{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2024:76DPSGXMOWWHM6WLVLLTQ5QWDU","short_pith_number":"pith:76DPSGXM","canonical_record":{"source":{"id":"2406.18495","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-06-26T16:58:20Z","cross_cats_sorted":[],"title_canon_sha256":"f05660010b34991862d4ad5d0ef784d10c5a15542480b9ea3cca4333ffd5706b","abstract_canon_sha256":"076b5fdce0133c1dbc9fa3d56c2226b1e5cc3ceb3b521afa3011331488f4a91d"},"schema_version":"1.0"},"canonical_sha256":"ff86f91aec75ac767acbaad73876161d00d977ea794c9085178f91385ce9e355","source":{"kind":"arxiv","id":"2406.18495","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2406.18495","created_at":"2026-05-17T23:38:13Z"},{"alias_kind":"arxiv_version","alias_value":"2406.18495v3","created_at":"2026-05-17T23:38:13Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2406.18495","created_at":"2026-05-17T23:38:13Z"},{"alias_kind":"pith_short_12","alias_value":"76DPSGXMOWWH","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"76DPSGXMOWWHM6WL","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"76DPSGXM","created_at":"2026-05-18T12:33:37Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2024:76DPSGXMOWWHM6WLVLLTQ5QWDU","target":"record","payload":{"canonical_record":{"source":{"id":"2406.18495","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-06-26T16:58:20Z","cross_cats_sorted":[],"title_canon_sha256":"f05660010b34991862d4ad5d0ef784d10c5a15542480b9ea3cca4333ffd5706b","abstract_canon_sha256":"076b5fdce0133c1dbc9fa3d56c2226b1e5cc3ceb3b521afa3011331488f4a91d"},"schema_version":"1.0"},"canonical_sha256":"ff86f91aec75ac767acbaad73876161d00d977ea794c9085178f91385ce9e355","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-17T23:38:13.601163Z","signature_b64":"qMR1oa3zWyorAIwTo4ggD0r3myqsfwNeYTqFawWj+pZKJB1erbleUDOC1vDWgMxKs/xbhkONXjsbnIKrXHmsCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ff86f91aec75ac767acbaad73876161d00d977ea794c9085178f91385ce9e355","last_reissued_at":"2026-05-17T23:38:13.600412Z","signature_status":"signed_v1","first_computed_at":"2026-05-17T23:38:13.600412Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2406.18495","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:38:13Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"5TJstiRLGQ6C9bIaUrOrw8j+fW7B5G7jV3wt38f8IcUyq21CSJ9AswFM+nV2LJoFt0PN5hY98/YMVZWD6o9+AQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-18T18:14:32.208333Z"},"content_sha256":"0a455614603c1fa379cc439c06b5abd17eba17ba188381be07072932bc99379e","schema_version":"1.0","event_id":"sha256:0a455614603c1fa379cc439c06b5abd17eba17ba188381be07072932bc99379e"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2024:76DPSGXMOWWHM6WLVLLTQ5QWDU","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"WildGuard: Open One-Stop Moderation Tools for Safety Risks, Jailbreaks, and Refusals of LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"WildGuard is an open moderation tool that detects malicious prompts, response risks, and refusal behaviors in LLMs with accuracy matching or exceeding GPT-4 on key tasks.","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Allyson Ettinger, Bill Yuchen Lin, Kavel Rao, Liwei Jiang, Nathan Lambert, Nouha Dziri, Seungju Han, Yejin Choi","submitted_at":"2024-06-26T16:58:20Z","abstract_excerpt":"We introduce WildGuard -- an open, light-weight moderation tool for LLM safety that achieves three goals: (1) identifying malicious intent in user prompts, (2) detecting safety risks of model responses, and (3) determining model refusal rate. Together, WildGuard serves the increasing needs for automatic safety moderation and evaluation of LLM interactions, providing a one-stop tool with enhanced accuracy and broad coverage across 13 risk categories. While existing open moderation tools such as Llama-Guard2 score reasonably well in classifying straightforward model interactions, they lag far be"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"WildGuard establishes state-of-the-art performance in open-source safety moderation across all the three tasks compared to ten strong existing open-source moderation models (e.g., up to 26.4% improvement on refusal detection). Importantly, WildGuard matches and sometimes exceeds GPT-4 performance (e.g., up to 3.9% improvement on prompt harmfulness identification). WildGuard serves as a highly effective safety moderator in an LLM interface, reducing the success rate of jailbreak attacks from 79.8% to 2.4%.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"The human-annotated WildGuardTest set of 5K items and the broader WildGuardMix dataset are representative of real-world user prompts, adversarial jailbreaks, and model behaviors, and that performance gains will generalize beyond the ten public benchmarks evaluated.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"WildGuard is a new open moderation model and dataset for LLM safety that identifies harmful prompts, risky responses, and refusal rates, achieving SOTA open-source performance and sometimes exceeding GPT-4 while cutting jailbreak success from 79.8% to 2.4%.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"WildGuard is an open moderation tool that detects malicious prompts, response risks, and refusal behaviors in LLMs with accuracy matching or exceeding GPT-4 on key tasks.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"5c0103e38097947a2d5fdb8273f4bcb334880538e35b26a43340c989693090d3"},"source":{"id":"2406.18495","kind":"arxiv","version":3},"verdict":{"id":"0b3c3aeb-a2f2-4e3b-b5aa-1d35cbe34f51","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-17T16:19:49.016828Z","strongest_claim":"WildGuard establishes state-of-the-art performance in open-source safety moderation across all the three tasks compared to ten strong existing open-source moderation models (e.g., up to 26.4% improvement on refusal detection). Importantly, WildGuard matches and sometimes exceeds GPT-4 performance (e.g., up to 3.9% improvement on prompt harmfulness identification). WildGuard serves as a highly effective safety moderator in an LLM interface, reducing the success rate of jailbreak attacks from 79.8% to 2.4%.","one_line_summary":"WildGuard is a new open moderation model and dataset for LLM safety that identifies harmful prompts, risky responses, and refusal rates, achieving SOTA open-source performance and sometimes exceeding GPT-4 while cutting jailbreak success from 79.8% to 2.4%.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"The human-annotated WildGuardTest set of 5K items and the broader WildGuardMix dataset are representative of real-world user prompts, adversarial jailbreaks, and model behaviors, and that performance gains will generalize beyond the ten public benchmarks evaluated.","pith_extraction_headline":"WildGuard is an open moderation tool that detects malicious prompts, response risks, and refusal behaviors in LLMs with accuracy matching or exceeding GPT-4 on key tasks."},"references":{"count":63,"sample":[{"doi":"","year":2023,"title":"GPT-4 Technical Report","work_id":"b928e041-6991-4c08-8c81-0359e4097c7b","ref_index":1,"cited_arxiv_id":"2303.08774","is_internal_anchor":true},{"doi":"","year":2024,"title":"Llama 3 model card","work_id":"c7ab4b73-84eb-419d-9567-20e065974941","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"The claude 3 model family: Opus, sonnet, haiku","work_id":"9f159deb-2679-42f7-b329-e85ade88cb92","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2024,"title":"Transactions on Machine Learning Research , author=","work_id":"da63c249-19b0-4d11-94bf-033eeaa2d43a","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2022,"title":"Training a helpful and harmless assistant with reinforcement learning from human feedback, 2022","work_id":"6b9cf002-ab59-4c61-ae20-2d2f7b0eecaf","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":63,"snapshot_sha256":"ca3febef57e702ff33568432713572223e865c2763303544b094592be9c202bc","internal_anchors":9},"formal_canon":{"evidence_count":2,"snapshot_sha256":"270d535674f34295ca4c877594d35ff8028fb82af14f4975d095d8f9fe9bb636"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"0b3c3aeb-a2f2-4e3b-b5aa-1d35cbe34f51"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-17T23:38:13Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"LoMfjibG7w3YJMo8YIo8VQqUDQMWaCa6vPssKMScUnSPOF8AdXRUWI0Yp+aUr1qStrF3C/dxx95CamMrP6GrAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-18T18:14:32.208911Z"},"content_sha256":"bb791af12258a2df7ce7cf6c2d533268eefa79834f23512ed3ca2194df07922d","schema_version":"1.0","event_id":"sha256:bb791af12258a2df7ce7cf6c2d533268eefa79834f23512ed3ca2194df07922d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/76DPSGXMOWWHM6WLVLLTQ5QWDU/bundle.json","state_url":"https://pith.science/pith/76DPSGXMOWWHM6WLVLLTQ5QWDU/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/76DPSGXMOWWHM6WLVLLTQ5QWDU/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-18T18:14:32Z","links":{"resolver":"https://pith.science/pith/76DPSGXMOWWHM6WLVLLTQ5QWDU","bundle":"https://pith.science/pith/76DPSGXMOWWHM6WLVLLTQ5QWDU/bundle.json","state":"https://pith.science/pith/76DPSGXMOWWHM6WLVLLTQ5QWDU/state.json","well_known_bundle":"https://pith.science/.well-known/pith/76DPSGXMOWWHM6WLVLLTQ5QWDU/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2024:76DPSGXMOWWHM6WLVLLTQ5QWDU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"076b5fdce0133c1dbc9fa3d56c2226b1e5cc3ceb3b521afa3011331488f4a91d","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-06-26T16:58:20Z","title_canon_sha256":"f05660010b34991862d4ad5d0ef784d10c5a15542480b9ea3cca4333ffd5706b"},"schema_version":"1.0","source":{"id":"2406.18495","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2406.18495","created_at":"2026-05-17T23:38:13Z"},{"alias_kind":"arxiv_version","alias_value":"2406.18495v3","created_at":"2026-05-17T23:38:13Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2406.18495","created_at":"2026-05-17T23:38:13Z"},{"alias_kind":"pith_short_12","alias_value":"76DPSGXMOWWH","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_16","alias_value":"76DPSGXMOWWHM6WL","created_at":"2026-05-18T12:33:37Z"},{"alias_kind":"pith_short_8","alias_value":"76DPSGXM","created_at":"2026-05-18T12:33:37Z"}],"graph_snapshots":[{"event_id":"sha256:bb791af12258a2df7ce7cf6c2d533268eefa79834f23512ed3ca2194df07922d","target":"graph","created_at":"2026-05-17T23:38:13Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"WildGuard establishes state-of-the-art performance in open-source safety moderation across all the three tasks compared to ten strong existing open-source moderation models (e.g., up to 26.4% improvement on refusal detection). Importantly, WildGuard matches and sometimes exceeds GPT-4 performance (e.g., up to 3.9% improvement on prompt harmfulness identification). WildGuard serves as a highly effective safety moderator in an LLM interface, reducing the success rate of jailbreak attacks from 79.8% to 2.4%."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The human-annotated WildGuardTest set of 5K items and the broader WildGuardMix dataset are representative of real-world user prompts, adversarial jailbreaks, and model behaviors, and that performance gains will generalize beyond the ten public benchmarks evaluated."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"WildGuard is a new open moderation model and dataset for LLM safety that identifies harmful prompts, risky responses, and refusal rates, achieving SOTA open-source performance and sometimes exceeding GPT-4 while cutting jailbreak success from 79.8% to 2.4%."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"WildGuard is an open moderation tool that detects malicious prompts, response risks, and refusal behaviors in LLMs with accuracy matching or exceeding GPT-4 on key tasks."}],"snapshot_sha256":"5c0103e38097947a2d5fdb8273f4bcb334880538e35b26a43340c989693090d3"},"formal_canon":{"evidence_count":2,"snapshot_sha256":"270d535674f34295ca4c877594d35ff8028fb82af14f4975d095d8f9fe9bb636"},"paper":{"abstract_excerpt":"We introduce WildGuard -- an open, light-weight moderation tool for LLM safety that achieves three goals: (1) identifying malicious intent in user prompts, (2) detecting safety risks of model responses, and (3) determining model refusal rate. Together, WildGuard serves the increasing needs for automatic safety moderation and evaluation of LLM interactions, providing a one-stop tool with enhanced accuracy and broad coverage across 13 risk categories. While existing open moderation tools such as Llama-Guard2 score reasonably well in classifying straightforward model interactions, they lag far be","authors_text":"Allyson Ettinger, Bill Yuchen Lin, Kavel Rao, Liwei Jiang, Nathan Lambert, Nouha Dziri, Seungju Han, Yejin Choi","cross_cats":[],"headline":"WildGuard is an open moderation tool that detects malicious prompts, response risks, and refusal behaviors in LLMs with accuracy matching or exceeding GPT-4 on key tasks.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-06-26T16:58:20Z","title":"WildGuard: Open One-Stop Moderation Tools for Safety Risks, Jailbreaks, and Refusals of LLMs"},"references":{"count":63,"internal_anchors":9,"resolved_work":63,"sample":[{"cited_arxiv_id":"2303.08774","doi":"","is_internal_anchor":true,"ref_index":1,"title":"GPT-4 Technical Report","work_id":"b928e041-6991-4c08-8c81-0359e4097c7b","year":2023},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"Llama 3 model card","work_id":"c7ab4b73-84eb-419d-9567-20e065974941","year":2024},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"The claude 3 model family: Opus, sonnet, haiku","work_id":"9f159deb-2679-42f7-b329-e85ade88cb92","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"Transactions on Machine Learning Research , author=","work_id":"da63c249-19b0-4d11-94bf-033eeaa2d43a","year":2024},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"Training a helpful and harmless assistant with reinforcement learning from human feedback, 2022","work_id":"6b9cf002-ab59-4c61-ae20-2d2f7b0eecaf","year":2022}],"snapshot_sha256":"ca3febef57e702ff33568432713572223e865c2763303544b094592be9c202bc"},"source":{"id":"2406.18495","kind":"arxiv","version":3},"verdict":{"created_at":"2026-05-17T16:19:49.016828Z","id":"0b3c3aeb-a2f2-4e3b-b5aa-1d35cbe34f51","model_set":{"reader":"grok-4.3"},"one_line_summary":"WildGuard is a new open moderation model and dataset for LLM safety that identifies harmful prompts, risky responses, and refusal rates, achieving SOTA open-source performance and sometimes exceeding GPT-4 while cutting jailbreak success from 79.8% to 2.4%.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"WildGuard is an open moderation tool that detects malicious prompts, response risks, and refusal behaviors in LLMs with accuracy matching or exceeding GPT-4 on key tasks.","strongest_claim":"WildGuard establishes state-of-the-art performance in open-source safety moderation across all the three tasks compared to ten strong existing open-source moderation models (e.g., up to 26.4% improvement on refusal detection). Importantly, WildGuard matches and sometimes exceeds GPT-4 performance (e.g., up to 3.9% improvement on prompt harmfulness identification). WildGuard serves as a highly effective safety moderator in an LLM interface, reducing the success rate of jailbreak attacks from 79.8% to 2.4%.","weakest_assumption":"The human-annotated WildGuardTest set of 5K items and the broader WildGuardMix dataset are representative of real-world user prompts, adversarial jailbreaks, and model behaviors, and that performance gains will generalize beyond the ten public benchmarks evaluated."}},"verdict_id":"0b3c3aeb-a2f2-4e3b-b5aa-1d35cbe34f51"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:0a455614603c1fa379cc439c06b5abd17eba17ba188381be07072932bc99379e","target":"record","created_at":"2026-05-17T23:38:13Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"076b5fdce0133c1dbc9fa3d56c2226b1e5cc3ceb3b521afa3011331488f4a91d","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2024-06-26T16:58:20Z","title_canon_sha256":"f05660010b34991862d4ad5d0ef784d10c5a15542480b9ea3cca4333ffd5706b"},"schema_version":"1.0","source":{"id":"2406.18495","kind":"arxiv","version":3}},"canonical_sha256":"ff86f91aec75ac767acbaad73876161d00d977ea794c9085178f91385ce9e355","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"ff86f91aec75ac767acbaad73876161d00d977ea794c9085178f91385ce9e355","first_computed_at":"2026-05-17T23:38:13.600412Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-17T23:38:13.600412Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"qMR1oa3zWyorAIwTo4ggD0r3myqsfwNeYTqFawWj+pZKJB1erbleUDOC1vDWgMxKs/xbhkONXjsbnIKrXHmsCg==","signature_status":"signed_v1","signed_at":"2026-05-17T23:38:13.601163Z","signed_message":"canonical_sha256_bytes"},"source_id":"2406.18495","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:0a455614603c1fa379cc439c06b5abd17eba17ba188381be07072932bc99379e","sha256:bb791af12258a2df7ce7cf6c2d533268eefa79834f23512ed3ca2194df07922d"],"state_sha256":"9f1e2226ad93c87dbf7515148607f36fedbaa3d007ee5195ebfa5fa823708bfa"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"E/K+0dLUjI/xYbobH4ix88dPk2+rTGwYf2vXVbiTTo4wz8AwxXExVtBhzA9rouKRit/Vxx58JajaEx58h8fRBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-18T18:14:32.210543Z","bundle_sha256":"2258163fc75f897e212011acbb9744bde8a4227492a48ee31b22495c2005dd2b"}}