{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:3FCFE35HMSCL3Y3STNSCNT3REU","short_pith_number":"pith:3FCFE35H","canonical_record":{"source":{"id":"2606.22779","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-22T02:42:38Z","cross_cats_sorted":["cs.CV"],"title_canon_sha256":"b90e6bee5135a05cf4c41869b27bbe513ac4469829ba0490eae6d595a3a77d70","abstract_canon_sha256":"104bb36aa708d9c529ac6e24233e1ac171671f1c34c737ebbd5179ec6db1eda4"},"schema_version":"1.0"},"canonical_sha256":"d944526fa76484bde3729b6426cf71251a725b96d7701d596a0bfdd53e1c1262","source":{"kind":"arxiv","id":"2606.22779","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.22779","created_at":"2026-06-23T02:13:54Z"},{"alias_kind":"arxiv_version","alias_value":"2606.22779v1","created_at":"2026-06-23T02:13:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.22779","created_at":"2026-06-23T02:13:54Z"},{"alias_kind":"pith_short_12","alias_value":"3FCFE35HMSCL","created_at":"2026-06-23T02:13:54Z"},{"alias_kind":"pith_short_16","alias_value":"3FCFE35HMSCL3Y3S","created_at":"2026-06-23T02:13:54Z"},{"alias_kind":"pith_short_8","alias_value":"3FCFE35H","created_at":"2026-06-23T02:13:54Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:3FCFE35HMSCL3Y3STNSCNT3REU","target":"record","payload":{"canonical_record":{"source":{"id":"2606.22779","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-22T02:42:38Z","cross_cats_sorted":["cs.CV"],"title_canon_sha256":"b90e6bee5135a05cf4c41869b27bbe513ac4469829ba0490eae6d595a3a77d70","abstract_canon_sha256":"104bb36aa708d9c529ac6e24233e1ac171671f1c34c737ebbd5179ec6db1eda4"},"schema_version":"1.0"},"canonical_sha256":"d944526fa76484bde3729b6426cf71251a725b96d7701d596a0bfdd53e1c1262","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-23T02:13:54.339083Z","signature_b64":"T2K1dnsWh4dnrN1uhGE3Fyph8tTCJGMDGjYR/bGc3uztnoV0WOJi79bZ4a4fH18BCXVLiT1fdx+flUqtkrpDBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d944526fa76484bde3729b6426cf71251a725b96d7701d596a0bfdd53e1c1262","last_reissued_at":"2026-06-23T02:13:54.338718Z","signature_status":"signed_v1","first_computed_at":"2026-06-23T02:13:54.338718Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.22779","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-23T02:13:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"86rPne3wsiVINxJ9gMLBjOLyZQpQ3siJ6V8mGvKFNnxPmvDR//rLbhgz7UGwQHpaspxcOESp2kfEKv3byblfCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T05:20:21.760106Z"},"content_sha256":"217be6e3b46d58d11ea018857c675327840cb608cb828da33626595a4d165758","schema_version":"1.0","event_id":"sha256:217be6e3b46d58d11ea018857c675327840cb608cb828da33626595a4d165758"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:3FCFE35HMSCL3Y3STNSCNT3REU","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"DE-FIVE: Detecting Malicious Image Prompts via Fourier Features and Image Vector Embeddings","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CV"],"primary_cat":"cs.CR","authors_text":"Kar Wai Fok, Varun Sharma, Vrizlynn L. L. Thing, Xingwei Zhong","submitted_at":"2026-06-22T02:42:38Z","abstract_excerpt":"Vision language models (VLMs) employ both visual and textual modalities to enable advanced vision-language inference. However, incorporating visual modalities expands the attack surface of VLMs, making them more susceptible to security threats such as adversarial perturbations and indirect prompt injection, wherein crafted malicious image prompts can elicit unintended model outputs. Existing defense methods against malicious image prompts remain insufficient as they typically demand extensive datasets for retraining or the deployment of additional, complex classifiers. Most critically, there i"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.22779","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.22779/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-23T02:13:54Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"akmq0ZOEbYyxF6pl+++67BBS/h8aKxXy+RZcU8sYylBuBm86gl1+87KosKEZ2TL6UWxv7Z80sdrdzGr6EWGeBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T05:20:21.760560Z"},"content_sha256":"0e8c321103aa79762e37014dfac1a21586fec58338fac2b3a060d762c1072325","schema_version":"1.0","event_id":"sha256:0e8c321103aa79762e37014dfac1a21586fec58338fac2b3a060d762c1072325"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/3FCFE35HMSCL3Y3STNSCNT3REU/bundle.json","state_url":"https://pith.science/pith/3FCFE35HMSCL3Y3STNSCNT3REU/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/3FCFE35HMSCL3Y3STNSCNT3REU/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-27T05:20:21Z","links":{"resolver":"https://pith.science/pith/3FCFE35HMSCL3Y3STNSCNT3REU","bundle":"https://pith.science/pith/3FCFE35HMSCL3Y3STNSCNT3REU/bundle.json","state":"https://pith.science/pith/3FCFE35HMSCL3Y3STNSCNT3REU/state.json","well_known_bundle":"https://pith.science/.well-known/pith/3FCFE35HMSCL3Y3STNSCNT3REU/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:3FCFE35HMSCL3Y3STNSCNT3REU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"104bb36aa708d9c529ac6e24233e1ac171671f1c34c737ebbd5179ec6db1eda4","cross_cats_sorted":["cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-22T02:42:38Z","title_canon_sha256":"b90e6bee5135a05cf4c41869b27bbe513ac4469829ba0490eae6d595a3a77d70"},"schema_version":"1.0","source":{"id":"2606.22779","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.22779","created_at":"2026-06-23T02:13:54Z"},{"alias_kind":"arxiv_version","alias_value":"2606.22779v1","created_at":"2026-06-23T02:13:54Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.22779","created_at":"2026-06-23T02:13:54Z"},{"alias_kind":"pith_short_12","alias_value":"3FCFE35HMSCL","created_at":"2026-06-23T02:13:54Z"},{"alias_kind":"pith_short_16","alias_value":"3FCFE35HMSCL3Y3S","created_at":"2026-06-23T02:13:54Z"},{"alias_kind":"pith_short_8","alias_value":"3FCFE35H","created_at":"2026-06-23T02:13:54Z"}],"graph_snapshots":[{"event_id":"sha256:0e8c321103aa79762e37014dfac1a21586fec58338fac2b3a060d762c1072325","target":"graph","created_at":"2026-06-23T02:13:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.22779/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Vision language models (VLMs) employ both visual and textual modalities to enable advanced vision-language inference. However, incorporating visual modalities expands the attack surface of VLMs, making them more susceptible to security threats such as adversarial perturbations and indirect prompt injection, wherein crafted malicious image prompts can elicit unintended model outputs. Existing defense methods against malicious image prompts remain insufficient as they typically demand extensive datasets for retraining or the deployment of additional, complex classifiers. Most critically, there i","authors_text":"Kar Wai Fok, Varun Sharma, Vrizlynn L. L. Thing, Xingwei Zhong","cross_cats":["cs.CV"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-22T02:42:38Z","title":"DE-FIVE: Detecting Malicious Image Prompts via Fourier Features and Image Vector Embeddings"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.22779","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:217be6e3b46d58d11ea018857c675327840cb608cb828da33626595a4d165758","target":"record","created_at":"2026-06-23T02:13:54Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"104bb36aa708d9c529ac6e24233e1ac171671f1c34c737ebbd5179ec6db1eda4","cross_cats_sorted":["cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-22T02:42:38Z","title_canon_sha256":"b90e6bee5135a05cf4c41869b27bbe513ac4469829ba0490eae6d595a3a77d70"},"schema_version":"1.0","source":{"id":"2606.22779","kind":"arxiv","version":1}},"canonical_sha256":"d944526fa76484bde3729b6426cf71251a725b96d7701d596a0bfdd53e1c1262","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d944526fa76484bde3729b6426cf71251a725b96d7701d596a0bfdd53e1c1262","first_computed_at":"2026-06-23T02:13:54.338718Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-23T02:13:54.338718Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"T2K1dnsWh4dnrN1uhGE3Fyph8tTCJGMDGjYR/bGc3uztnoV0WOJi79bZ4a4fH18BCXVLiT1fdx+flUqtkrpDBA==","signature_status":"signed_v1","signed_at":"2026-06-23T02:13:54.339083Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.22779","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:217be6e3b46d58d11ea018857c675327840cb608cb828da33626595a4d165758","sha256:0e8c321103aa79762e37014dfac1a21586fec58338fac2b3a060d762c1072325"],"state_sha256":"7ab89efa129f8c1cc9ebc4b01a675bd518b62cac5996766901dee5b9656374de"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"zfq4vlqGOA7ywMERkbRp09hxJ2KMmnBewr6G0snaYHHucr2ZJ2+zW614EmTfM4DkOcMbtai93LuRfsjFJJPwDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-27T05:20:21.762508Z","bundle_sha256":"759231c271d97ce6570749b8f4fe1713249487f3f2b0fb48aa39bb4f1a1456f0"}}