{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:YXPCNTYKO7NGDQ3C7A2LZV56DN","short_pith_number":"pith:YXPCNTYK","schema_version":"1.0","canonical_sha256":"c5de26cf0a77da61c362f834bcd7be1b6f2120391625aa2b08fb7a80dff76aa2","source":{"kind":"arxiv","id":"2504.05147","version":2},"attestation_state":"computed","paper":{"title":"Pr$\\epsilon\\epsilon$mpt: Sanitizing Sensitive Prompts for LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Amrita Roy Chowdhury, David Glukhov, Divyam Anshumaan, Mihir Bellare, Nicolas Papernot, Prasad Chalasani, Somesh Jha","submitted_at":"2025-04-07T14:52:40Z","abstract_excerpt":"The rise of large language models (LLMs) has introduced new privacy challenges, particularly during inference where sensitive information in prompts may be exposed to proprietary LLM APIs. In this paper, we address the problem of formally protecting the sensitive information contained in a prompt while maintaining response quality. To this end, first, we introduce a cryptographically inspired notion of a prompt sanitizer which transforms an input prompt to protect its sensitive tokens. Second, we propose Pr$\\epsilon\\epsilon$mpt, a novel system that implements a prompt sanitizer. Pr$\\epsilon\\ep"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2504.05147","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-04-07T14:52:40Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"8a2d158e6998d73293789daf587e2e52cd73185692de69e998855c7c60d462a0","abstract_canon_sha256":"0c87d8d80d806f7dd7e842ae92342186c06a0d2c027b648a8146972d898959d5"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:54:30.387579Z","signature_b64":"A+kTKpIFnHyeD7oecaDTB+MhdI9vUdkXPqrNQWxud49jb8a3SmKLJn4GzZYqqSv+RVio9/ij6oLA2HTLVG7TDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c5de26cf0a77da61c362f834bcd7be1b6f2120391625aa2b08fb7a80dff76aa2","last_reissued_at":"2026-07-05T11:54:30.387094Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:54:30.387094Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Pr$\\epsilon\\epsilon$mpt: Sanitizing Sensitive Prompts for LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Amrita Roy Chowdhury, David Glukhov, Divyam Anshumaan, Mihir Bellare, Nicolas Papernot, Prasad Chalasani, Somesh Jha","submitted_at":"2025-04-07T14:52:40Z","abstract_excerpt":"The rise of large language models (LLMs) has introduced new privacy challenges, particularly during inference where sensitive information in prompts may be exposed to proprietary LLM APIs. In this paper, we address the problem of formally protecting the sensitive information contained in a prompt while maintaining response quality. To this end, first, we introduce a cryptographically inspired notion of a prompt sanitizer which transforms an input prompt to protect its sensitive tokens. Second, we propose Pr$\\epsilon\\epsilon$mpt, a novel system that implements a prompt sanitizer. Pr$\\epsilon\\ep"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2504.05147","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2504.05147/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2504.05147","created_at":"2026-07-05T11:54:30.387151+00:00"},{"alias_kind":"arxiv_version","alias_value":"2504.05147v2","created_at":"2026-07-05T11:54:30.387151+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2504.05147","created_at":"2026-07-05T11:54:30.387151+00:00"},{"alias_kind":"pith_short_12","alias_value":"YXPCNTYKO7NG","created_at":"2026-07-05T11:54:30.387151+00:00"},{"alias_kind":"pith_short_16","alias_value":"YXPCNTYKO7NGDQ3C","created_at":"2026-07-05T11:54:30.387151+00:00"},{"alias_kind":"pith_short_8","alias_value":"YXPCNTYK","created_at":"2026-07-05T11:54:30.387151+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2505.14549","citing_title":"Can Large Language Models Really Recognize Your Name?","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2605.08646","citing_title":"PAAC: Privacy-Aware Agentic Device-Cloud Collaboration","ref_index":8,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/YXPCNTYKO7NGDQ3C7A2LZV56DN","json":"https://pith.science/pith/YXPCNTYKO7NGDQ3C7A2LZV56DN.json","graph_json":"https://pith.science/api/pith-number/YXPCNTYKO7NGDQ3C7A2LZV56DN/graph.json","events_json":"https://pith.science/api/pith-number/YXPCNTYKO7NGDQ3C7A2LZV56DN/events.json","paper":"https://pith.science/paper/YXPCNTYK"},"agent_actions":{"view_html":"https://pith.science/pith/YXPCNTYKO7NGDQ3C7A2LZV56DN","download_json":"https://pith.science/pith/YXPCNTYKO7NGDQ3C7A2LZV56DN.json","view_paper":"https://pith.science/paper/YXPCNTYK","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2504.05147&json=true","fetch_graph":"https://pith.science/api/pith-number/YXPCNTYKO7NGDQ3C7A2LZV56DN/graph.json","fetch_events":"https://pith.science/api/pith-number/YXPCNTYKO7NGDQ3C7A2LZV56DN/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/YXPCNTYKO7NGDQ3C7A2LZV56DN/action/timestamp_anchor","attest_storage":"https://pith.science/pith/YXPCNTYKO7NGDQ3C7A2LZV56DN/action/storage_attestation","attest_author":"https://pith.science/pith/YXPCNTYKO7NGDQ3C7A2LZV56DN/action/author_attestation","sign_citation":"https://pith.science/pith/YXPCNTYKO7NGDQ3C7A2LZV56DN/action/citation_signature","submit_replication":"https://pith.science/pith/YXPCNTYKO7NGDQ3C7A2LZV56DN/action/replication_record"}},"created_at":"2026-07-05T11:54:30.387151+00:00","updated_at":"2026-07-05T11:54:30.387151+00:00"}