{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:4TUASMXH32LPCAFKLSFCILCP23","short_pith_number":"pith:4TUASMXH","canonical_record":{"source":{"id":"2504.04809","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-04-07T08:04:23Z","cross_cats_sorted":[],"title_canon_sha256":"c3ecc08dc11ad29734feaf9935a03608ad6c7bfc44aea8db8031af389325ea43","abstract_canon_sha256":"723e7ddf1afd32cf19a3b52d4f6e21396ecc7477c290a92015765ed9c0267eb8"},"schema_version":"1.0"},"canonical_sha256":"e4e80932e7de96f100aa5c8a242c4fd6c760ea80825fc3ad309fc8dbae50382e","source":{"kind":"arxiv","id":"2504.04809","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2504.04809","created_at":"2026-06-03T01:05:43Z"},{"alias_kind":"arxiv_version","alias_value":"2504.04809v2","created_at":"2026-06-03T01:05:43Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2504.04809","created_at":"2026-06-03T01:05:43Z"},{"alias_kind":"pith_short_12","alias_value":"4TUASMXH32LP","created_at":"2026-06-03T01:05:43Z"},{"alias_kind":"pith_short_16","alias_value":"4TUASMXH32LPCAFK","created_at":"2026-06-03T01:05:43Z"},{"alias_kind":"pith_short_8","alias_value":"4TUASMXH","created_at":"2026-06-03T01:05:43Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:4TUASMXH32LPCAFKLSFCILCP23","target":"record","payload":{"canonical_record":{"source":{"id":"2504.04809","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-04-07T08:04:23Z","cross_cats_sorted":[],"title_canon_sha256":"c3ecc08dc11ad29734feaf9935a03608ad6c7bfc44aea8db8031af389325ea43","abstract_canon_sha256":"723e7ddf1afd32cf19a3b52d4f6e21396ecc7477c290a92015765ed9c0267eb8"},"schema_version":"1.0"},"canonical_sha256":"e4e80932e7de96f100aa5c8a242c4fd6c760ea80825fc3ad309fc8dbae50382e","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-03T01:05:43.753182Z","signature_b64":"Y+gnx+7SPLxZAqq5aJQ0bNJCcXRKO4AgAs9v45XIAwCSPssYFwzs2l8isoG+pmJhNuYxxV5tbXawikjjJejfDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e4e80932e7de96f100aa5c8a242c4fd6c760ea80825fc3ad309fc8dbae50382e","last_reissued_at":"2026-06-03T01:05:43.752757Z","signature_status":"signed_v1","first_computed_at":"2026-06-03T01:05:43.752757Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2504.04809","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:43Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"j4/jUSEAHzdRozrAXc5WK1jjx2p/lyqusaLdy3YzipXGegNl+LuPJfRN73fB1apsVQWNX3inGBJUgwuyh5r0Ag==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T11:41:50.648743Z"},"content_sha256":"cb0fd6e56f5ecd0459c5faf33da17da613744b5a6b189806cab9572492c41039","schema_version":"1.0","event_id":"sha256:cb0fd6e56f5ecd0459c5faf33da17da613744b5a6b189806cab9572492c41039"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:4TUASMXH32LPCAFKLSFCILCP23","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"SEEM: Exploiting Black-Box Text Attacks to Manipulate Tool Selection","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Hao Gao, Jinghao Zhang, Liang Wang, Liuji Chen, Qiang Liu, Shu Wu","submitted_at":"2025-04-07T08:04:23Z","abstract_excerpt":"Tool learning has emerged as a powerful auxiliary mechanism that extends the capabilities of large language models (LLMs), enabling them to address complex tasks that demand real-time relevance or high-precision operations. However, beneath this strength lie significant security risks. Prior studies have primarily concentrated on corrupting the outputs of invoked tools, while largely overlooking the vulnerability of the tool selection process itself. To bridge this gap, we introduce a black-box, text-based attack that substantially increases the likelihood of a target tool being selected. We p"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2504.04809","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2504.04809/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:43Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"1QGSfHuhY1MT7rYc2sNxwtZ/EGr6ctP6dGMd4gCRPkkdoafbXZAiAwEKjT+w4oUkPZfojFn4NQ9ZjHGK//+oBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T11:41:50.649552Z"},"content_sha256":"871ed290a1d8eda070109463f7cade11357cb0c8c9c1c1d328c86c23e1ea9d64","schema_version":"1.0","event_id":"sha256:871ed290a1d8eda070109463f7cade11357cb0c8c9c1c1d328c86c23e1ea9d64"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/4TUASMXH32LPCAFKLSFCILCP23/bundle.json","state_url":"https://pith.science/pith/4TUASMXH32LPCAFKLSFCILCP23/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/4TUASMXH32LPCAFKLSFCILCP23/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-10T11:41:50Z","links":{"resolver":"https://pith.science/pith/4TUASMXH32LPCAFKLSFCILCP23","bundle":"https://pith.science/pith/4TUASMXH32LPCAFKLSFCILCP23/bundle.json","state":"https://pith.science/pith/4TUASMXH32LPCAFKLSFCILCP23/state.json","well_known_bundle":"https://pith.science/.well-known/pith/4TUASMXH32LPCAFKLSFCILCP23/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:4TUASMXH32LPCAFKLSFCILCP23","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"723e7ddf1afd32cf19a3b52d4f6e21396ecc7477c290a92015765ed9c0267eb8","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-04-07T08:04:23Z","title_canon_sha256":"c3ecc08dc11ad29734feaf9935a03608ad6c7bfc44aea8db8031af389325ea43"},"schema_version":"1.0","source":{"id":"2504.04809","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2504.04809","created_at":"2026-06-03T01:05:43Z"},{"alias_kind":"arxiv_version","alias_value":"2504.04809v2","created_at":"2026-06-03T01:05:43Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2504.04809","created_at":"2026-06-03T01:05:43Z"},{"alias_kind":"pith_short_12","alias_value":"4TUASMXH32LP","created_at":"2026-06-03T01:05:43Z"},{"alias_kind":"pith_short_16","alias_value":"4TUASMXH32LPCAFK","created_at":"2026-06-03T01:05:43Z"},{"alias_kind":"pith_short_8","alias_value":"4TUASMXH","created_at":"2026-06-03T01:05:43Z"}],"graph_snapshots":[{"event_id":"sha256:871ed290a1d8eda070109463f7cade11357cb0c8c9c1c1d328c86c23e1ea9d64","target":"graph","created_at":"2026-06-03T01:05:43Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2504.04809/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Tool learning has emerged as a powerful auxiliary mechanism that extends the capabilities of large language models (LLMs), enabling them to address complex tasks that demand real-time relevance or high-precision operations. However, beneath this strength lie significant security risks. Prior studies have primarily concentrated on corrupting the outputs of invoked tools, while largely overlooking the vulnerability of the tool selection process itself. To bridge this gap, we introduce a black-box, text-based attack that substantially increases the likelihood of a target tool being selected. We p","authors_text":"Hao Gao, Jinghao Zhang, Liang Wang, Liuji Chen, Qiang Liu, Shu Wu","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-04-07T08:04:23Z","title":"SEEM: Exploiting Black-Box Text Attacks to Manipulate Tool Selection"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2504.04809","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:cb0fd6e56f5ecd0459c5faf33da17da613744b5a6b189806cab9572492c41039","target":"record","created_at":"2026-06-03T01:05:43Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"723e7ddf1afd32cf19a3b52d4f6e21396ecc7477c290a92015765ed9c0267eb8","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-04-07T08:04:23Z","title_canon_sha256":"c3ecc08dc11ad29734feaf9935a03608ad6c7bfc44aea8db8031af389325ea43"},"schema_version":"1.0","source":{"id":"2504.04809","kind":"arxiv","version":2}},"canonical_sha256":"e4e80932e7de96f100aa5c8a242c4fd6c760ea80825fc3ad309fc8dbae50382e","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"e4e80932e7de96f100aa5c8a242c4fd6c760ea80825fc3ad309fc8dbae50382e","first_computed_at":"2026-06-03T01:05:43.752757Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-03T01:05:43.752757Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Y+gnx+7SPLxZAqq5aJQ0bNJCcXRKO4AgAs9v45XIAwCSPssYFwzs2l8isoG+pmJhNuYxxV5tbXawikjjJejfDQ==","signature_status":"signed_v1","signed_at":"2026-06-03T01:05:43.753182Z","signed_message":"canonical_sha256_bytes"},"source_id":"2504.04809","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:cb0fd6e56f5ecd0459c5faf33da17da613744b5a6b189806cab9572492c41039","sha256:871ed290a1d8eda070109463f7cade11357cb0c8c9c1c1d328c86c23e1ea9d64"],"state_sha256":"d31d3d5659449df71cc4e71c6a12de10a86062feab74fc66a3761c6c55847234"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"WJTlhkTFDzuRmXnL2EA0MPxiLLRyUl4xQVB9qNSFQdRWep3A5paxCr9SC5gQ0eSbsiVQwAYqj4P6rHqHEWqRAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-10T11:41:50.654444Z","bundle_sha256":"18c1fa74b272dbe4f60005d8d982dd1a1fa2d0666bea21d5b7082b911cf24a45"}}