{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:74BMPPY4HUZWGKYOL27MQ7RIXR","short_pith_number":"pith:74BMPPY4","canonical_record":{"source":{"id":"2606.18996","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T12:17:02Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"6fbfdb2e8c53a70003d784b17c6af2b1266a563019f8b68c265da50c1789628b","abstract_canon_sha256":"820b2ebfbcb60491361c99ff59895063b5750dbb6f0f0478c0e4883ea4d51d4e"},"schema_version":"1.0"},"canonical_sha256":"ff02c7bf1c3d33632b0e5ebec87e28bc59be995f6d717a0086a4140cb61a3cb6","source":{"kind":"arxiv","id":"2606.18996","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.18996","created_at":"2026-06-19T16:12:22Z"},{"alias_kind":"arxiv_version","alias_value":"2606.18996v2","created_at":"2026-06-19T16:12:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.18996","created_at":"2026-06-19T16:12:22Z"},{"alias_kind":"pith_short_12","alias_value":"74BMPPY4HUZW","created_at":"2026-06-19T16:12:22Z"},{"alias_kind":"pith_short_16","alias_value":"74BMPPY4HUZWGKYO","created_at":"2026-06-19T16:12:22Z"},{"alias_kind":"pith_short_8","alias_value":"74BMPPY4","created_at":"2026-06-19T16:12:22Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:74BMPPY4HUZWGKYOL27MQ7RIXR","target":"record","payload":{"canonical_record":{"source":{"id":"2606.18996","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T12:17:02Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"6fbfdb2e8c53a70003d784b17c6af2b1266a563019f8b68c265da50c1789628b","abstract_canon_sha256":"820b2ebfbcb60491361c99ff59895063b5750dbb6f0f0478c0e4883ea4d51d4e"},"schema_version":"1.0"},"canonical_sha256":"ff02c7bf1c3d33632b0e5ebec87e28bc59be995f6d717a0086a4140cb61a3cb6","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-19T16:12:22.427626Z","signature_b64":"Mzi7D0xwOjeQ5dEY1pWeSCcb4iMWGSdqv4ZapDPR7X0mn+AKHizQWWnlrLGvnBTac2kMGZdqTIJPPFCzjveUCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ff02c7bf1c3d33632b0e5ebec87e28bc59be995f6d717a0086a4140cb61a3cb6","last_reissued_at":"2026-06-19T16:12:22.427210Z","signature_status":"signed_v1","first_computed_at":"2026-06-19T16:12:22.427210Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.18996","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:12:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4kAfseKluC4uCMtDNiGdIwkdZvbfIb1DRoKq8k5OvhTSDV/GepodIGS/qqoTAshQ8bepwieMVgDE1Ul/DC1pCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-04T07:57:32.262021Z"},"content_sha256":"f10fd1789aa26442665703bb82688bf4d8ecd2d5a3815322b974798d710ab76c","schema_version":"1.0","event_id":"sha256:f10fd1789aa26442665703bb82688bf4d8ecd2d5a3815322b974798d710ab76c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:74BMPPY4HUZWGKYOL27MQ7RIXR","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"TRAP: Benchmark for Task-completion and Resistance to Active Privacy-extraction","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Baek Seong-Eun, Moon Ye-Bin, Nam Hyeon-Woo, Tae-Hyun Oh, Yejin Yeo","submitted_at":"2026-06-17T12:17:02Z","abstract_excerpt":"Agents are increasingly deployed in document-intensive workflows where sensitive private information is not an edge case but a routine input, e.g., an agent booking a flight needs passport numbers. In such settings, the agent must use private information to complete tasks accurately while never exposing it in its responses, because it cannot verify who is actually at the keyboard. These two obligations are in fundamental tension. A model capable enough to use private information for task completion can, by the same capability, be induced to reveal it. To evaluate the trade-off of task accuracy"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.18996","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.18996/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:12:22Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+jIoGMe82jQeKf6sBTTlFQCi1LQkPFndM4Q3MY7aA0TPqRjGSSHXYluUIUapLFvDXGjfOK3kf56u9umAZKY/Bw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-04T07:57:32.262413Z"},"content_sha256":"5e0e37de56739322459190c7cc1bf9f0af9d66e13f0e3e2b56e140602931a18c","schema_version":"1.0","event_id":"sha256:5e0e37de56739322459190c7cc1bf9f0af9d66e13f0e3e2b56e140602931a18c"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/74BMPPY4HUZWGKYOL27MQ7RIXR/bundle.json","state_url":"https://pith.science/pith/74BMPPY4HUZWGKYOL27MQ7RIXR/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/74BMPPY4HUZWGKYOL27MQ7RIXR/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-04T07:57:32Z","links":{"resolver":"https://pith.science/pith/74BMPPY4HUZWGKYOL27MQ7RIXR","bundle":"https://pith.science/pith/74BMPPY4HUZWGKYOL27MQ7RIXR/bundle.json","state":"https://pith.science/pith/74BMPPY4HUZWGKYOL27MQ7RIXR/state.json","well_known_bundle":"https://pith.science/.well-known/pith/74BMPPY4HUZWGKYOL27MQ7RIXR/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:74BMPPY4HUZWGKYOL27MQ7RIXR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"820b2ebfbcb60491361c99ff59895063b5750dbb6f0f0478c0e4883ea4d51d4e","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T12:17:02Z","title_canon_sha256":"6fbfdb2e8c53a70003d784b17c6af2b1266a563019f8b68c265da50c1789628b"},"schema_version":"1.0","source":{"id":"2606.18996","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.18996","created_at":"2026-06-19T16:12:22Z"},{"alias_kind":"arxiv_version","alias_value":"2606.18996v2","created_at":"2026-06-19T16:12:22Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.18996","created_at":"2026-06-19T16:12:22Z"},{"alias_kind":"pith_short_12","alias_value":"74BMPPY4HUZW","created_at":"2026-06-19T16:12:22Z"},{"alias_kind":"pith_short_16","alias_value":"74BMPPY4HUZWGKYO","created_at":"2026-06-19T16:12:22Z"},{"alias_kind":"pith_short_8","alias_value":"74BMPPY4","created_at":"2026-06-19T16:12:22Z"}],"graph_snapshots":[{"event_id":"sha256:5e0e37de56739322459190c7cc1bf9f0af9d66e13f0e3e2b56e140602931a18c","target":"graph","created_at":"2026-06-19T16:12:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.18996/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Agents are increasingly deployed in document-intensive workflows where sensitive private information is not an edge case but a routine input, e.g., an agent booking a flight needs passport numbers. In such settings, the agent must use private information to complete tasks accurately while never exposing it in its responses, because it cannot verify who is actually at the keyboard. These two obligations are in fundamental tension. A model capable enough to use private information for task completion can, by the same capability, be induced to reveal it. To evaluate the trade-off of task accuracy","authors_text":"Baek Seong-Eun, Moon Ye-Bin, Nam Hyeon-Woo, Tae-Hyun Oh, Yejin Yeo","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T12:17:02Z","title":"TRAP: Benchmark for Task-completion and Resistance to Active Privacy-extraction"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.18996","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f10fd1789aa26442665703bb82688bf4d8ecd2d5a3815322b974798d710ab76c","target":"record","created_at":"2026-06-19T16:12:22Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"820b2ebfbcb60491361c99ff59895063b5750dbb6f0f0478c0e4883ea4d51d4e","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T12:17:02Z","title_canon_sha256":"6fbfdb2e8c53a70003d784b17c6af2b1266a563019f8b68c265da50c1789628b"},"schema_version":"1.0","source":{"id":"2606.18996","kind":"arxiv","version":2}},"canonical_sha256":"ff02c7bf1c3d33632b0e5ebec87e28bc59be995f6d717a0086a4140cb61a3cb6","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"ff02c7bf1c3d33632b0e5ebec87e28bc59be995f6d717a0086a4140cb61a3cb6","first_computed_at":"2026-06-19T16:12:22.427210Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-19T16:12:22.427210Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Mzi7D0xwOjeQ5dEY1pWeSCcb4iMWGSdqv4ZapDPR7X0mn+AKHizQWWnlrLGvnBTac2kMGZdqTIJPPFCzjveUCg==","signature_status":"signed_v1","signed_at":"2026-06-19T16:12:22.427626Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.18996","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f10fd1789aa26442665703bb82688bf4d8ecd2d5a3815322b974798d710ab76c","sha256:5e0e37de56739322459190c7cc1bf9f0af9d66e13f0e3e2b56e140602931a18c"],"state_sha256":"1bd29d2a102e21ac03d8bed2dcdf6e2babf2ca389f825f3f2a2184c607607374"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yxwkgr0uE2K8KDCh/bk9Q8qkvAx40o58tnbmqWok3263O6zlis2ouiJJxmqYgqnZ0sNkDzRoMKfdJl/NJ8udDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-04T07:57:32.264459Z","bundle_sha256":"79e500a289fea8b0f4e5e56e4bd581f177f615248ae00f396439882209fad329"}}