{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:ZPNZCK663C25UFCMMJPWCXGTVH","short_pith_number":"pith:ZPNZCK66","schema_version":"1.0","canonical_sha256":"cbdb912bded8b5da144c625f615cd3a9f1f0f4dde8487fef971cdf472f0e1eef","source":{"kind":"arxiv","id":"2303.12233","version":2},"attestation_state":"computed","paper":{"title":"LOKI: Large-scale Data Reconstruction Attack against Federated Learning through Model Manipulation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Ahmed Roushdy Elkordy, Atul Sharma, Joshua C. Zhao, Salman Avestimehr, Saurabh Bagchi, Yahya H. Ezzeldin","submitted_at":"2023-03-21T23:29:35Z","abstract_excerpt":"Federated learning was introduced to enable machine learning over large decentralized datasets while promising privacy by eliminating the need for data sharing. Despite this, prior work has shown that shared gradients often contain private information and attackers can gain knowledge either through malicious modification of the architecture and parameters or by using optimization to approximate user data from the shared gradients. However, prior data reconstruction attacks have been limited in setting and scale, as most works target FedSGD and limit the attack to single-client gradients. Many "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2303.12233","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2023-03-21T23:29:35Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"8b2a18cbd8b420dadbdca7bb393085d1060021ae459c95217bacdb0cf5202363","abstract_canon_sha256":"bd31ed9dd0143acfec8e7fde17edc19ea6ac58bede25f4436b206ea7789f964e"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T06:53:35.755010Z","signature_b64":"MSg8tJA5W2ei5VVSP9Nb9sm4dQ0ih/EOvIxSlKiILAX1mmcQDCldpSjEZb1EPeZxa2TL301v8kEczz2JymzJDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"cbdb912bded8b5da144c625f615cd3a9f1f0f4dde8487fef971cdf472f0e1eef","last_reissued_at":"2026-07-05T06:53:35.754518Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T06:53:35.754518Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"LOKI: Large-scale Data Reconstruction Attack against Federated Learning through Model Manipulation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Ahmed Roushdy Elkordy, Atul Sharma, Joshua C. Zhao, Salman Avestimehr, Saurabh Bagchi, Yahya H. Ezzeldin","submitted_at":"2023-03-21T23:29:35Z","abstract_excerpt":"Federated learning was introduced to enable machine learning over large decentralized datasets while promising privacy by eliminating the need for data sharing. Despite this, prior work has shown that shared gradients often contain private information and attackers can gain knowledge either through malicious modification of the architecture and parameters or by using optimization to approximate user data from the shared gradients. However, prior data reconstruction attacks have been limited in setting and scale, as most works target FedSGD and limit the attack to single-client gradients. Many "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2303.12233","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2303.12233/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2303.12233","created_at":"2026-07-05T06:53:35.754578+00:00"},{"alias_kind":"arxiv_version","alias_value":"2303.12233v2","created_at":"2026-07-05T06:53:35.754578+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2303.12233","created_at":"2026-07-05T06:53:35.754578+00:00"},{"alias_kind":"pith_short_12","alias_value":"ZPNZCK663C25","created_at":"2026-07-05T06:53:35.754578+00:00"},{"alias_kind":"pith_short_16","alias_value":"ZPNZCK663C25UFCM","created_at":"2026-07-05T06:53:35.754578+00:00"},{"alias_kind":"pith_short_8","alias_value":"ZPNZCK66","created_at":"2026-07-05T06:53:35.754578+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2506.01777","citing_title":"DRAUN: An Algorithm-Agnostic Data Reconstruction Attack on Federated Unlearning Systems","ref_index":61,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/ZPNZCK663C25UFCMMJPWCXGTVH","json":"https://pith.science/pith/ZPNZCK663C25UFCMMJPWCXGTVH.json","graph_json":"https://pith.science/api/pith-number/ZPNZCK663C25UFCMMJPWCXGTVH/graph.json","events_json":"https://pith.science/api/pith-number/ZPNZCK663C25UFCMMJPWCXGTVH/events.json","paper":"https://pith.science/paper/ZPNZCK66"},"agent_actions":{"view_html":"https://pith.science/pith/ZPNZCK663C25UFCMMJPWCXGTVH","download_json":"https://pith.science/pith/ZPNZCK663C25UFCMMJPWCXGTVH.json","view_paper":"https://pith.science/paper/ZPNZCK66","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2303.12233&json=true","fetch_graph":"https://pith.science/api/pith-number/ZPNZCK663C25UFCMMJPWCXGTVH/graph.json","fetch_events":"https://pith.science/api/pith-number/ZPNZCK663C25UFCMMJPWCXGTVH/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/ZPNZCK663C25UFCMMJPWCXGTVH/action/timestamp_anchor","attest_storage":"https://pith.science/pith/ZPNZCK663C25UFCMMJPWCXGTVH/action/storage_attestation","attest_author":"https://pith.science/pith/ZPNZCK663C25UFCMMJPWCXGTVH/action/author_attestation","sign_citation":"https://pith.science/pith/ZPNZCK663C25UFCMMJPWCXGTVH/action/citation_signature","submit_replication":"https://pith.science/pith/ZPNZCK663C25UFCMMJPWCXGTVH/action/replication_record"}},"created_at":"2026-07-05T06:53:35.754578+00:00","updated_at":"2026-07-05T06:53:35.754578+00:00"}