2c587c165fb5dc81d4afad0c5e18012ac7b4ab","cross_cats_sorted":["cs.AI","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-08-01T22:45:48Z","title_canon_sha256":"72da018e554d9e7659527427d5ce4908013564bdf0deb806277777d061e250cf"},"schema_version":"1.0","source":{"id":"1808.00590","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1808.00590","created_at":"2026-05-17T23:54:39Z"},{"alias_kind":"arxiv_version","alias_value":"1808.00590v2","created_at":"2026-05-17T23:54:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1808.00590","created_at":"2026-05-17T23:54:39Z"},{"alias_kind":"pith_short_12","alias_value":"WLIW3XE3CI3X","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_16","alias_value":"WLIW3XE3CI3XIM3D","created_at":"2026-05-18T12:33:01Z"},{"alias_kind":"pith_short_8","alias_value":"WLIW3XE3","created_at":"2026-05-18T12:33:01Z"}],"graph_snapshots":[{"event_id":"sha256:2ac72f08d2fc31c6671feb334474019ea00f0ac0670f2df91b60e245d3887092","target":"graph","created_at":"2026-05-17T23:54:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"With the widespread use of machine learning (ML) techniques, ML as a service has become increasingly popular. In this setting, an ML model resides on a server and users can query it with their data via an API. However, if the user's input is sensitive, sending it to the server is undesirable and sometimes even legally not possible. Equally, the service provider does not want to share the model by sending it to the client for protecting its intellectual property and pay-per-query business model.\n  In this paper, we propose MLCapsule, a guarded offline deployment of machine learning as a service","authors_text":"Ahmed Salem, Kathrin Grosse, Lucjan Hanzlik, Mario Fritz, Max Augustin, Michael Backes, Yang Zhang","cross_cats":["cs.AI","cs.LG","stat.ML"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-08-01T22:45:48Z","title":"MLCapsule: Guarded Offline Deployment of Machine Learning as a Service"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1808.00590","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:6019f87830c6938ee2fb9f99fe71663031b2e8796fae7d471e66f56557b50a5a","target":"record","created_at":"2026-05-17T23:54:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"9c114b1b05c8385d3e4b207f6e2c587c165fb5dc81d4afad0c5e18012ac7b4ab","cross_cats_sorted":["cs.AI","cs.LG","stat.ML"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-08-01T22:45:48Z","title_canon_sha256":"72da018e554d9e7659527427d5ce4908013564bdf0deb806277777d061e250cf"},"schema_version":"1.0","source":{"id":"1808.00590","kind":"arxiv","version":2}},"canonical_sha256":"b2d16ddc9b123774336302e6cc22d7e33718f18f41b4ea69224c1353e83f2769","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b2d16ddc9b123774336302e6cc22d7e33718f18f41b4ea69224c1353e83f2769","first_computed_at":"2026-05-17T23:54:39.392549Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:54:39.392549Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"iDvJLMRKEN+FAmBmZ9rZc2Wa3UNzr6XDwOYuSOwnjaDr8JPbTwQCTUveVY9vbjfW7OZro3wv6GW7YFYK3bycBQ==","signature_status":"signed_v1","signed_at":"2026-05-17T23:54:39.393040Z","signed_message":"canonical_sha256_bytes"},"source_id":"1808.00590","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:6019f87830c6938ee2fb9f99fe71663031b2e8796fae7d471e66f56557b50a5a","sha256:2ac72f08d2fc31c6671feb334474019ea00f0ac0670f2df91b60e245d3887092"],"state_sha256":"92681c15e6b932d549d13b64205f497f6da4af28596d567f0eaa0c80f779a4dd"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"sS+3zKlr8NIDwufeSTd8XOwu3Xhjz4a20j2i6wzYNTfHIeL1FejTOsxrUTzeuQIkw9KqnIOxNnsiTZxn5BnoCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-27T10:53:18.629693Z","bundle_sha256":"1a5d02ee8697522a9b9a1f65e39880b7803cff0bd857cd89be96137fe7034e0d"}}