{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:6LDOO2ZIVWYQ7JGHFHKQFVXXK6","short_pith_number":"pith:6LDOO2ZI","canonical_record":{"source":{"id":"2606.00152","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-29T04:55:12Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"71438be7f49c68030952b1ad90961fae713b0a9b5517e76f9e7f85e845a485d5","abstract_canon_sha256":"0316710c0bd0fc4d9c7ec9b7d8ca9821d7a86ea1f762fbc4d4c34137bd953c3c"},"schema_version":"1.0"},"canonical_sha256":"f2c6e76b28adb10fa4c729d502d6f757bd1ab041260ecaa3c448277b3b357cf0","source":{"kind":"arxiv","id":"2606.00152","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.00152","created_at":"2026-06-02T01:03:19Z"},{"alias_kind":"arxiv_version","alias_value":"2606.00152v1","created_at":"2026-06-02T01:03:19Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.00152","created_at":"2026-06-02T01:03:19Z"},{"alias_kind":"pith_short_12","alias_value":"6LDOO2ZIVWYQ","created_at":"2026-06-02T01:03:19Z"},{"alias_kind":"pith_short_16","alias_value":"6LDOO2ZIVWYQ7JGH","created_at":"2026-06-02T01:03:19Z"},{"alias_kind":"pith_short_8","alias_value":"6LDOO2ZI","created_at":"2026-06-02T01:03:19Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:6LDOO2ZIVWYQ7JGHFHKQFVXXK6","target":"record","payload":{"canonical_record":{"source":{"id":"2606.00152","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-29T04:55:12Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"71438be7f49c68030952b1ad90961fae713b0a9b5517e76f9e7f85e845a485d5","abstract_canon_sha256":"0316710c0bd0fc4d9c7ec9b7d8ca9821d7a86ea1f762fbc4d4c34137bd953c3c"},"schema_version":"1.0"},"canonical_sha256":"f2c6e76b28adb10fa4c729d502d6f757bd1ab041260ecaa3c448277b3b357cf0","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-02T01:03:19.932396Z","signature_b64":"5NqJYzJH3uYSQM3+7P2xy+vUPCXf2jbhbxh1RUaBX0NzoJk6oTrdbS3/37RfTHOnGNLjCemA0fym55q4nVt3AA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f2c6e76b28adb10fa4c729d502d6f757bd1ab041260ecaa3c448277b3b357cf0","last_reissued_at":"2026-06-02T01:03:19.931999Z","signature_status":"signed_v1","first_computed_at":"2026-06-02T01:03:19.931999Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.00152","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T01:03:19Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"44VrIvKOl4uQG/B+Cbm0lVDozPi8zHQluriIaEAQ9qtFH1MPj002DIn1bsgX2YJ05UQaPIsiJUuDL0ESqsRVCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-08T04:40:32.319136Z"},"content_sha256":"02549acdf3ffc47a1d6b07ec13f706ba500919aef381825f1116119f1a469fbe","schema_version":"1.0","event_id":"sha256:02549acdf3ffc47a1d6b07ec13f706ba500919aef381825f1116119f1a469fbe"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:6LDOO2ZIVWYQ7JGHFHKQFVXXK6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"PrivacyPeek: Auditing What LLM-Based Agents Acquire, Not Just What They Say","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Dadi Guo, Dongrui Liu, Guanchu Wang, Jiahui Han, Mingxuan Zhang, Na Zou, Songze Li, Xia Hu","submitted_at":"2026-05-29T04:55:12Z","abstract_excerpt":"LLM-based agents are rapidly advancing, autonomously invoking external tools to complete multi-step tasks for users. However, agents often acquire more sensitive information than the task requires. Existing privacy benchmarks audit what the agent's response or outgoing actions disclose, but overlook the acquisition stage where data first enters the agent's context. The over-acquired information is then one careless action or one attack away from an outright leak. To assess its prevalence, we introduce \\emph{PrivacyPeek}, a benchmark for evaluating acquisition-stage privacy leakage of LLM-based"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.00152","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.00152/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T01:03:19Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wQGz2k8wertFergF8Y734kxcmJ/qzK8V8bzz6EMMEXzg/LrgFWtH1caV5xoo58Q9CdhCz+hwbhe0j/Sn+oPODQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-08T04:40:32.319939Z"},"content_sha256":"1d31aaff7963905e3531250c05bf739deb40a0842e158affde52774d52523055","schema_version":"1.0","event_id":"sha256:1d31aaff7963905e3531250c05bf739deb40a0842e158affde52774d52523055"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/6LDOO2ZIVWYQ7JGHFHKQFVXXK6/bundle.json","state_url":"https://pith.science/pith/6LDOO2ZIVWYQ7JGHFHKQFVXXK6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/6LDOO2ZIVWYQ7JGHFHKQFVXXK6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-08T04:40:32Z","links":{"resolver":"https://pith.science/pith/6LDOO2ZIVWYQ7JGHFHKQFVXXK6","bundle":"https://pith.science/pith/6LDOO2ZIVWYQ7JGHFHKQFVXXK6/bundle.json","state":"https://pith.science/pith/6LDOO2ZIVWYQ7JGHFHKQFVXXK6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/6LDOO2ZIVWYQ7JGHFHKQFVXXK6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:6LDOO2ZIVWYQ7JGHFHKQFVXXK6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0316710c0bd0fc4d9c7ec9b7d8ca9821d7a86ea1f762fbc4d4c34137bd953c3c","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-29T04:55:12Z","title_canon_sha256":"71438be7f49c68030952b1ad90961fae713b0a9b5517e76f9e7f85e845a485d5"},"schema_version":"1.0","source":{"id":"2606.00152","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.00152","created_at":"2026-06-02T01:03:19Z"},{"alias_kind":"arxiv_version","alias_value":"2606.00152v1","created_at":"2026-06-02T01:03:19Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.00152","created_at":"2026-06-02T01:03:19Z"},{"alias_kind":"pith_short_12","alias_value":"6LDOO2ZIVWYQ","created_at":"2026-06-02T01:03:19Z"},{"alias_kind":"pith_short_16","alias_value":"6LDOO2ZIVWYQ7JGH","created_at":"2026-06-02T01:03:19Z"},{"alias_kind":"pith_short_8","alias_value":"6LDOO2ZI","created_at":"2026-06-02T01:03:19Z"}],"graph_snapshots":[{"event_id":"sha256:1d31aaff7963905e3531250c05bf739deb40a0842e158affde52774d52523055","target":"graph","created_at":"2026-06-02T01:03:19Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.00152/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"LLM-based agents are rapidly advancing, autonomously invoking external tools to complete multi-step tasks for users. However, agents often acquire more sensitive information than the task requires. Existing privacy benchmarks audit what the agent's response or outgoing actions disclose, but overlook the acquisition stage where data first enters the agent's context. The over-acquired information is then one careless action or one attack away from an outright leak. To assess its prevalence, we introduce \\emph{PrivacyPeek}, a benchmark for evaluating acquisition-stage privacy leakage of LLM-based","authors_text":"Dadi Guo, Dongrui Liu, Guanchu Wang, Jiahui Han, Mingxuan Zhang, Na Zou, Songze Li, Xia Hu","cross_cats":["cs.AI"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-29T04:55:12Z","title":"PrivacyPeek: Auditing What LLM-Based Agents Acquire, Not Just What They Say"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.00152","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:02549acdf3ffc47a1d6b07ec13f706ba500919aef381825f1116119f1a469fbe","target":"record","created_at":"2026-06-02T01:03:19Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0316710c0bd0fc4d9c7ec9b7d8ca9821d7a86ea1f762fbc4d4c34137bd953c3c","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-29T04:55:12Z","title_canon_sha256":"71438be7f49c68030952b1ad90961fae713b0a9b5517e76f9e7f85e845a485d5"},"schema_version":"1.0","source":{"id":"2606.00152","kind":"arxiv","version":1}},"canonical_sha256":"f2c6e76b28adb10fa4c729d502d6f757bd1ab041260ecaa3c448277b3b357cf0","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"f2c6e76b28adb10fa4c729d502d6f757bd1ab041260ecaa3c448277b3b357cf0","first_computed_at":"2026-06-02T01:03:19.931999Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-02T01:03:19.931999Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"5NqJYzJH3uYSQM3+7P2xy+vUPCXf2jbhbxh1RUaBX0NzoJk6oTrdbS3/37RfTHOnGNLjCemA0fym55q4nVt3AA==","signature_status":"signed_v1","signed_at":"2026-06-02T01:03:19.932396Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.00152","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:02549acdf3ffc47a1d6b07ec13f706ba500919aef381825f1116119f1a469fbe","sha256:1d31aaff7963905e3531250c05bf739deb40a0842e158affde52774d52523055"],"state_sha256":"d995ac2b45ff7378dbf1cbdcb4946ae0f9431ca11fb97d14d236a15037db0fcb"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jGV0PDds92jT1cX0wjwtDxtM8DWxAqqAMkvm8v3pluyliOGKaaZ2HCYjU0+pKEbSw/W0LuLh+ky18A8hiircCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-08T04:40:32.323953Z","bundle_sha256":"fdee80d59853ae2ef8438fe3c344e2b12607fb44a4b5ecc468cffa952d210a8d"}}