{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:3R4R44DHMRZSN64POGZHJTPMB3","short_pith_number":"pith:3R4R44DH","canonical_record":{"source":{"id":"2606.01837","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-01T07:49:12Z","cross_cats_sorted":[],"title_canon_sha256":"a533e595bd05cc3073bdb91f5c5f7f609fbe3705f2fe066d0c8269f11ec25d3a","abstract_canon_sha256":"271eecf8bf11ccaa5642e486ceb5b0c43c856a46eb0a35501950b4c3022712cb"},"schema_version":"1.0"},"canonical_sha256":"dc791e7067647326fb8f71b274cdec0ec4a860f73ca88456b5135e10fab16a13","source":{"kind":"arxiv","id":"2606.01837","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.01837","created_at":"2026-06-02T02:04:58Z"},{"alias_kind":"arxiv_version","alias_value":"2606.01837v1","created_at":"2026-06-02T02:04:58Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.01837","created_at":"2026-06-02T02:04:58Z"},{"alias_kind":"pith_short_12","alias_value":"3R4R44DHMRZS","created_at":"2026-06-02T02:04:58Z"},{"alias_kind":"pith_short_16","alias_value":"3R4R44DHMRZSN64P","created_at":"2026-06-02T02:04:58Z"},{"alias_kind":"pith_short_8","alias_value":"3R4R44DH","created_at":"2026-06-02T02:04:58Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:3R4R44DHMRZSN64POGZHJTPMB3","target":"record","payload":{"canonical_record":{"source":{"id":"2606.01837","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-01T07:49:12Z","cross_cats_sorted":[],"title_canon_sha256":"a533e595bd05cc3073bdb91f5c5f7f609fbe3705f2fe066d0c8269f11ec25d3a","abstract_canon_sha256":"271eecf8bf11ccaa5642e486ceb5b0c43c856a46eb0a35501950b4c3022712cb"},"schema_version":"1.0"},"canonical_sha256":"dc791e7067647326fb8f71b274cdec0ec4a860f73ca88456b5135e10fab16a13","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-02T02:04:58.166818Z","signature_b64":"UzCIBdoNLRGnwkSjH5+SpPQE4rLkLuq+hQX1Pz/bbRBJCtFzCTUH015PCeQp9KPPynebv7+IYHNbd/KdOnbmDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"dc791e7067647326fb8f71b274cdec0ec4a860f73ca88456b5135e10fab16a13","last_reissued_at":"2026-06-02T02:04:58.166429Z","signature_status":"signed_v1","first_computed_at":"2026-06-02T02:04:58.166429Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.01837","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T02:04:58Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"VNyOEk9pCfFEodORrScVQ8BR4SniXu7nyd15nqrEmzqCLJyFHpaGHHtkCd3qUPMwJjj4U5NLq6l778zdDeYpCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T09:13:40.486185Z"},"content_sha256":"ad6a5fce71e58f07935985472c7887743868f611e3d2e56867f57a3c4ff7bbb7","schema_version":"1.0","event_id":"sha256:ad6a5fce71e58f07935985472c7887743868f611e3d2e56867f57a3c4ff7bbb7"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:3R4R44DHMRZSN64POGZHJTPMB3","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Benign Inputs, Harmful Outputs: Cross-Modal Jailbreaking via Distributed Semantic Recomposition","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Yang Liu, Yani Wang, Yilong Yang, Zhuo Ma, Zhuzhu Wang, Zuobin Ying","submitted_at":"2026-06-01T07:49:12Z","abstract_excerpt":"Multimodal Large Language Models (MLLMs) have recently demonstrated remarkable capabilities in content synthesis and autonomous reasoning. Previous safety guardrails are primarily designed for unimodal textual input interception, leaving them vulnerable to cross-modal jailbreak attacks. However, regardless unimodal textual attack or cross-modal jailbreak, typically inclusive part of explicit harmful or sensitive content at the input level, which is called Harm-Bearing. It allow the model's safety filters to detect and block such content easily. To address this limitations, we propose Distribut"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.01837","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.01837/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T02:04:58Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"WrEz2UC9yiiTr3Yh7pAiu9lCQxDVopYGsA0M9PaZA1VlUerEhYdW60n+0+whCVkrZv8sBY3G+KNyn/LxKilVBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T09:13:40.486596Z"},"content_sha256":"9487f0664b66b8798560fe45ef3b97c6d8938ee6884c7d0636ae153faa028735","schema_version":"1.0","event_id":"sha256:9487f0664b66b8798560fe45ef3b97c6d8938ee6884c7d0636ae153faa028735"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/3R4R44DHMRZSN64POGZHJTPMB3/bundle.json","state_url":"https://pith.science/pith/3R4R44DHMRZSN64POGZHJTPMB3/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/3R4R44DHMRZSN64POGZHJTPMB3/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-03T09:13:40Z","links":{"resolver":"https://pith.science/pith/3R4R44DHMRZSN64POGZHJTPMB3","bundle":"https://pith.science/pith/3R4R44DHMRZSN64POGZHJTPMB3/bundle.json","state":"https://pith.science/pith/3R4R44DHMRZSN64POGZHJTPMB3/state.json","well_known_bundle":"https://pith.science/.well-known/pith/3R4R44DHMRZSN64POGZHJTPMB3/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:3R4R44DHMRZSN64POGZHJTPMB3","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"271eecf8bf11ccaa5642e486ceb5b0c43c856a46eb0a35501950b4c3022712cb","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-01T07:49:12Z","title_canon_sha256":"a533e595bd05cc3073bdb91f5c5f7f609fbe3705f2fe066d0c8269f11ec25d3a"},"schema_version":"1.0","source":{"id":"2606.01837","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.01837","created_at":"2026-06-02T02:04:58Z"},{"alias_kind":"arxiv_version","alias_value":"2606.01837v1","created_at":"2026-06-02T02:04:58Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.01837","created_at":"2026-06-02T02:04:58Z"},{"alias_kind":"pith_short_12","alias_value":"3R4R44DHMRZS","created_at":"2026-06-02T02:04:58Z"},{"alias_kind":"pith_short_16","alias_value":"3R4R44DHMRZSN64P","created_at":"2026-06-02T02:04:58Z"},{"alias_kind":"pith_short_8","alias_value":"3R4R44DH","created_at":"2026-06-02T02:04:58Z"}],"graph_snapshots":[{"event_id":"sha256:9487f0664b66b8798560fe45ef3b97c6d8938ee6884c7d0636ae153faa028735","target":"graph","created_at":"2026-06-02T02:04:58Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.01837/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Multimodal Large Language Models (MLLMs) have recently demonstrated remarkable capabilities in content synthesis and autonomous reasoning. Previous safety guardrails are primarily designed for unimodal textual input interception, leaving them vulnerable to cross-modal jailbreak attacks. However, regardless unimodal textual attack or cross-modal jailbreak, typically inclusive part of explicit harmful or sensitive content at the input level, which is called Harm-Bearing. It allow the model's safety filters to detect and block such content easily. To address this limitations, we propose Distribut","authors_text":"Yang Liu, Yani Wang, Yilong Yang, Zhuo Ma, Zhuzhu Wang, Zuobin Ying","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-01T07:49:12Z","title":"Benign Inputs, Harmful Outputs: Cross-Modal Jailbreaking via Distributed Semantic Recomposition"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.01837","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:ad6a5fce71e58f07935985472c7887743868f611e3d2e56867f57a3c4ff7bbb7","target":"record","created_at":"2026-06-02T02:04:58Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"271eecf8bf11ccaa5642e486ceb5b0c43c856a46eb0a35501950b4c3022712cb","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-01T07:49:12Z","title_canon_sha256":"a533e595bd05cc3073bdb91f5c5f7f609fbe3705f2fe066d0c8269f11ec25d3a"},"schema_version":"1.0","source":{"id":"2606.01837","kind":"arxiv","version":1}},"canonical_sha256":"dc791e7067647326fb8f71b274cdec0ec4a860f73ca88456b5135e10fab16a13","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"dc791e7067647326fb8f71b274cdec0ec4a860f73ca88456b5135e10fab16a13","first_computed_at":"2026-06-02T02:04:58.166429Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-02T02:04:58.166429Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"UzCIBdoNLRGnwkSjH5+SpPQE4rLkLuq+hQX1Pz/bbRBJCtFzCTUH015PCeQp9KPPynebv7+IYHNbd/KdOnbmDQ==","signature_status":"signed_v1","signed_at":"2026-06-02T02:04:58.166818Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.01837","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:ad6a5fce71e58f07935985472c7887743868f611e3d2e56867f57a3c4ff7bbb7","sha256:9487f0664b66b8798560fe45ef3b97c6d8938ee6884c7d0636ae153faa028735"],"state_sha256":"4d73d4f9fd99a181fcb5b3af538f96554556416db1989c8c15848536f0a3d90f"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"fP4WUzujK+aCqpAdjLpLIgpEYvwz4/bQjrHKriIwWhL7iWTQTJKY+K2Op4Gn+O3yk0QIU507aPruTEKr5a33Cw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-03T09:13:40.488882Z","bundle_sha256":"1420c7c364e9e3c37cb1804151ab558260682290007b9dbc7c2a5a3b791a782d"}}