{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:7OVR7EE3NV263MWJWI2CSKQ2UY","short_pith_number":"pith:7OVR7EE3","canonical_record":{"source":{"id":"2606.06244","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-04T14:48:23Z","cross_cats_sorted":[],"title_canon_sha256":"88542025adec42fe68246074554afa4532082a4dc26e57e2b7ee76297e7fc87f","abstract_canon_sha256":"131bf913ce4a57e5d8dd8258be619c4aa223ad15c866c400cc8f0f900871c7fc"},"schema_version":"1.0"},"canonical_sha256":"fbab1f909b6d75edb2c9b234292a1aa605fb3669e383e9083096dbf5a6a4b707","source":{"kind":"arxiv","id":"2606.06244","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.06244","created_at":"2026-06-05T01:15:39Z"},{"alias_kind":"arxiv_version","alias_value":"2606.06244v1","created_at":"2026-06-05T01:15:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.06244","created_at":"2026-06-05T01:15:39Z"},{"alias_kind":"pith_short_12","alias_value":"7OVR7EE3NV26","created_at":"2026-06-05T01:15:39Z"},{"alias_kind":"pith_short_16","alias_value":"7OVR7EE3NV263MWJ","created_at":"2026-06-05T01:15:39Z"},{"alias_kind":"pith_short_8","alias_value":"7OVR7EE3","created_at":"2026-06-05T01:15:39Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:7OVR7EE3NV263MWJWI2CSKQ2UY","target":"record","payload":{"canonical_record":{"source":{"id":"2606.06244","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-04T14:48:23Z","cross_cats_sorted":[],"title_canon_sha256":"88542025adec42fe68246074554afa4532082a4dc26e57e2b7ee76297e7fc87f","abstract_canon_sha256":"131bf913ce4a57e5d8dd8258be619c4aa223ad15c866c400cc8f0f900871c7fc"},"schema_version":"1.0"},"canonical_sha256":"fbab1f909b6d75edb2c9b234292a1aa605fb3669e383e9083096dbf5a6a4b707","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-05T01:15:39.125273Z","signature_b64":"aiKFB+FHVFjCTrT1vykrt0ykBWrXGc/+8bIFkXeS/glPQ/czJpsK0EM4Rd/n+ugOVfAWxbQR3yfFzAC7+T2LCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"fbab1f909b6d75edb2c9b234292a1aa605fb3669e383e9083096dbf5a6a4b707","last_reissued_at":"2026-06-05T01:15:39.124788Z","signature_status":"signed_v1","first_computed_at":"2026-06-05T01:15:39.124788Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.06244","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-05T01:15:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"JnCCcnJxNhqd1JuG19FVLVR73o8LiOMgAakIH72JomaLtPMdQEUDV3t1c74k5Qdh6cyO+Pp7IgO+8ZIbg8AMCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T19:12:18.159411Z"},"content_sha256":"53bfaaa249a56f02a0391643c8fd9e11d36bf7c1d097319ca33e19cd6512ee89","schema_version":"1.0","event_id":"sha256:53bfaaa249a56f02a0391643c8fd9e11d36bf7c1d097319ca33e19cd6512ee89"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:7OVR7EE3NV263MWJWI2CSKQ2UY","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Steering LLM Viewpoints through Fabricated Evidence Injection","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chang Liu, Haoran Li, Jian Weng, Weiming Zhang, Xi Yang, Yangqiu Song, Zhenglin Huang","submitted_at":"2026-06-04T14:48:23Z","abstract_excerpt":"As chatbots increasingly influence daily decision-making, their potential to produce misleading responses poses substantial risks to users. This paper investigates a critical cognitive vulnerability in LLMs: their tendency to uncritically trust external context when presented with fabricated evidence bearing markers of credibility. We introduce Ghostwriter, a two-phase attack framework that first repackages misleading statements with fabricated rationales, then instruct target LLMs to incorporate these viewpoints when responding to relevant queries. Experiments on BBQ, ToxiGen, and our special"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.06244","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.06244/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-05T01:15:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"qG5TA+axwumdvGOef75tEsxQCYpP+DRAfwOofUWuwEz7/lOTSuXfL7NuMQ7hdMJ5z7h7kf5aI0ceuVgRt4/9Dg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T19:12:18.159795Z"},"content_sha256":"fb39f66b6384db58c1d726c95fd81e9006951ac2f12bec2a8b4c4d9fcbb10b87","schema_version":"1.0","event_id":"sha256:fb39f66b6384db58c1d726c95fd81e9006951ac2f12bec2a8b4c4d9fcbb10b87"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/7OVR7EE3NV263MWJWI2CSKQ2UY/bundle.json","state_url":"https://pith.science/pith/7OVR7EE3NV263MWJWI2CSKQ2UY/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/7OVR7EE3NV263MWJWI2CSKQ2UY/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-02T19:12:18Z","links":{"resolver":"https://pith.science/pith/7OVR7EE3NV263MWJWI2CSKQ2UY","bundle":"https://pith.science/pith/7OVR7EE3NV263MWJWI2CSKQ2UY/bundle.json","state":"https://pith.science/pith/7OVR7EE3NV263MWJWI2CSKQ2UY/state.json","well_known_bundle":"https://pith.science/.well-known/pith/7OVR7EE3NV263MWJWI2CSKQ2UY/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:7OVR7EE3NV263MWJWI2CSKQ2UY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"131bf913ce4a57e5d8dd8258be619c4aa223ad15c866c400cc8f0f900871c7fc","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-04T14:48:23Z","title_canon_sha256":"88542025adec42fe68246074554afa4532082a4dc26e57e2b7ee76297e7fc87f"},"schema_version":"1.0","source":{"id":"2606.06244","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.06244","created_at":"2026-06-05T01:15:39Z"},{"alias_kind":"arxiv_version","alias_value":"2606.06244v1","created_at":"2026-06-05T01:15:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.06244","created_at":"2026-06-05T01:15:39Z"},{"alias_kind":"pith_short_12","alias_value":"7OVR7EE3NV26","created_at":"2026-06-05T01:15:39Z"},{"alias_kind":"pith_short_16","alias_value":"7OVR7EE3NV263MWJ","created_at":"2026-06-05T01:15:39Z"},{"alias_kind":"pith_short_8","alias_value":"7OVR7EE3","created_at":"2026-06-05T01:15:39Z"}],"graph_snapshots":[{"event_id":"sha256:fb39f66b6384db58c1d726c95fd81e9006951ac2f12bec2a8b4c4d9fcbb10b87","target":"graph","created_at":"2026-06-05T01:15:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.06244/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"As chatbots increasingly influence daily decision-making, their potential to produce misleading responses poses substantial risks to users. This paper investigates a critical cognitive vulnerability in LLMs: their tendency to uncritically trust external context when presented with fabricated evidence bearing markers of credibility. We introduce Ghostwriter, a two-phase attack framework that first repackages misleading statements with fabricated rationales, then instruct target LLMs to incorporate these viewpoints when responding to relevant queries. Experiments on BBQ, ToxiGen, and our special","authors_text":"Chang Liu, Haoran Li, Jian Weng, Weiming Zhang, Xi Yang, Yangqiu Song, Zhenglin Huang","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-04T14:48:23Z","title":"Steering LLM Viewpoints through Fabricated Evidence Injection"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.06244","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:53bfaaa249a56f02a0391643c8fd9e11d36bf7c1d097319ca33e19cd6512ee89","target":"record","created_at":"2026-06-05T01:15:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"131bf913ce4a57e5d8dd8258be619c4aa223ad15c866c400cc8f0f900871c7fc","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-04T14:48:23Z","title_canon_sha256":"88542025adec42fe68246074554afa4532082a4dc26e57e2b7ee76297e7fc87f"},"schema_version":"1.0","source":{"id":"2606.06244","kind":"arxiv","version":1}},"canonical_sha256":"fbab1f909b6d75edb2c9b234292a1aa605fb3669e383e9083096dbf5a6a4b707","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"fbab1f909b6d75edb2c9b234292a1aa605fb3669e383e9083096dbf5a6a4b707","first_computed_at":"2026-06-05T01:15:39.124788Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-05T01:15:39.124788Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"aiKFB+FHVFjCTrT1vykrt0ykBWrXGc/+8bIFkXeS/glPQ/czJpsK0EM4Rd/n+ugOVfAWxbQR3yfFzAC7+T2LCQ==","signature_status":"signed_v1","signed_at":"2026-06-05T01:15:39.125273Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.06244","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:53bfaaa249a56f02a0391643c8fd9e11d36bf7c1d097319ca33e19cd6512ee89","sha256:fb39f66b6384db58c1d726c95fd81e9006951ac2f12bec2a8b4c4d9fcbb10b87"],"state_sha256":"24f1df760adad6161358ccf3f6ea6a15ab0a8af6f23094bdb7e12886626c951f"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"CKt08pYyciD6hG4z1c2IBo3cY1VCmDGibhApHlA11fGvW35FioABmE0W0vbLqR8BexsoWXWeoxNMV4YVawcHAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-02T19:12:18.161889Z","bundle_sha256":"84710cb556b8def90e178818689b7277d1ff60b4dfcad128986a44763291dfa3"}}