{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:YPOCRNVHWKWXYFC2R3A3GK6NCE","short_pith_number":"pith:YPOCRNVH","canonical_record":{"source":{"id":"2606.24408","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-23T10:45:11Z","cross_cats_sorted":[],"title_canon_sha256":"da1c4ef9373f6c0e266a461b0c536821c1adb2c2d331bb001acf12ce9023de65","abstract_canon_sha256":"8336a7ea4ce7807f2931ba66c1b1050a8f01d9aeeb57750e316687d9cbba4840"},"schema_version":"1.0"},"canonical_sha256":"c3dc28b6a7b2ad7c145a8ec1b32bcd1134460eb8fc654f72d8f7d55fde57006e","source":{"kind":"arxiv","id":"2606.24408","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.24408","created_at":"2026-06-24T01:15:29Z"},{"alias_kind":"arxiv_version","alias_value":"2606.24408v1","created_at":"2026-06-24T01:15:29Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.24408","created_at":"2026-06-24T01:15:29Z"},{"alias_kind":"pith_short_12","alias_value":"YPOCRNVHWKWX","created_at":"2026-06-24T01:15:29Z"},{"alias_kind":"pith_short_16","alias_value":"YPOCRNVHWKWXYFC2","created_at":"2026-06-24T01:15:29Z"},{"alias_kind":"pith_short_8","alias_value":"YPOCRNVH","created_at":"2026-06-24T01:15:29Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:YPOCRNVHWKWXYFC2R3A3GK6NCE","target":"record","payload":{"canonical_record":{"source":{"id":"2606.24408","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-23T10:45:11Z","cross_cats_sorted":[],"title_canon_sha256":"da1c4ef9373f6c0e266a461b0c536821c1adb2c2d331bb001acf12ce9023de65","abstract_canon_sha256":"8336a7ea4ce7807f2931ba66c1b1050a8f01d9aeeb57750e316687d9cbba4840"},"schema_version":"1.0"},"canonical_sha256":"c3dc28b6a7b2ad7c145a8ec1b32bcd1134460eb8fc654f72d8f7d55fde57006e","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-24T01:15:29.748472Z","signature_b64":"oD73v1zKqnB8nXb/GRWnX0KNH6ERGYj4DRV6bTaxrXpHdhJa/Dz4ObPJSTsyNyudo4iYsUgi/HzFRLqM33qkDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c3dc28b6a7b2ad7c145a8ec1b32bcd1134460eb8fc654f72d8f7d55fde57006e","last_reissued_at":"2026-06-24T01:15:29.748118Z","signature_status":"signed_v1","first_computed_at":"2026-06-24T01:15:29.748118Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.24408","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-24T01:15:29Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"l0j7W4kF9flUvneB7TYKmdZZR9jOyQTEOze86yuO28JvOcJ8xMEBGkMhjf4niWbd5W/VUuVu/HFoAKegxt0QAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T12:17:28.472218Z"},"content_sha256":"24989958e85ff6651e70ff1e19887e7a3dd14822e4c8ffa10d7e680853016518","schema_version":"1.0","event_id":"sha256:24989958e85ff6651e70ff1e19887e7a3dd14822e4c8ffa10d7e680853016518"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:YPOCRNVHWKWXYFC2R3A3GK6NCE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Natural Identifiers for Privacy and Data Audits in Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Adam Dziedzic, Bart{\\l}omiej Marek, Franziska Boenisch, Lorenzo Rossi","submitted_at":"2026-06-23T10:45:11Z","abstract_excerpt":"Assessing the privacy of large language models (LLMs) presents significant challenges. In particular, most existing methods for auditing differential privacy require the insertion of specially crafted canary data during training, making them impractical for auditing already-trained models without costly retraining. Additionally, dataset inference, which audits whether a suspect dataset was used to train a model, is infeasible without access to a private non-member held-out dataset. Yet, such held-out datasets are often unavailable or difficult to construct for real-world cases since they have "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.24408","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.24408/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-24T01:15:29Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZG9QuH9ijZZoO0Ug8VZ+i12ETIvrKLDN9B+yI+pnTS7VFLRWZ/2Vgj2NVjm4hjy08+5+PGd1iTJpG235A9OYAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-28T12:17:28.472607Z"},"content_sha256":"f3a571359e7d7b49cb0b28093b25f745a1b79a5541535ee227150cddb78f8865","schema_version":"1.0","event_id":"sha256:f3a571359e7d7b49cb0b28093b25f745a1b79a5541535ee227150cddb78f8865"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/YPOCRNVHWKWXYFC2R3A3GK6NCE/bundle.json","state_url":"https://pith.science/pith/YPOCRNVHWKWXYFC2R3A3GK6NCE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/YPOCRNVHWKWXYFC2R3A3GK6NCE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-28T12:17:28Z","links":{"resolver":"https://pith.science/pith/YPOCRNVHWKWXYFC2R3A3GK6NCE","bundle":"https://pith.science/pith/YPOCRNVHWKWXYFC2R3A3GK6NCE/bundle.json","state":"https://pith.science/pith/YPOCRNVHWKWXYFC2R3A3GK6NCE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/YPOCRNVHWKWXYFC2R3A3GK6NCE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:YPOCRNVHWKWXYFC2R3A3GK6NCE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"8336a7ea4ce7807f2931ba66c1b1050a8f01d9aeeb57750e316687d9cbba4840","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-23T10:45:11Z","title_canon_sha256":"da1c4ef9373f6c0e266a461b0c536821c1adb2c2d331bb001acf12ce9023de65"},"schema_version":"1.0","source":{"id":"2606.24408","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.24408","created_at":"2026-06-24T01:15:29Z"},{"alias_kind":"arxiv_version","alias_value":"2606.24408v1","created_at":"2026-06-24T01:15:29Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.24408","created_at":"2026-06-24T01:15:29Z"},{"alias_kind":"pith_short_12","alias_value":"YPOCRNVHWKWX","created_at":"2026-06-24T01:15:29Z"},{"alias_kind":"pith_short_16","alias_value":"YPOCRNVHWKWXYFC2","created_at":"2026-06-24T01:15:29Z"},{"alias_kind":"pith_short_8","alias_value":"YPOCRNVH","created_at":"2026-06-24T01:15:29Z"}],"graph_snapshots":[{"event_id":"sha256:f3a571359e7d7b49cb0b28093b25f745a1b79a5541535ee227150cddb78f8865","target":"graph","created_at":"2026-06-24T01:15:29Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.24408/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Assessing the privacy of large language models (LLMs) presents significant challenges. In particular, most existing methods for auditing differential privacy require the insertion of specially crafted canary data during training, making them impractical for auditing already-trained models without costly retraining. Additionally, dataset inference, which audits whether a suspect dataset was used to train a model, is infeasible without access to a private non-member held-out dataset. Yet, such held-out datasets are often unavailable or difficult to construct for real-world cases since they have ","authors_text":"Adam Dziedzic, Bart{\\l}omiej Marek, Franziska Boenisch, Lorenzo Rossi","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-23T10:45:11Z","title":"Natural Identifiers for Privacy and Data Audits in Large Language Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.24408","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:24989958e85ff6651e70ff1e19887e7a3dd14822e4c8ffa10d7e680853016518","target":"record","created_at":"2026-06-24T01:15:29Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"8336a7ea4ce7807f2931ba66c1b1050a8f01d9aeeb57750e316687d9cbba4840","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-06-23T10:45:11Z","title_canon_sha256":"da1c4ef9373f6c0e266a461b0c536821c1adb2c2d331bb001acf12ce9023de65"},"schema_version":"1.0","source":{"id":"2606.24408","kind":"arxiv","version":1}},"canonical_sha256":"c3dc28b6a7b2ad7c145a8ec1b32bcd1134460eb8fc654f72d8f7d55fde57006e","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"c3dc28b6a7b2ad7c145a8ec1b32bcd1134460eb8fc654f72d8f7d55fde57006e","first_computed_at":"2026-06-24T01:15:29.748118Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-24T01:15:29.748118Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"oD73v1zKqnB8nXb/GRWnX0KNH6ERGYj4DRV6bTaxrXpHdhJa/Dz4ObPJSTsyNyudo4iYsUgi/HzFRLqM33qkDA==","signature_status":"signed_v1","signed_at":"2026-06-24T01:15:29.748472Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.24408","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:24989958e85ff6651e70ff1e19887e7a3dd14822e4c8ffa10d7e680853016518","sha256:f3a571359e7d7b49cb0b28093b25f745a1b79a5541535ee227150cddb78f8865"],"state_sha256":"794610eda3108b705a53815c34fd1f65099b62448c8e5a9f4c00c8a22abf8a5d"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wcNvseV9xT35Rk19UV4U/4RboRfxQvCky/fcaqNpuwhs4utKogxfofKCbnhFCaWFPZYWdalGXsR2F5tof1ojDA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-28T12:17:28.474497Z","bundle_sha256":"1dd1eafa7995647ff8f693c79a14285de83456e86d9db3522036a0c695385903"}}