{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:7U3FZJUMND7XR5A6MFW5JPJRWU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"944cf6494615681925b7241fa67065b3d30e06b18d81ea364fd12d229e61a9b0","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T04:20:00Z","title_canon_sha256":"80d7c177d914d798270a2d25aa8db95052b0315bf1debd89b6a626435bcacad7"},"schema_version":"1.0","source":{"id":"2606.18673","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.18673","created_at":"2026-06-19T16:11:44Z"},{"alias_kind":"arxiv_version","alias_value":"2606.18673v1","created_at":"2026-06-19T16:11:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.18673","created_at":"2026-06-19T16:11:44Z"},{"alias_kind":"pith_short_12","alias_value":"7U3FZJUMND7X","created_at":"2026-06-19T16:11:44Z"},{"alias_kind":"pith_short_16","alias_value":"7U3FZJUMND7XR5A6","created_at":"2026-06-19T16:11:44Z"},{"alias_kind":"pith_short_8","alias_value":"7U3FZJUM","created_at":"2026-06-19T16:11:44Z"}],"graph_snapshots":[{"event_id":"sha256:0e1c1e044d17eb0124a373bbfc83690e6c15e097bf38cc7346e740d6e804c3ea","target":"graph","created_at":"2026-06-19T16:11:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.18673/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language model (LLM)-based applications rely on system prompts to encode core logic and developer-defined constraints, making these prompts important intellectual property. However, system prompts are vulnerable to prompt leaking attacks. Although prior work has shown such attacks in controlled settings, their prevalence, causes, and defenses in real-world deployments remain unclear.\n  This paper presents a systematic study of prompt leaking in real-world LLM-based applications. We measure 1,200 applications across six major commercial platforms and find that over 80% of deployments leak","authors_text":"Chong Fu, Qingming Li, Rui Zeng, Shouling Ji, Tianyu Du, Tong Zhang, Wenzhi Chen, Yong Yang, Zonghui Wang","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T04:20:00Z","title":"Understanding and Mitigating Prompt Leaking Attacks in Real-World LLM-Based Applications"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.18673","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:a1ce6d7aa1afda818986a17faea0905efecfc3be79ee75ac2cb7ed9927cd42f1","target":"record","created_at":"2026-06-19T16:11:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"944cf6494615681925b7241fa67065b3d30e06b18d81ea364fd12d229e61a9b0","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T04:20:00Z","title_canon_sha256":"80d7c177d914d798270a2d25aa8db95052b0315bf1debd89b6a626435bcacad7"},"schema_version":"1.0","source":{"id":"2606.18673","kind":"arxiv","version":1}},"canonical_sha256":"fd365ca68c68ff78f41e616dd4bd31b5399f81cc3272e339ee0c8d2cf49feaed","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"fd365ca68c68ff78f41e616dd4bd31b5399f81cc3272e339ee0c8d2cf49feaed","first_computed_at":"2026-06-19T16:11:44.242772Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-19T16:11:44.242772Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"lz/SwmEUFRwiN4j0bZXYw4SxKzqELG1TMnvxsdBHbxVK7bQ54lIrzroYKqT+aoWztpYb3DqvAJXRkwFZT/PWAA==","signature_status":"signed_v1","signed_at":"2026-06-19T16:11:44.243119Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.18673","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:a1ce6d7aa1afda818986a17faea0905efecfc3be79ee75ac2cb7ed9927cd42f1","sha256:0e1c1e044d17eb0124a373bbfc83690e6c15e097bf38cc7346e740d6e804c3ea"],"state_sha256":"905b3959fde27a0701ac7d38a93bad2ed31d5e0bd458f22c7ee196c98d4db232"}