{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:6ZT25RRWPI7S3F2A643ZOJY6SF","short_pith_number":"pith:6ZT25RRW","schema_version":"1.0","canonical_sha256":"f667aec6367a3f2d9740f73797271e916f9816d166b850a974796e3be29840f1","source":{"kind":"arxiv","id":"2605.27631","version":1},"attestation_state":"computed","paper":{"title":"Poison with Style: A Practical Poisoning Attack on Code Large Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Issa Khalil, Khang Tran, Md Rizwan Parvez, NHatHai Phan, Ting Yu, Yazan Boshmaf","submitted_at":"2026-05-26T19:51:57Z","abstract_excerpt":"Code Large Language Models (CLLMs) serve as the core of modern code agents, enabling developers to automate complex software development tasks. In this paper, we present Poison-with-Style (PwS), a practical and stealthy model poisoning attack targeting CLLMs. Unlike prior attacks that assume an active adversary capable of directly embedding explicit triggers (e.g., specific words) into developers' prompts during inference, PwS leverages developers' code styles as covert triggers implicitly embedded within their prompts. PwS introduces a novel data collection method and a two-step training stra"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2605.27631","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-26T19:51:57Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"b30d4a2232b442601643c8fe6a2c6a0ca3b3c9b5f4c0242fd458a4e22a10f7c3","abstract_canon_sha256":"69c3204b9209e3cf1349b78976be21834c1dec39f4c72187d9acedeb50858209"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-28T01:04:44.800683Z","signature_b64":"SFDixT58zSV8VoG67KicZXTCKdXGc3CHeu5JE70IPR/hxh/x2voySbQMaQeLMIe8Mf/TYvdnLg09MRx7txMoAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f667aec6367a3f2d9740f73797271e916f9816d166b850a974796e3be29840f1","last_reissued_at":"2026-05-28T01:04:44.800214Z","signature_status":"signed_v1","first_computed_at":"2026-05-28T01:04:44.800214Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Poison with Style: A Practical Poisoning Attack on Code Large Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Issa Khalil, Khang Tran, Md Rizwan Parvez, NHatHai Phan, Ting Yu, Yazan Boshmaf","submitted_at":"2026-05-26T19:51:57Z","abstract_excerpt":"Code Large Language Models (CLLMs) serve as the core of modern code agents, enabling developers to automate complex software development tasks. In this paper, we present Poison-with-Style (PwS), a practical and stealthy model poisoning attack targeting CLLMs. Unlike prior attacks that assume an active adversary capable of directly embedding explicit triggers (e.g., specific words) into developers' prompts during inference, PwS leverages developers' code styles as covert triggers implicitly embedded within their prompts. PwS introduces a novel data collection method and a two-step training stra"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.27631","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.27631/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2605.27631","created_at":"2026-05-28T01:04:44.800272+00:00"},{"alias_kind":"arxiv_version","alias_value":"2605.27631v1","created_at":"2026-05-28T01:04:44.800272+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.27631","created_at":"2026-05-28T01:04:44.800272+00:00"},{"alias_kind":"pith_short_12","alias_value":"6ZT25RRWPI7S","created_at":"2026-05-28T01:04:44.800272+00:00"},{"alias_kind":"pith_short_16","alias_value":"6ZT25RRWPI7S3F2A","created_at":"2026-05-28T01:04:44.800272+00:00"},{"alias_kind":"pith_short_8","alias_value":"6ZT25RRW","created_at":"2026-05-28T01:04:44.800272+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/6ZT25RRWPI7S3F2A643ZOJY6SF","json":"https://pith.science/pith/6ZT25RRWPI7S3F2A643ZOJY6SF.json","graph_json":"https://pith.science/api/pith-number/6ZT25RRWPI7S3F2A643ZOJY6SF/graph.json","events_json":"https://pith.science/api/pith-number/6ZT25RRWPI7S3F2A643ZOJY6SF/events.json","paper":"https://pith.science/paper/6ZT25RRW"},"agent_actions":{"view_html":"https://pith.science/pith/6ZT25RRWPI7S3F2A643ZOJY6SF","download_json":"https://pith.science/pith/6ZT25RRWPI7S3F2A643ZOJY6SF.json","view_paper":"https://pith.science/paper/6ZT25RRW","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2605.27631&json=true","fetch_graph":"https://pith.science/api/pith-number/6ZT25RRWPI7S3F2A643ZOJY6SF/graph.json","fetch_events":"https://pith.science/api/pith-number/6ZT25RRWPI7S3F2A643ZOJY6SF/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/6ZT25RRWPI7S3F2A643ZOJY6SF/action/timestamp_anchor","attest_storage":"https://pith.science/pith/6ZT25RRWPI7S3F2A643ZOJY6SF/action/storage_attestation","attest_author":"https://pith.science/pith/6ZT25RRWPI7S3F2A643ZOJY6SF/action/author_attestation","sign_citation":"https://pith.science/pith/6ZT25RRWPI7S3F2A643ZOJY6SF/action/citation_signature","submit_replication":"https://pith.science/pith/6ZT25RRWPI7S3F2A643ZOJY6SF/action/replication_record"}},"created_at":"2026-05-28T01:04:44.800272+00:00","updated_at":"2026-05-28T01:04:44.800272+00:00"}