{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:YA3EYCG6XBY3DWPU37R3GNWTRF","short_pith_number":"pith:YA3EYCG6","schema_version":"1.0","canonical_sha256":"c0364c08deb871b1d9f4dfe3b336d3894ab4fc12cf5b0c0c84e25265c797b17d","source":{"kind":"arxiv","id":"2405.11916","version":3},"attestation_state":"computed","paper":{"title":"Information Leakage from Embedding in Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Anda Cheng, Lei Wang, Yinggui Wang, Zhipeng Wan","submitted_at":"2024-05-20T09:52:31Z","abstract_excerpt":"The widespread adoption of large language models (LLMs) has raised concerns regarding data privacy. This study aims to investigate the potential for privacy invasion through input reconstruction attacks, in which a malicious model provider could potentially recover user inputs from embeddings. We first propose two base methods to reconstruct original texts from a model's hidden states. We find that these two methods are effective in attacking the embeddings from shallow layers, but their effectiveness decreases when attacking embeddings from deeper layers. To address this issue, we then presen"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2405.11916","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2024-05-20T09:52:31Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"9a08e734533a15173eb039c6eccdce7be768279b375ded92a47491e381f76e1c","abstract_canon_sha256":"6760139c4e3b716a11765c2c947113df23ed7028212110bea6f379ca88275c68"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:21:55.522347Z","signature_b64":"SX++yGEzXNNJoARNcA3WTirJ7WOCAYQxY5HpvcLhfsLeEz4fwkAzq1Bl2RL4Tlg1MfHjqT/+mNSoZASp8BVzDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c0364c08deb871b1d9f4dfe3b336d3894ab4fc12cf5b0c0c84e25265c797b17d","last_reissued_at":"2026-07-05T08:21:55.521867Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:21:55.521867Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Information Leakage from Embedding in Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Anda Cheng, Lei Wang, Yinggui Wang, Zhipeng Wan","submitted_at":"2024-05-20T09:52:31Z","abstract_excerpt":"The widespread adoption of large language models (LLMs) has raised concerns regarding data privacy. This study aims to investigate the potential for privacy invasion through input reconstruction attacks, in which a malicious model provider could potentially recover user inputs from embeddings. We first propose two base methods to reconstruct original texts from a model's hidden states. We find that these two methods are effective in attacking the embeddings from shallow layers, but their effectiveness decreases when attacking embeddings from deeper layers. To address this issue, we then presen"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2405.11916","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2405.11916/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2405.11916","created_at":"2026-07-05T08:21:55.521924+00:00"},{"alias_kind":"arxiv_version","alias_value":"2405.11916v3","created_at":"2026-07-05T08:21:55.521924+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2405.11916","created_at":"2026-07-05T08:21:55.521924+00:00"},{"alias_kind":"pith_short_12","alias_value":"YA3EYCG6XBY3","created_at":"2026-07-05T08:21:55.521924+00:00"},{"alias_kind":"pith_short_16","alias_value":"YA3EYCG6XBY3DWPU","created_at":"2026-07-05T08:21:55.521924+00:00"},{"alias_kind":"pith_short_8","alias_value":"YA3EYCG6","created_at":"2026-07-05T08:21:55.521924+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.28958","citing_title":"When Latent Agents Lie: KV-Cache Integrity in Multi-Agent LLM Collaboration","ref_index":18,"is_internal_anchor":false},{"citing_arxiv_id":"2605.24817","citing_title":"RouteScan: A Non-Intrusive Approach to Auditing MoE LLMs Safety via Expert Routing Telemetry","ref_index":47,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/YA3EYCG6XBY3DWPU37R3GNWTRF","json":"https://pith.science/pith/YA3EYCG6XBY3DWPU37R3GNWTRF.json","graph_json":"https://pith.science/api/pith-number/YA3EYCG6XBY3DWPU37R3GNWTRF/graph.json","events_json":"https://pith.science/api/pith-number/YA3EYCG6XBY3DWPU37R3GNWTRF/events.json","paper":"https://pith.science/paper/YA3EYCG6"},"agent_actions":{"view_html":"https://pith.science/pith/YA3EYCG6XBY3DWPU37R3GNWTRF","download_json":"https://pith.science/pith/YA3EYCG6XBY3DWPU37R3GNWTRF.json","view_paper":"https://pith.science/paper/YA3EYCG6","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2405.11916&json=true","fetch_graph":"https://pith.science/api/pith-number/YA3EYCG6XBY3DWPU37R3GNWTRF/graph.json","fetch_events":"https://pith.science/api/pith-number/YA3EYCG6XBY3DWPU37R3GNWTRF/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/YA3EYCG6XBY3DWPU37R3GNWTRF/action/timestamp_anchor","attest_storage":"https://pith.science/pith/YA3EYCG6XBY3DWPU37R3GNWTRF/action/storage_attestation","attest_author":"https://pith.science/pith/YA3EYCG6XBY3DWPU37R3GNWTRF/action/author_attestation","sign_citation":"https://pith.science/pith/YA3EYCG6XBY3DWPU37R3GNWTRF/action/citation_signature","submit_replication":"https://pith.science/pith/YA3EYCG6XBY3DWPU37R3GNWTRF/action/replication_record"}},"created_at":"2026-07-05T08:21:55.521924+00:00","updated_at":"2026-07-05T08:21:55.521924+00:00"}