{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:76WPTJJ4HJPMGNICGRHZTK5XQF","short_pith_number":"pith:76WPTJJ4","canonical_record":{"source":{"id":"2602.04899","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-02-03T14:38:07Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"a78bcfba9ab80bbbc840262dcd4cf8b2b3c9febca099b38caeac27d080877499","abstract_canon_sha256":"7c721e99bc874395a35150bcf63eba3182f65cd170f30cb03dd218d9df8feab4"},"schema_version":"1.0"},"canonical_sha256":"ffacf9a53c3a5ec33502344f99abb7814925622d1674b323c846ac3985c01273","source":{"kind":"arxiv","id":"2602.04899","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2602.04899","created_at":"2026-06-03T02:05:45Z"},{"alias_kind":"arxiv_version","alias_value":"2602.04899v2","created_at":"2026-06-03T02:05:45Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2602.04899","created_at":"2026-06-03T02:05:45Z"},{"alias_kind":"pith_short_12","alias_value":"76WPTJJ4HJPM","created_at":"2026-06-03T02:05:45Z"},{"alias_kind":"pith_short_16","alias_value":"76WPTJJ4HJPMGNIC","created_at":"2026-06-03T02:05:45Z"},{"alias_kind":"pith_short_8","alias_value":"76WPTJJ4","created_at":"2026-06-03T02:05:45Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:76WPTJJ4HJPMGNICGRHZTK5XQF","target":"record","payload":{"canonical_record":{"source":{"id":"2602.04899","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-02-03T14:38:07Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"a78bcfba9ab80bbbc840262dcd4cf8b2b3c9febca099b38caeac27d080877499","abstract_canon_sha256":"7c721e99bc874395a35150bcf63eba3182f65cd170f30cb03dd218d9df8feab4"},"schema_version":"1.0"},"canonical_sha256":"ffacf9a53c3a5ec33502344f99abb7814925622d1674b323c846ac3985c01273","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-03T02:05:45.483609Z","signature_b64":"pLIdCpYn3fcvROc/bE2xo4R7+hTRjEWzbV9TvAAI4/3uz9zPn89D4c6Pr8nBwA4kivysBr1XFiuXEuyA50kBAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ffacf9a53c3a5ec33502344f99abb7814925622d1674b323c846ac3985c01273","last_reissued_at":"2026-06-03T02:05:45.483035Z","signature_status":"signed_v1","first_computed_at":"2026-06-03T02:05:45.483035Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2602.04899","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T02:05:45Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"nrQ+Z0hM+FXz3pToAQoXNUwNF0KMshMZhnWVYV3UQyh3wzL/LB6cxSVLnfhiEVSye+CpWh6UcFlXUpP/cpVxDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T06:43:51.979981Z"},"content_sha256":"545ff2bc63a4391a4da9af3494fd34325d11dfeb063c83845e2cd0b0982565ab","schema_version":"1.0","event_id":"sha256:545ff2bc63a4391a4da9af3494fd34325d11dfeb063c83845e2cd0b0982565ab"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:76WPTJJ4HJPMGNICGRHZTK5XQF","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Phantom Transfer: Data Poisoning can Survive Data-Level Defences","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Anandmayi Bhongade, Andrew Draganov, Mary Phuong, Tolga H. Dur","submitted_at":"2026-02-03T14:38:07Z","abstract_excerpt":"We present a data poisoning attack -- Phantom Transfer -- with the property that, even if you know precisely how the poison was placed into an otherwise benign dataset, you cannot filter it out. We achieve this by modifying subliminal learning to work in real-world contexts and demonstrate that the attack works regardless of which model produced the data, which model is trained on the data or what the attack target is. Furthermore, the attack survives 11 tested data-level defences, including one where every sample is paraphrased by another model. We characterise when this attack works best and"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2602.04899","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2602.04899/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T02:05:45Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"NCUg2mpf0HVGIbdKS5koErYwBiZvpioLrJZXAenl6TBp4XtU9Sr6xmRQSbyLA5G1afCuPKEGNdbm1BkYWyD7AQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T06:43:51.980412Z"},"content_sha256":"e9a7ace0084a2297aef8a9587bc0d5b7fdd802df9df8bfd1dd6303f60e2d8471","schema_version":"1.0","event_id":"sha256:e9a7ace0084a2297aef8a9587bc0d5b7fdd802df9df8bfd1dd6303f60e2d8471"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/76WPTJJ4HJPMGNICGRHZTK5XQF/bundle.json","state_url":"https://pith.science/pith/76WPTJJ4HJPMGNICGRHZTK5XQF/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/76WPTJJ4HJPMGNICGRHZTK5XQF/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-09T06:43:51Z","links":{"resolver":"https://pith.science/pith/76WPTJJ4HJPMGNICGRHZTK5XQF","bundle":"https://pith.science/pith/76WPTJJ4HJPMGNICGRHZTK5XQF/bundle.json","state":"https://pith.science/pith/76WPTJJ4HJPMGNICGRHZTK5XQF/state.json","well_known_bundle":"https://pith.science/.well-known/pith/76WPTJJ4HJPMGNICGRHZTK5XQF/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:76WPTJJ4HJPMGNICGRHZTK5XQF","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"7c721e99bc874395a35150bcf63eba3182f65cd170f30cb03dd218d9df8feab4","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-02-03T14:38:07Z","title_canon_sha256":"a78bcfba9ab80bbbc840262dcd4cf8b2b3c9febca099b38caeac27d080877499"},"schema_version":"1.0","source":{"id":"2602.04899","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2602.04899","created_at":"2026-06-03T02:05:45Z"},{"alias_kind":"arxiv_version","alias_value":"2602.04899v2","created_at":"2026-06-03T02:05:45Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2602.04899","created_at":"2026-06-03T02:05:45Z"},{"alias_kind":"pith_short_12","alias_value":"76WPTJJ4HJPM","created_at":"2026-06-03T02:05:45Z"},{"alias_kind":"pith_short_16","alias_value":"76WPTJJ4HJPMGNIC","created_at":"2026-06-03T02:05:45Z"},{"alias_kind":"pith_short_8","alias_value":"76WPTJJ4","created_at":"2026-06-03T02:05:45Z"}],"graph_snapshots":[{"event_id":"sha256:e9a7ace0084a2297aef8a9587bc0d5b7fdd802df9df8bfd1dd6303f60e2d8471","target":"graph","created_at":"2026-06-03T02:05:45Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2602.04899/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"We present a data poisoning attack -- Phantom Transfer -- with the property that, even if you know precisely how the poison was placed into an otherwise benign dataset, you cannot filter it out. We achieve this by modifying subliminal learning to work in real-world contexts and demonstrate that the attack works regardless of which model produced the data, which model is trained on the data or what the attack target is. Furthermore, the attack survives 11 tested data-level defences, including one where every sample is paraphrased by another model. We characterise when this attack works best and","authors_text":"Anandmayi Bhongade, Andrew Draganov, Mary Phuong, Tolga H. Dur","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-02-03T14:38:07Z","title":"Phantom Transfer: Data Poisoning can Survive Data-Level Defences"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2602.04899","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:545ff2bc63a4391a4da9af3494fd34325d11dfeb063c83845e2cd0b0982565ab","target":"record","created_at":"2026-06-03T02:05:45Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"7c721e99bc874395a35150bcf63eba3182f65cd170f30cb03dd218d9df8feab4","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-02-03T14:38:07Z","title_canon_sha256":"a78bcfba9ab80bbbc840262dcd4cf8b2b3c9febca099b38caeac27d080877499"},"schema_version":"1.0","source":{"id":"2602.04899","kind":"arxiv","version":2}},"canonical_sha256":"ffacf9a53c3a5ec33502344f99abb7814925622d1674b323c846ac3985c01273","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"ffacf9a53c3a5ec33502344f99abb7814925622d1674b323c846ac3985c01273","first_computed_at":"2026-06-03T02:05:45.483035Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-03T02:05:45.483035Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"pLIdCpYn3fcvROc/bE2xo4R7+hTRjEWzbV9TvAAI4/3uz9zPn89D4c6Pr8nBwA4kivysBr1XFiuXEuyA50kBAg==","signature_status":"signed_v1","signed_at":"2026-06-03T02:05:45.483609Z","signed_message":"canonical_sha256_bytes"},"source_id":"2602.04899","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:545ff2bc63a4391a4da9af3494fd34325d11dfeb063c83845e2cd0b0982565ab","sha256:e9a7ace0084a2297aef8a9587bc0d5b7fdd802df9df8bfd1dd6303f60e2d8471"],"state_sha256":"3c8e03370e736bec4230b1ecd99e1ce0470725c1570f785523286813d7a7ca46"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"tLUkO7ARq0uCiu2Bd4pJUkzjgD/DCkKAY9pPlXYOcPI5VrPpJCIeAfbwalwcNcHgmWSbl13YPOQDR+LiVhonDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-09T06:43:51.982426Z","bundle_sha256":"51d6d23c1d5be726ed0b27cb28ef1af3a86974e8a50073426dc0d6a301bd46a6"}}