{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:3QSICUOKE2LEEGFJFFMZYIFRLC","short_pith_number":"pith:3QSICUOK","canonical_record":{"source":{"id":"2605.25194","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-24T17:51:34Z","cross_cats_sorted":[],"title_canon_sha256":"2ed52de81a668684e212e7a913065815c7160dbea57217be80438bd9ffa5686c","abstract_canon_sha256":"2b3db5e31cff2650cd498eac7ff03353a87f579cd1a6046ce5b8bc447b9fa9ad"},"schema_version":"1.0"},"canonical_sha256":"dc248151ca26964218a929599c20b158a4af01a3cc4cebfc5d980b742aa4abd7","source":{"kind":"arxiv","id":"2605.25194","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.25194","created_at":"2026-05-26T02:04:22Z"},{"alias_kind":"arxiv_version","alias_value":"2605.25194v1","created_at":"2026-05-26T02:04:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.25194","created_at":"2026-05-26T02:04:22Z"},{"alias_kind":"pith_short_12","alias_value":"3QSICUOKE2LE","created_at":"2026-05-26T02:04:22Z"},{"alias_kind":"pith_short_16","alias_value":"3QSICUOKE2LEEGFJ","created_at":"2026-05-26T02:04:22Z"},{"alias_kind":"pith_short_8","alias_value":"3QSICUOK","created_at":"2026-05-26T02:04:22Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:3QSICUOKE2LEEGFJFFMZYIFRLC","target":"record","payload":{"canonical_record":{"source":{"id":"2605.25194","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-24T17:51:34Z","cross_cats_sorted":[],"title_canon_sha256":"2ed52de81a668684e212e7a913065815c7160dbea57217be80438bd9ffa5686c","abstract_canon_sha256":"2b3db5e31cff2650cd498eac7ff03353a87f579cd1a6046ce5b8bc447b9fa9ad"},"schema_version":"1.0"},"canonical_sha256":"dc248151ca26964218a929599c20b158a4af01a3cc4cebfc5d980b742aa4abd7","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T02:04:22.542079Z","signature_b64":"Qp4einvDe5/VjEmYZmvQOF6haasAkzq/k5u9FslfdvcBFkTRNCpXD8JMFlLdT0HiN/wZJT0QB9bR2usMU4d0AA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"dc248151ca26964218a929599c20b158a4af01a3cc4cebfc5d980b742aa4abd7","last_reissued_at":"2026-05-26T02:04:22.541223Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T02:04:22.541223Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.25194","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T02:04:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iCqGeRmYyNimIfEpbPXU/viJ9fDGeEiKZtGjpK5t3ruZbFey5eC5BcgltSAtP0QKgTnSHhs669Mg0BtrvU8oDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T12:37:56.642842Z"},"content_sha256":"ee6b3ee28f8a6ce9e65c22ce38c167dab5642e176319e35e7201c4e2df40d14a","schema_version":"1.0","event_id":"sha256:ee6b3ee28f8a6ce9e65c22ce38c167dab5642e176319e35e7201c4e2df40d14a"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:3QSICUOKE2LEEGFJFFMZYIFRLC","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Localization then Neutralization: Gradient-guided Token Suppression against Visual Prompt Injection Attack","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Dongpeng Zhang, Gaozheng Pei, Ke Ma, Longtao Huang, Qianqian Xu, Qingming Huang, Yangbangyan Jiang","submitted_at":"2026-05-24T17:51:34Z","abstract_excerpt":"Adversarial images pose a severe security threat to multimodal large language models through prompt injection. Existing defenses largely lack a principled understanding of the underlying mechanisms and struggle to balance efficiency and defense utility. In this work, we show that successful adversarial attacks do not rely on the entire image uniformly but instead depend on a small subset of critical image tokens. Based on this insight, we propose Gradient Token Masking (GTM), which localizes these tokens via gradient analysis and neutralizes them through masking. We find that attribution based"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.25194","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.25194/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T02:04:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8HztancApmR27nTzneqgD1WdeG22yYualEQ9MKozB/xDx7oHM/yZE6P6EfJiVyLKS1Vrh5VhQV+w3XlwWJfgAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T12:37:56.643559Z"},"content_sha256":"436f2cda09902b7c2177952941b4402f389d76c3fa539af41f1f4f846acd81da","schema_version":"1.0","event_id":"sha256:436f2cda09902b7c2177952941b4402f389d76c3fa539af41f1f4f846acd81da"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/3QSICUOKE2LEEGFJFFMZYIFRLC/bundle.json","state_url":"https://pith.science/pith/3QSICUOKE2LEEGFJFFMZYIFRLC/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/3QSICUOKE2LEEGFJFFMZYIFRLC/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-27T12:37:56Z","links":{"resolver":"https://pith.science/pith/3QSICUOKE2LEEGFJFFMZYIFRLC","bundle":"https://pith.science/pith/3QSICUOKE2LEEGFJFFMZYIFRLC/bundle.json","state":"https://pith.science/pith/3QSICUOKE2LEEGFJFFMZYIFRLC/state.json","well_known_bundle":"https://pith.science/.well-known/pith/3QSICUOKE2LEEGFJFFMZYIFRLC/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:3QSICUOKE2LEEGFJFFMZYIFRLC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"2b3db5e31cff2650cd498eac7ff03353a87f579cd1a6046ce5b8bc447b9fa9ad","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-24T17:51:34Z","title_canon_sha256":"2ed52de81a668684e212e7a913065815c7160dbea57217be80438bd9ffa5686c"},"schema_version":"1.0","source":{"id":"2605.25194","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.25194","created_at":"2026-05-26T02:04:22Z"},{"alias_kind":"arxiv_version","alias_value":"2605.25194v1","created_at":"2026-05-26T02:04:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.25194","created_at":"2026-05-26T02:04:22Z"},{"alias_kind":"pith_short_12","alias_value":"3QSICUOKE2LE","created_at":"2026-05-26T02:04:22Z"},{"alias_kind":"pith_short_16","alias_value":"3QSICUOKE2LEEGFJ","created_at":"2026-05-26T02:04:22Z"},{"alias_kind":"pith_short_8","alias_value":"3QSICUOK","created_at":"2026-05-26T02:04:22Z"}],"graph_snapshots":[{"event_id":"sha256:436f2cda09902b7c2177952941b4402f389d76c3fa539af41f1f4f846acd81da","target":"graph","created_at":"2026-05-26T02:04:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.25194/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Adversarial images pose a severe security threat to multimodal large language models through prompt injection. Existing defenses largely lack a principled understanding of the underlying mechanisms and struggle to balance efficiency and defense utility. In this work, we show that successful adversarial attacks do not rely on the entire image uniformly but instead depend on a small subset of critical image tokens. Based on this insight, we propose Gradient Token Masking (GTM), which localizes these tokens via gradient analysis and neutralizes them through masking. We find that attribution based","authors_text":"Dongpeng Zhang, Gaozheng Pei, Ke Ma, Longtao Huang, Qianqian Xu, Qingming Huang, Yangbangyan Jiang","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-24T17:51:34Z","title":"Localization then Neutralization: Gradient-guided Token Suppression against Visual Prompt Injection Attack"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.25194","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ee6b3ee28f8a6ce9e65c22ce38c167dab5642e176319e35e7201c4e2df40d14a","target":"record","created_at":"2026-05-26T02:04:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"2b3db5e31cff2650cd498eac7ff03353a87f579cd1a6046ce5b8bc447b9fa9ad","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-24T17:51:34Z","title_canon_sha256":"2ed52de81a668684e212e7a913065815c7160dbea57217be80438bd9ffa5686c"},"schema_version":"1.0","source":{"id":"2605.25194","kind":"arxiv","version":1}},"canonical_sha256":"dc248151ca26964218a929599c20b158a4af01a3cc4cebfc5d980b742aa4abd7","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"dc248151ca26964218a929599c20b158a4af01a3cc4cebfc5d980b742aa4abd7","first_computed_at":"2026-05-26T02:04:22.541223Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-26T02:04:22.541223Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Qp4einvDe5/VjEmYZmvQOF6haasAkzq/k5u9FslfdvcBFkTRNCpXD8JMFlLdT0HiN/wZJT0QB9bR2usMU4d0AA==","signature_status":"signed_v1","signed_at":"2026-05-26T02:04:22.542079Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.25194","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ee6b3ee28f8a6ce9e65c22ce38c167dab5642e176319e35e7201c4e2df40d14a","sha256:436f2cda09902b7c2177952941b4402f389d76c3fa539af41f1f4f846acd81da"],"state_sha256":"1e50e1a8a52192087547c1822bef1c801951af200d0115d6a33adfbd4a206303"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"HTzt5XMsPcvXPxsBrH624vDxhsujuZQVnX2di9J7RJsSR0hTcuiJg8T/PGdTanqBtS34qTHnI9lsA3M9Uu4QBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-27T12:37:56.647205Z","bundle_sha256":"0900f25a8107e93bddd1c291dc08e72e064f652f0719ed29ab8cf3901c2ac36f"}}