{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:WTBP5E2CDMU5MYK5LIW5EVIUY4","short_pith_number":"pith:WTBP5E2C","canonical_record":{"source":{"id":"2602.00688","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-01-31T12:18:36Z","cross_cats_sorted":[],"title_canon_sha256":"fa292f3bc61fc204e61baec7f86ba23e8022344eec222ea0d67ad69c72435370","abstract_canon_sha256":"b756d02f402f1275d1b4e52092493d7c7900559e87d7747bc502949e009b7ad6"},"schema_version":"1.0"},"canonical_sha256":"b4c2fe93421b29d6615d5a2dd25514c7344cd66c67e09714bdd3344f32ad36e6","source":{"kind":"arxiv","id":"2602.00688","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2602.00688","created_at":"2026-05-22T01:04:54Z"},{"alias_kind":"arxiv_version","alias_value":"2602.00688v2","created_at":"2026-05-22T01:04:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2602.00688","created_at":"2026-05-22T01:04:54Z"},{"alias_kind":"pith_short_12","alias_value":"WTBP5E2CDMU5","created_at":"2026-05-22T01:04:54Z"},{"alias_kind":"pith_short_16","alias_value":"WTBP5E2CDMU5MYK5","created_at":"2026-05-22T01:04:54Z"},{"alias_kind":"pith_short_8","alias_value":"WTBP5E2C","created_at":"2026-05-22T01:04:54Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:WTBP5E2CDMU5MYK5LIW5EVIUY4","target":"record","payload":{"canonical_record":{"source":{"id":"2602.00688","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-01-31T12:18:36Z","cross_cats_sorted":[],"title_canon_sha256":"fa292f3bc61fc204e61baec7f86ba23e8022344eec222ea0d67ad69c72435370","abstract_canon_sha256":"b756d02f402f1275d1b4e52092493d7c7900559e87d7747bc502949e009b7ad6"},"schema_version":"1.0"},"canonical_sha256":"b4c2fe93421b29d6615d5a2dd25514c7344cd66c67e09714bdd3344f32ad36e6","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-22T01:04:54.621777Z","signature_b64":"eak3AyvMI1Uac+g/E44i6aNXfzhIz4yZh1uzrLctRp8I5B7GohZiS2Vpqwyu7GaplVcEPrPyqMFgAkKz1W/EDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b4c2fe93421b29d6615d5a2dd25514c7344cd66c67e09714bdd3344f32ad36e6","last_reissued_at":"2026-05-22T01:04:54.620969Z","signature_status":"signed_v1","first_computed_at":"2026-05-22T01:04:54.620969Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2602.00688","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:04:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"GAcV4a57zCthQNQ2oJ8CouIyvHFBZCIo4Pc+ST7+OHjehyKJ+0ZrUv8bKESUj9iaojaPzFdFXlu5IxD954blAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T21:30:04.530587Z"},"content_sha256":"64b95fcfec4e1c7e97cda1dc34eda7f83951a9ddce8f54b9f23fc1205709eab4","schema_version":"1.0","event_id":"sha256:64b95fcfec4e1c7e97cda1dc34eda7f83951a9ddce8f54b9f23fc1205709eab4"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:WTBP5E2CDMU5MYK5LIW5EVIUY4","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Provably Protecting Fine-Tuned LLMs from Training Data Extraction while Preserving Utility","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Asaf Shabtai, Tom Segal, Yuval Elovici","submitted_at":"2026-01-31T12:18:36Z","abstract_excerpt":"Fine-tuning large language models (LLMs) on sensitive datasets raises privacy concerns, as training data extraction (TDE) attacks can expose highly confidential information. Existing defenses against such attacks either lack formal privacy guarantees or incur substantial utility degradation. We observe that fine-tuning induces widespread probability shifts, yet preserving only a small subset of influential token-level deviations is sufficient; the remaining shifts can be aggressively smoothed with minimal impact on utility. Motivated by this insight, we propose SCP-$\\Delta_r$, a Near Access Fr"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2602.00688","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2602.00688/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:04:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"rriWm5p9FIvlmOsz13VU5K41QecgLlYu+WpG+hd9fA9c9UD/6lADTiNFfEkqPCybEqelB/eC3T5Eh+vNP/CADQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T21:30:04.531265Z"},"content_sha256":"2616004843e8fb4248ade2689aeaf4a34ee604690e6735efeebc5559cd05b5dd","schema_version":"1.0","event_id":"sha256:2616004843e8fb4248ade2689aeaf4a34ee604690e6735efeebc5559cd05b5dd"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/WTBP5E2CDMU5MYK5LIW5EVIUY4/bundle.json","state_url":"https://pith.science/pith/WTBP5E2CDMU5MYK5LIW5EVIUY4/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/WTBP5E2CDMU5MYK5LIW5EVIUY4/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-06T21:30:04Z","links":{"resolver":"https://pith.science/pith/WTBP5E2CDMU5MYK5LIW5EVIUY4","bundle":"https://pith.science/pith/WTBP5E2CDMU5MYK5LIW5EVIUY4/bundle.json","state":"https://pith.science/pith/WTBP5E2CDMU5MYK5LIW5EVIUY4/state.json","well_known_bundle":"https://pith.science/.well-known/pith/WTBP5E2CDMU5MYK5LIW5EVIUY4/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:WTBP5E2CDMU5MYK5LIW5EVIUY4","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b756d02f402f1275d1b4e52092493d7c7900559e87d7747bc502949e009b7ad6","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-01-31T12:18:36Z","title_canon_sha256":"fa292f3bc61fc204e61baec7f86ba23e8022344eec222ea0d67ad69c72435370"},"schema_version":"1.0","source":{"id":"2602.00688","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2602.00688","created_at":"2026-05-22T01:04:54Z"},{"alias_kind":"arxiv_version","alias_value":"2602.00688v2","created_at":"2026-05-22T01:04:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2602.00688","created_at":"2026-05-22T01:04:54Z"},{"alias_kind":"pith_short_12","alias_value":"WTBP5E2CDMU5","created_at":"2026-05-22T01:04:54Z"},{"alias_kind":"pith_short_16","alias_value":"WTBP5E2CDMU5MYK5","created_at":"2026-05-22T01:04:54Z"},{"alias_kind":"pith_short_8","alias_value":"WTBP5E2C","created_at":"2026-05-22T01:04:54Z"}],"graph_snapshots":[{"event_id":"sha256:2616004843e8fb4248ade2689aeaf4a34ee604690e6735efeebc5559cd05b5dd","target":"graph","created_at":"2026-05-22T01:04:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2602.00688/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Fine-tuning large language models (LLMs) on sensitive datasets raises privacy concerns, as training data extraction (TDE) attacks can expose highly confidential information. Existing defenses against such attacks either lack formal privacy guarantees or incur substantial utility degradation. We observe that fine-tuning induces widespread probability shifts, yet preserving only a small subset of influential token-level deviations is sufficient; the remaining shifts can be aggressively smoothed with minimal impact on utility. Motivated by this insight, we propose SCP-$\\Delta_r$, a Near Access Fr","authors_text":"Asaf Shabtai, Tom Segal, Yuval Elovici","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-01-31T12:18:36Z","title":"Provably Protecting Fine-Tuned LLMs from Training Data Extraction while Preserving Utility"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2602.00688","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:64b95fcfec4e1c7e97cda1dc34eda7f83951a9ddce8f54b9f23fc1205709eab4","target":"record","created_at":"2026-05-22T01:04:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b756d02f402f1275d1b4e52092493d7c7900559e87d7747bc502949e009b7ad6","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-01-31T12:18:36Z","title_canon_sha256":"fa292f3bc61fc204e61baec7f86ba23e8022344eec222ea0d67ad69c72435370"},"schema_version":"1.0","source":{"id":"2602.00688","kind":"arxiv","version":2}},"canonical_sha256":"b4c2fe93421b29d6615d5a2dd25514c7344cd66c67e09714bdd3344f32ad36e6","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b4c2fe93421b29d6615d5a2dd25514c7344cd66c67e09714bdd3344f32ad36e6","first_computed_at":"2026-05-22T01:04:54.620969Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-22T01:04:54.620969Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"eak3AyvMI1Uac+g/E44i6aNXfzhIz4yZh1uzrLctRp8I5B7GohZiS2Vpqwyu7GaplVcEPrPyqMFgAkKz1W/EDA==","signature_status":"signed_v1","signed_at":"2026-05-22T01:04:54.621777Z","signed_message":"canonical_sha256_bytes"},"source_id":"2602.00688","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:64b95fcfec4e1c7e97cda1dc34eda7f83951a9ddce8f54b9f23fc1205709eab4","sha256:2616004843e8fb4248ade2689aeaf4a34ee604690e6735efeebc5559cd05b5dd"],"state_sha256":"9f3f363de01abc74af083bc44395e13527df4208fbddaf3beab0c161b760dbd8"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"oTE1q6F1GlVYlq8rHbti7M5gp2ImolHxsKbQJnOVUwzVTZNuSvZ9tuXGgR3gsq6boujUlK9pkQf4SaGaL0l4DA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-06T21:30:04.534496Z","bundle_sha256":"7900b7e2005045219acc3774ea71726ce17613935a7cc15003567eb99b7e268b"}}