{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:3T63JM3YO3GSGMHP74ZZ7F5XFF","short_pith_number":"pith:3T63JM3Y","canonical_record":{"source":{"id":"2503.14852","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2025-03-19T03:18:45Z","cross_cats_sorted":[],"title_canon_sha256":"4d34dc1cdcf58381679f097c4cbff1a007c1bdd9a2074f7c70b77bf2f7e55a78","abstract_canon_sha256":"e7433a2cee37d5aa641826776f6d4790984ad4c993326019efce195c6f45fce2"},"schema_version":"1.0"},"canonical_sha256":"dcfdb4b37876cd2330efff339f97b7295083e951e97636d9f59aa5fea1b2c521","source":{"kind":"arxiv","id":"2503.14852","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2503.14852","created_at":"2026-05-20T00:00:18Z"},{"alias_kind":"arxiv_version","alias_value":"2503.14852v2","created_at":"2026-05-20T00:00:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.14852","created_at":"2026-05-20T00:00:18Z"},{"alias_kind":"pith_short_12","alias_value":"3T63JM3YO3GS","created_at":"2026-05-20T00:00:18Z"},{"alias_kind":"pith_short_16","alias_value":"3T63JM3YO3GSGMHP","created_at":"2026-05-20T00:00:18Z"},{"alias_kind":"pith_short_8","alias_value":"3T63JM3Y","created_at":"2026-05-20T00:00:18Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:3T63JM3YO3GSGMHP74ZZ7F5XFF","target":"record","payload":{"canonical_record":{"source":{"id":"2503.14852","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2025-03-19T03:18:45Z","cross_cats_sorted":[],"title_canon_sha256":"4d34dc1cdcf58381679f097c4cbff1a007c1bdd9a2074f7c70b77bf2f7e55a78","abstract_canon_sha256":"e7433a2cee37d5aa641826776f6d4790984ad4c993326019efce195c6f45fce2"},"schema_version":"1.0"},"canonical_sha256":"dcfdb4b37876cd2330efff339f97b7295083e951e97636d9f59aa5fea1b2c521","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-20T00:00:18.329212Z","signature_b64":"L1HYExsyLnMx7IAga4cYULrS0tTte+gG7RCg/Qug751lFgLpNuCDVOIwLHtubaXfELVArus8a0+71GQ36mQ7Dg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"dcfdb4b37876cd2330efff339f97b7295083e951e97636d9f59aa5fea1b2c521","last_reissued_at":"2026-05-20T00:00:18.328413Z","signature_status":"signed_v1","first_computed_at":"2026-05-20T00:00:18.328413Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2503.14852","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:00:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"XzhHZMqwZAJNertzBVZZ2Zr+OF5YJHB/M7CZvM0FVb4DDtuEFUhTV93JVGvC7jv6xtNaNnQBqbWdDVGZN3HaDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T06:36:06.801101Z"},"content_sha256":"cf4bf8083806c3865dd85ed819fc2e391af4f82b926e364941ea7909798809b1","schema_version":"1.0","event_id":"sha256:cf4bf8083806c3865dd85ed819fc2e391af4f82b926e364941ea7909798809b1"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:3T63JM3YO3GSGMHP74ZZ7F5XFF","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"UntrustVul: An Automated Approach for Identifying Untrustworthy Alerts in Vulnerability Detection Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.SE","authors_text":"Aldeida Aleti, Lam Nguyen Tung, Neelofar Neelofar, Xiaoning Du","submitted_at":"2025-03-19T03:18:45Z","abstract_excerpt":"Machine learning (ML) has shown promise in vulnerability detection, but ML detectors may rely on irrelevant code features, causing them to highlight non-vulnerable lines as suspicious. Such misleading predictions increase developers' manual effort and may lead to incorrect patching strategies, motivating the need to identify untrustworthy predictions automatically. We present UntrustVul, an approach for detecting untrustworthy vulnerability predictions by identifying suspicious lines that are inherently unrelated to vulnerabilities. UntrustVul leverages patterns from historical vulnerable line"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.14852","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2503.14852/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:00:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"uTfqpoSwMyFK3jCkeI7KKS1tNbaH8RmpyC/E/nmZmQRYRmN/JrNnhHEeqJxoYmFH9320sj9SuRVLp/hxejOuBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T06:36:06.801995Z"},"content_sha256":"87ba40158286b0db6cf0259b972594be6ba4512b139b89695e227d193a860fd0","schema_version":"1.0","event_id":"sha256:87ba40158286b0db6cf0259b972594be6ba4512b139b89695e227d193a860fd0"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/3T63JM3YO3GSGMHP74ZZ7F5XFF/bundle.json","state_url":"https://pith.science/pith/3T63JM3YO3GSGMHP74ZZ7F5XFF/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/3T63JM3YO3GSGMHP74ZZ7F5XFF/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T06:36:06Z","links":{"resolver":"https://pith.science/pith/3T63JM3YO3GSGMHP74ZZ7F5XFF","bundle":"https://pith.science/pith/3T63JM3YO3GSGMHP74ZZ7F5XFF/bundle.json","state":"https://pith.science/pith/3T63JM3YO3GSGMHP74ZZ7F5XFF/state.json","well_known_bundle":"https://pith.science/.well-known/pith/3T63JM3YO3GSGMHP74ZZ7F5XFF/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:3T63JM3YO3GSGMHP74ZZ7F5XFF","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e7433a2cee37d5aa641826776f6d4790984ad4c993326019efce195c6f45fce2","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2025-03-19T03:18:45Z","title_canon_sha256":"4d34dc1cdcf58381679f097c4cbff1a007c1bdd9a2074f7c70b77bf2f7e55a78"},"schema_version":"1.0","source":{"id":"2503.14852","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2503.14852","created_at":"2026-05-20T00:00:18Z"},{"alias_kind":"arxiv_version","alias_value":"2503.14852v2","created_at":"2026-05-20T00:00:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.14852","created_at":"2026-05-20T00:00:18Z"},{"alias_kind":"pith_short_12","alias_value":"3T63JM3YO3GS","created_at":"2026-05-20T00:00:18Z"},{"alias_kind":"pith_short_16","alias_value":"3T63JM3YO3GSGMHP","created_at":"2026-05-20T00:00:18Z"},{"alias_kind":"pith_short_8","alias_value":"3T63JM3Y","created_at":"2026-05-20T00:00:18Z"}],"graph_snapshots":[{"event_id":"sha256:87ba40158286b0db6cf0259b972594be6ba4512b139b89695e227d193a860fd0","target":"graph","created_at":"2026-05-20T00:00:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2503.14852/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Machine learning (ML) has shown promise in vulnerability detection, but ML detectors may rely on irrelevant code features, causing them to highlight non-vulnerable lines as suspicious. Such misleading predictions increase developers' manual effort and may lead to incorrect patching strategies, motivating the need to identify untrustworthy predictions automatically. We present UntrustVul, an approach for detecting untrustworthy vulnerability predictions by identifying suspicious lines that are inherently unrelated to vulnerabilities. UntrustVul leverages patterns from historical vulnerable line","authors_text":"Aldeida Aleti, Lam Nguyen Tung, Neelofar Neelofar, Xiaoning Du","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2025-03-19T03:18:45Z","title":"UntrustVul: An Automated Approach for Identifying Untrustworthy Alerts in Vulnerability Detection Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.14852","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:cf4bf8083806c3865dd85ed819fc2e391af4f82b926e364941ea7909798809b1","target":"record","created_at":"2026-05-20T00:00:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e7433a2cee37d5aa641826776f6d4790984ad4c993326019efce195c6f45fce2","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2025-03-19T03:18:45Z","title_canon_sha256":"4d34dc1cdcf58381679f097c4cbff1a007c1bdd9a2074f7c70b77bf2f7e55a78"},"schema_version":"1.0","source":{"id":"2503.14852","kind":"arxiv","version":2}},"canonical_sha256":"dcfdb4b37876cd2330efff339f97b7295083e951e97636d9f59aa5fea1b2c521","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"dcfdb4b37876cd2330efff339f97b7295083e951e97636d9f59aa5fea1b2c521","first_computed_at":"2026-05-20T00:00:18.328413Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:00:18.328413Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"L1HYExsyLnMx7IAga4cYULrS0tTte+gG7RCg/Qug751lFgLpNuCDVOIwLHtubaXfELVArus8a0+71GQ36mQ7Dg==","signature_status":"signed_v1","signed_at":"2026-05-20T00:00:18.329212Z","signed_message":"canonical_sha256_bytes"},"source_id":"2503.14852","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:cf4bf8083806c3865dd85ed819fc2e391af4f82b926e364941ea7909798809b1","sha256:87ba40158286b0db6cf0259b972594be6ba4512b139b89695e227d193a860fd0"],"state_sha256":"6c711aa0807228a15feb47ab177f6babcc3d7ac99458f14a278da33443776c12"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4DMPiFkp5L3U4YL0oPQ4g0W68M1974QC73YFG8KlKmfE/BhkoJZntCOeDp3u9PHRw4Zz2SqKGmzKk4lSu+KxDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T06:36:06.806402Z","bundle_sha256":"b764dbe1d150f11862fe8b111a51599ec1e7069ccf72ff11caefb5f4750b2c89"}}