{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:6S74M5APLJD463X3B4Q54BKKZL","short_pith_number":"pith:6S74M5AP","canonical_record":{"source":{"id":"2607.01919","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-07-02T09:18:09Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"7c319bcb7a34a960716cfa0ed2b66a04cd8be961fbba87bbb605cc0fb7916c08","abstract_canon_sha256":"1b0bae15eb782bc6a0030e823b8e101269b65d22656c6cc2fd401bc492b4a61b"},"schema_version":"1.0"},"canonical_sha256":"f4bfc6740f5a47cf6efb0f21de054acae7a76d6249a2e72be5b9aa00275e78f4","source":{"kind":"arxiv","id":"2607.01919","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2607.01919","created_at":"2026-07-03T01:17:33Z"},{"alias_kind":"arxiv_version","alias_value":"2607.01919v1","created_at":"2026-07-03T01:17:33Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.01919","created_at":"2026-07-03T01:17:33Z"},{"alias_kind":"pith_short_12","alias_value":"6S74M5APLJD4","created_at":"2026-07-03T01:17:33Z"},{"alias_kind":"pith_short_16","alias_value":"6S74M5APLJD463X3","created_at":"2026-07-03T01:17:33Z"},{"alias_kind":"pith_short_8","alias_value":"6S74M5AP","created_at":"2026-07-03T01:17:33Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:6S74M5APLJD463X3B4Q54BKKZL","target":"record","payload":{"canonical_record":{"source":{"id":"2607.01919","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-07-02T09:18:09Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"7c319bcb7a34a960716cfa0ed2b66a04cd8be961fbba87bbb605cc0fb7916c08","abstract_canon_sha256":"1b0bae15eb782bc6a0030e823b8e101269b65d22656c6cc2fd401bc492b4a61b"},"schema_version":"1.0"},"canonical_sha256":"f4bfc6740f5a47cf6efb0f21de054acae7a76d6249a2e72be5b9aa00275e78f4","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-03T01:17:33.454439Z","signature_b64":"d7DQotjkSktcOnClpz/oxo3BvehTiPdkm1upnEfFH2QE+V2Gfo+16PlKRoIf+UBQ5SpiMTxCn/zuN2GWLESGBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f4bfc6740f5a47cf6efb0f21de054acae7a76d6249a2e72be5b9aa00275e78f4","last_reissued_at":"2026-07-03T01:17:33.454013Z","signature_status":"signed_v1","first_computed_at":"2026-07-03T01:17:33.454013Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2607.01919","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-03T01:17:33Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"51SEKrpf+xEZc1pyy/G7pyhPkzqVgifkB9RMzKpXCeO6KvmK1Ke3C+3cknJujJIPmwzPriGL02FcOmgQm5+RAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-03T22:09:48.647088Z"},"content_sha256":"c05526961c87a00184d9545a8eb70cb2f793c453a90f25c55c5ea38605eb0ff2","schema_version":"1.0","event_id":"sha256:c05526961c87a00184d9545a8eb70cb2f793c453a90f25c55c5ea38605eb0ff2"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:6S74M5APLJD463X3B4Q54BKKZL","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"ElephantAgent: Contextual State Continuity in Agentic Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.AI","authors_text":"Deyue Zhang, Dongdong Yang, Jiankai Jin, Quanchen Zou, Wenzhuo Xu, Xiangzheng Zhang, Zhao Liu","submitted_at":"2026-07-02T09:18:09Z","abstract_excerpt":"Agentic systems enhance their capabilities by invoking external tools and maintaining persistent memory. However, these external dependencies introduce novel attack surfaces. Recent tool and memory poisoning attacks show that maliciously crafted tool descriptors and poisoned memory can covertly bias agent behavior. These threats reflect a deeper issue: the lack of verifiable continuity in the agent's contextual state for planning and execution. We present ElephantAgent, a protocol that enforces Contextual State Continuity to defend against contextual state poisoning. Inspired by prior state-co"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.01919","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2607.01919/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-03T01:17:33Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"P6br9StSLIovLRbl5AQu1LNM/iYDUo/vlSZTUljVxqyDIgfl4adGVsn+ESIYfKaRm3kPIYTKdtCUeo0tpfDYBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-03T22:09:48.647482Z"},"content_sha256":"827748b5e480345ae35abfdaaeb3a365b65b8138a08c9e52fa15df52b204512a","schema_version":"1.0","event_id":"sha256:827748b5e480345ae35abfdaaeb3a365b65b8138a08c9e52fa15df52b204512a"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/6S74M5APLJD463X3B4Q54BKKZL/bundle.json","state_url":"https://pith.science/pith/6S74M5APLJD463X3B4Q54BKKZL/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/6S74M5APLJD463X3B4Q54BKKZL/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-03T22:09:48Z","links":{"resolver":"https://pith.science/pith/6S74M5APLJD463X3B4Q54BKKZL","bundle":"https://pith.science/pith/6S74M5APLJD463X3B4Q54BKKZL/bundle.json","state":"https://pith.science/pith/6S74M5APLJD463X3B4Q54BKKZL/state.json","well_known_bundle":"https://pith.science/.well-known/pith/6S74M5APLJD463X3B4Q54BKKZL/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:6S74M5APLJD463X3B4Q54BKKZL","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"1b0bae15eb782bc6a0030e823b8e101269b65d22656c6cc2fd401bc492b4a61b","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-07-02T09:18:09Z","title_canon_sha256":"7c319bcb7a34a960716cfa0ed2b66a04cd8be961fbba87bbb605cc0fb7916c08"},"schema_version":"1.0","source":{"id":"2607.01919","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2607.01919","created_at":"2026-07-03T01:17:33Z"},{"alias_kind":"arxiv_version","alias_value":"2607.01919v1","created_at":"2026-07-03T01:17:33Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.01919","created_at":"2026-07-03T01:17:33Z"},{"alias_kind":"pith_short_12","alias_value":"6S74M5APLJD4","created_at":"2026-07-03T01:17:33Z"},{"alias_kind":"pith_short_16","alias_value":"6S74M5APLJD463X3","created_at":"2026-07-03T01:17:33Z"},{"alias_kind":"pith_short_8","alias_value":"6S74M5AP","created_at":"2026-07-03T01:17:33Z"}],"graph_snapshots":[{"event_id":"sha256:827748b5e480345ae35abfdaaeb3a365b65b8138a08c9e52fa15df52b204512a","target":"graph","created_at":"2026-07-03T01:17:33Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2607.01919/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Agentic systems enhance their capabilities by invoking external tools and maintaining persistent memory. However, these external dependencies introduce novel attack surfaces. Recent tool and memory poisoning attacks show that maliciously crafted tool descriptors and poisoned memory can covertly bias agent behavior. These threats reflect a deeper issue: the lack of verifiable continuity in the agent's contextual state for planning and execution. We present ElephantAgent, a protocol that enforces Contextual State Continuity to defend against contextual state poisoning. Inspired by prior state-co","authors_text":"Deyue Zhang, Dongdong Yang, Jiankai Jin, Quanchen Zou, Wenzhuo Xu, Xiangzheng Zhang, Zhao Liu","cross_cats":["cs.CR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-07-02T09:18:09Z","title":"ElephantAgent: Contextual State Continuity in Agentic Systems"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.01919","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:c05526961c87a00184d9545a8eb70cb2f793c453a90f25c55c5ea38605eb0ff2","target":"record","created_at":"2026-07-03T01:17:33Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"1b0bae15eb782bc6a0030e823b8e101269b65d22656c6cc2fd401bc492b4a61b","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-07-02T09:18:09Z","title_canon_sha256":"7c319bcb7a34a960716cfa0ed2b66a04cd8be961fbba87bbb605cc0fb7916c08"},"schema_version":"1.0","source":{"id":"2607.01919","kind":"arxiv","version":1}},"canonical_sha256":"f4bfc6740f5a47cf6efb0f21de054acae7a76d6249a2e72be5b9aa00275e78f4","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"f4bfc6740f5a47cf6efb0f21de054acae7a76d6249a2e72be5b9aa00275e78f4","first_computed_at":"2026-07-03T01:17:33.454013Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-03T01:17:33.454013Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"d7DQotjkSktcOnClpz/oxo3BvehTiPdkm1upnEfFH2QE+V2Gfo+16PlKRoIf+UBQ5SpiMTxCn/zuN2GWLESGBw==","signature_status":"signed_v1","signed_at":"2026-07-03T01:17:33.454439Z","signed_message":"canonical_sha256_bytes"},"source_id":"2607.01919","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:c05526961c87a00184d9545a8eb70cb2f793c453a90f25c55c5ea38605eb0ff2","sha256:827748b5e480345ae35abfdaaeb3a365b65b8138a08c9e52fa15df52b204512a"],"state_sha256":"b7648eef90ba7f181eb6f7004ee15e2d03216931018e7ef051358525f69edbc0"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hAOXQs5V7jLoWwKml8hDhMtxDZZhYU0ZxzufiLcZbfFUzLDcdxwB7C1Xy0P2L/IvV99HGiURH3ub79yguYMGBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-03T22:09:48.649460Z","bundle_sha256":"89e399789994dbec649b3e0200d0b31a390eda0ce08aff46cedf0294ffd54b8e"}}