{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:6WASEI7OIMLYLTWASMSYWGTGYO","short_pith_number":"pith:6WASEI7O","canonical_record":{"source":{"id":"2601.09923","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-01-14T23:06:35Z","cross_cats_sorted":[],"title_canon_sha256":"3b1d67ec6b033dc03eed31f9b3e2656818c871daae9c8cd300429e292e8332b9","abstract_canon_sha256":"bca4b374127b2be21869fbd8c0b41506615172e84489ca657eaffb87164c82e1"},"schema_version":"1.0"},"canonical_sha256":"f5812223ee431785cec093258b1a66c3a8a062aeb53c2b3f38add6bc3e56f7c2","source":{"kind":"arxiv","id":"2601.09923","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2601.09923","created_at":"2026-06-05T01:15:18Z"},{"alias_kind":"arxiv_version","alias_value":"2601.09923v3","created_at":"2026-06-05T01:15:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2601.09923","created_at":"2026-06-05T01:15:18Z"},{"alias_kind":"pith_short_12","alias_value":"6WASEI7OIMLY","created_at":"2026-06-05T01:15:18Z"},{"alias_kind":"pith_short_16","alias_value":"6WASEI7OIMLYLTWA","created_at":"2026-06-05T01:15:18Z"},{"alias_kind":"pith_short_8","alias_value":"6WASEI7O","created_at":"2026-06-05T01:15:18Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:6WASEI7OIMLYLTWASMSYWGTGYO","target":"record","payload":{"canonical_record":{"source":{"id":"2601.09923","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-01-14T23:06:35Z","cross_cats_sorted":[],"title_canon_sha256":"3b1d67ec6b033dc03eed31f9b3e2656818c871daae9c8cd300429e292e8332b9","abstract_canon_sha256":"bca4b374127b2be21869fbd8c0b41506615172e84489ca657eaffb87164c82e1"},"schema_version":"1.0"},"canonical_sha256":"f5812223ee431785cec093258b1a66c3a8a062aeb53c2b3f38add6bc3e56f7c2","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-05T01:15:18.964720Z","signature_b64":"x9PaGYZTZtmjTEhQUi9bgq7zegyb8xOo60clug7aftAWYV9FZelU28ov1wIyWLxQO359NKJOCrPgIft+bOPlDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f5812223ee431785cec093258b1a66c3a8a062aeb53c2b3f38add6bc3e56f7c2","last_reissued_at":"2026-06-05T01:15:18.964133Z","signature_status":"signed_v1","first_computed_at":"2026-06-05T01:15:18.964133Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2601.09923","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-05T01:15:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"cVYh78Pt0HQHB0siGCcrO4fUf8gUVZ7fKpn16ydrnqBz6x98nc/OpZ5Y31W3vQg89gKfvidparaWpmWZJew3Cw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T23:05:30.601848Z"},"content_sha256":"e365bf91ee6f619c0018bffab5fa24c46ae2356e10124872ceccadef9d84ea7a","schema_version":"1.0","event_id":"sha256:e365bf91ee6f619c0018bffab5fa24c46ae2356e10124872ceccadef9d84ea7a"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:6WASEI7OIMLYLTWASMSYWGTGYO","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.AI","authors_text":"Cheng Zhang, Florian Tram\\`er, Hanna Foerster, Ilia Shumailov, Kristina Nikoli\\'c, Nicolas Papernot, Robert Mullins, Tom Blanchard, Yiren Zhao","submitted_at":"2026-01-14T23:06:35Z","abstract_excerpt":"AI agents are vulnerable to prompt injection attacks, where malicious content hijacks agent behavior. Among proposed defenses, architectural isolation provides the strongest guarantees by strictly separating trusted task planning from untrusted environment observations. However, applying this design to Computer Use Agents (CUAs), which automate tasks by viewing screens and executing actions, presents a fundamental challenge. Current agents require continuous observation of UI state to determine each action, which conflicts with the isolation required for security. We resolve this tension by de"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2601.09923","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2601.09923/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-05T01:15:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"OqBeBQLloYQDyz0JNFcfhJHmpihCPnkXbyISxRgC9LIE3S8qSuWmbpm4KJ6hglj0uSzd/wbUdxG0oz06zXtaCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-06T23:05:30.602508Z"},"content_sha256":"20e87979cf43c87c0cab44534ead684b9f3935494cfdd2fdbf5674b5a125d249","schema_version":"1.0","event_id":"sha256:20e87979cf43c87c0cab44534ead684b9f3935494cfdd2fdbf5674b5a125d249"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/6WASEI7OIMLYLTWASMSYWGTGYO/bundle.json","state_url":"https://pith.science/pith/6WASEI7OIMLYLTWASMSYWGTGYO/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/6WASEI7OIMLYLTWASMSYWGTGYO/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-06T23:05:30Z","links":{"resolver":"https://pith.science/pith/6WASEI7OIMLYLTWASMSYWGTGYO","bundle":"https://pith.science/pith/6WASEI7OIMLYLTWASMSYWGTGYO/bundle.json","state":"https://pith.science/pith/6WASEI7OIMLYLTWASMSYWGTGYO/state.json","well_known_bundle":"https://pith.science/.well-known/pith/6WASEI7OIMLYLTWASMSYWGTGYO/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:6WASEI7OIMLYLTWASMSYWGTGYO","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"bca4b374127b2be21869fbd8c0b41506615172e84489ca657eaffb87164c82e1","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-01-14T23:06:35Z","title_canon_sha256":"3b1d67ec6b033dc03eed31f9b3e2656818c871daae9c8cd300429e292e8332b9"},"schema_version":"1.0","source":{"id":"2601.09923","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2601.09923","created_at":"2026-06-05T01:15:18Z"},{"alias_kind":"arxiv_version","alias_value":"2601.09923v3","created_at":"2026-06-05T01:15:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2601.09923","created_at":"2026-06-05T01:15:18Z"},{"alias_kind":"pith_short_12","alias_value":"6WASEI7OIMLY","created_at":"2026-06-05T01:15:18Z"},{"alias_kind":"pith_short_16","alias_value":"6WASEI7OIMLYLTWA","created_at":"2026-06-05T01:15:18Z"},{"alias_kind":"pith_short_8","alias_value":"6WASEI7O","created_at":"2026-06-05T01:15:18Z"}],"graph_snapshots":[{"event_id":"sha256:20e87979cf43c87c0cab44534ead684b9f3935494cfdd2fdbf5674b5a125d249","target":"graph","created_at":"2026-06-05T01:15:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2601.09923/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"AI agents are vulnerable to prompt injection attacks, where malicious content hijacks agent behavior. Among proposed defenses, architectural isolation provides the strongest guarantees by strictly separating trusted task planning from untrusted environment observations. However, applying this design to Computer Use Agents (CUAs), which automate tasks by viewing screens and executing actions, presents a fundamental challenge. Current agents require continuous observation of UI state to determine each action, which conflicts with the isolation required for security. We resolve this tension by de","authors_text":"Cheng Zhang, Florian Tram\\`er, Hanna Foerster, Ilia Shumailov, Kristina Nikoli\\'c, Nicolas Papernot, Robert Mullins, Tom Blanchard, Yiren Zhao","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-01-14T23:06:35Z","title":"CaMeLs Can Use Computers Too: System-level Security for Computer Use Agents"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2601.09923","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e365bf91ee6f619c0018bffab5fa24c46ae2356e10124872ceccadef9d84ea7a","target":"record","created_at":"2026-06-05T01:15:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"bca4b374127b2be21869fbd8c0b41506615172e84489ca657eaffb87164c82e1","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-01-14T23:06:35Z","title_canon_sha256":"3b1d67ec6b033dc03eed31f9b3e2656818c871daae9c8cd300429e292e8332b9"},"schema_version":"1.0","source":{"id":"2601.09923","kind":"arxiv","version":3}},"canonical_sha256":"f5812223ee431785cec093258b1a66c3a8a062aeb53c2b3f38add6bc3e56f7c2","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"f5812223ee431785cec093258b1a66c3a8a062aeb53c2b3f38add6bc3e56f7c2","first_computed_at":"2026-06-05T01:15:18.964133Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-05T01:15:18.964133Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"x9PaGYZTZtmjTEhQUi9bgq7zegyb8xOo60clug7aftAWYV9FZelU28ov1wIyWLxQO359NKJOCrPgIft+bOPlDw==","signature_status":"signed_v1","signed_at":"2026-06-05T01:15:18.964720Z","signed_message":"canonical_sha256_bytes"},"source_id":"2601.09923","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e365bf91ee6f619c0018bffab5fa24c46ae2356e10124872ceccadef9d84ea7a","sha256:20e87979cf43c87c0cab44534ead684b9f3935494cfdd2fdbf5674b5a125d249"],"state_sha256":"c4f6c6958b4b76e64bc7c84699facd50b31e0dae182abd11d94feb0a9576d00c"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ETaoYYXILj2kriIckGtzhDs0trtIZ9Wb7oRSLQySEcp0lI63I/A1vU3fwir0VZ8jrvQgXQSjfnnO6zoWBeSwCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-06T23:05:30.606028Z","bundle_sha256":"37e171d18bf2ae5131d5363da869a67aaefdbbf5e3e81af85504ab657952ed7b"}}