{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:6RJI3MYZLKBEOSSORYP332YC3N","short_pith_number":"pith:6RJI3MYZ","schema_version":"1.0","canonical_sha256":"f4528db3195a82474a4e8e1fbdeb02db490e13ab85ef18d177e8dda563f539bc","source":{"kind":"arxiv","id":"2502.12497","version":1},"attestation_state":"computed","paper":{"title":"SoK: Understanding Vulnerabilities in the Large Language Model Supply Chain","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Haoyu Wang, Quanchen Zou, Shenao Wang, Yanjie Zhao, Zhao Liu","submitted_at":"2025-02-18T03:22:38Z","abstract_excerpt":"Large Language Models (LLMs) transform artificial intelligence, driving advancements in natural language understanding, text generation, and autonomous systems. The increasing complexity of their development and deployment introduces significant security challenges, particularly within the LLM supply chain. However, existing research primarily focuses on content safety, such as adversarial attacks, jailbreaking, and backdoor attacks, while overlooking security vulnerabilities in the underlying software systems. To address this gap, this study systematically analyzes 529 vulnerabilities reporte"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2502.12497","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-02-18T03:22:38Z","cross_cats_sorted":[],"title_canon_sha256":"c743e63fe2f857d51f790bb1d5f2c60533a4cfe2d5e6b6a4c21954692fd00c01","abstract_canon_sha256":"95073e683519720e7dd06b6ef5989f8b17daff1865c162bc2971b636146f413b"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:15:56.528531Z","signature_b64":"7JtNJIUgp7jGaiaxIOmKLm19UKcblYF7q/sYO8Vs0gnp39n7XxB9E04+lNUSumHUkgh6SZdorbX17rb7z5wxDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f4528db3195a82474a4e8e1fbdeb02db490e13ab85ef18d177e8dda563f539bc","last_reissued_at":"2026-07-05T10:15:56.528031Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:15:56.528031Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"SoK: Understanding Vulnerabilities in the Large Language Model Supply Chain","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Haoyu Wang, Quanchen Zou, Shenao Wang, Yanjie Zhao, Zhao Liu","submitted_at":"2025-02-18T03:22:38Z","abstract_excerpt":"Large Language Models (LLMs) transform artificial intelligence, driving advancements in natural language understanding, text generation, and autonomous systems. The increasing complexity of their development and deployment introduces significant security challenges, particularly within the LLM supply chain. However, existing research primarily focuses on content safety, such as adversarial attacks, jailbreaking, and backdoor attacks, while overlooking security vulnerabilities in the underlying software systems. To address this gap, this study systematically analyzes 529 vulnerabilities reporte"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2502.12497","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2502.12497/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2502.12497","created_at":"2026-07-05T10:15:56.528099+00:00"},{"alias_kind":"arxiv_version","alias_value":"2502.12497v1","created_at":"2026-07-05T10:15:56.528099+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2502.12497","created_at":"2026-07-05T10:15:56.528099+00:00"},{"alias_kind":"pith_short_12","alias_value":"6RJI3MYZLKBE","created_at":"2026-07-05T10:15:56.528099+00:00"},{"alias_kind":"pith_short_16","alias_value":"6RJI3MYZLKBEOSSO","created_at":"2026-07-05T10:15:56.528099+00:00"},{"alias_kind":"pith_short_8","alias_value":"6RJI3MYZ","created_at":"2026-07-05T10:15:56.528099+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":3,"sample":[{"citing_arxiv_id":"2607.01640","citing_title":"AgentFlow: Building Agent Dependency Graphs for Static Analysis of Agent Programs","ref_index":57,"is_internal_anchor":true},{"citing_arxiv_id":"2605.28893","citing_title":"Towards Demystifying and Repairing LLM-in-the-Loop Vulnerabilities","ref_index":52,"is_internal_anchor":true},{"citing_arxiv_id":"2604.16543","citing_title":"Conjunctive Prompt Attacks in Multi-Agent LLM Systems","ref_index":40,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/6RJI3MYZLKBEOSSORYP332YC3N","json":"https://pith.science/pith/6RJI3MYZLKBEOSSORYP332YC3N.json","graph_json":"https://pith.science/api/pith-number/6RJI3MYZLKBEOSSORYP332YC3N/graph.json","events_json":"https://pith.science/api/pith-number/6RJI3MYZLKBEOSSORYP332YC3N/events.json","paper":"https://pith.science/paper/6RJI3MYZ"},"agent_actions":{"view_html":"https://pith.science/pith/6RJI3MYZLKBEOSSORYP332YC3N","download_json":"https://pith.science/pith/6RJI3MYZLKBEOSSORYP332YC3N.json","view_paper":"https://pith.science/paper/6RJI3MYZ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2502.12497&json=true","fetch_graph":"https://pith.science/api/pith-number/6RJI3MYZLKBEOSSORYP332YC3N/graph.json","fetch_events":"https://pith.science/api/pith-number/6RJI3MYZLKBEOSSORYP332YC3N/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/6RJI3MYZLKBEOSSORYP332YC3N/action/timestamp_anchor","attest_storage":"https://pith.science/pith/6RJI3MYZLKBEOSSORYP332YC3N/action/storage_attestation","attest_author":"https://pith.science/pith/6RJI3MYZLKBEOSSORYP332YC3N/action/author_attestation","sign_citation":"https://pith.science/pith/6RJI3MYZLKBEOSSORYP332YC3N/action/citation_signature","submit_replication":"https://pith.science/pith/6RJI3MYZLKBEOSSORYP332YC3N/action/replication_record"}},"created_at":"2026-07-05T10:15:56.528099+00:00","updated_at":"2026-07-05T10:15:56.528099+00:00"}