{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:7UJUQX6QN553OVO67PHABCVTNO","short_pith_number":"pith:7UJUQX6Q","canonical_record":{"source":{"id":"2510.22963","kind":"arxiv","version":4},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2025-10-27T03:37:41Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"33ead21849095eccde0a573c721b014f208e33edb19aa64da535a77a75ef1d94","abstract_canon_sha256":"906a55fb7ac4880b484252eda628d015f1dd1ea5407427faa24153768ff26cb9"},"schema_version":"1.0"},"canonical_sha256":"fd13485fd06f7bb755defbce008ab36bbf59b3dd22dd0d6ca5a2f0474304dcc7","source":{"kind":"arxiv","id":"2510.22963","version":4},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2510.22963","created_at":"2026-06-23T01:12:47Z"},{"alias_kind":"arxiv_version","alias_value":"2510.22963v4","created_at":"2026-06-23T01:12:47Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2510.22963","created_at":"2026-06-23T01:12:47Z"},{"alias_kind":"pith_short_12","alias_value":"7UJUQX6QN553","created_at":"2026-06-23T01:12:47Z"},{"alias_kind":"pith_short_16","alias_value":"7UJUQX6QN553OVO6","created_at":"2026-06-23T01:12:47Z"},{"alias_kind":"pith_short_8","alias_value":"7UJUQX6Q","created_at":"2026-06-23T01:12:47Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:7UJUQX6QN553OVO67PHABCVTNO","target":"record","payload":{"canonical_record":{"source":{"id":"2510.22963","kind":"arxiv","version":4},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2025-10-27T03:37:41Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"33ead21849095eccde0a573c721b014f208e33edb19aa64da535a77a75ef1d94","abstract_canon_sha256":"906a55fb7ac4880b484252eda628d015f1dd1ea5407427faa24153768ff26cb9"},"schema_version":"1.0"},"canonical_sha256":"fd13485fd06f7bb755defbce008ab36bbf59b3dd22dd0d6ca5a2f0474304dcc7","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-23T01:12:47.940420Z","signature_b64":"jI6JgDkm6rH66sYPVLdjcAs1/JWesuUzf2eWSedAj7QfW4G4Ial4Y3fYwsenZowx95l3ERbC/woIr6NsbyAIDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"fd13485fd06f7bb755defbce008ab36bbf59b3dd22dd0d6ca5a2f0474304dcc7","last_reissued_at":"2026-06-23T01:12:47.939839Z","signature_status":"signed_v1","first_computed_at":"2026-06-23T01:12:47.939839Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2510.22963","source_version":4,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-23T01:12:47Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Wv/Xh1tZQeAsjpaGORH/Kfmn4qyLsqvNFAH7+TT0UmLafP1nzYTn6wYbWLCjHiIfHHKWZX0A/d9gGMXP8dJJCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-01T07:20:22.843093Z"},"content_sha256":"d956c053f24d51b0eb6620188cd79f939c39f11228cfc6d572ad3b2f7c5253ab","schema_version":"1.0","event_id":"sha256:d956c053f24d51b0eb6620188cd79f939c39f11228cfc6d572ad3b2f7c5253ab"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:7UJUQX6QN553OVO67PHABCVTNO","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Dongdong She, Yuchong Xie, Zesen Liu, Zhixiang Zhang","submitted_at":"2025-10-27T03:37:41Z","abstract_excerpt":"Prompt compression is increasingly deployed in LLM agents to reduce latency and cost, but it also determines what the backend LLM ultimately sees. We show that, when trusted and untrusted inputs are compressed under a shared budget, this lossy transformation creates a new attack surface: by perturbing only untrusted inputs before compression, an adversary can cause the compressor to discard task-critical evidence or safety guardrails before inference. Unlike prompt injection, jailbreaks, or RAG poisoning, the attack target is the compressor rather than the backend LLM; the perturbation need no"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2510.22963","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2510.22963/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-23T01:12:47Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"fKdL+TzXfy8+91kGW0PhBVjOsdyziYi6KJW4SblB9qPehNQDe7v/ZC07PRR2tvH0FhU4F5pPW5QMYBDL8W3nBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-01T07:20:22.843504Z"},"content_sha256":"6ee1e11ac4e8d237868b7faa3fd9ef4fdad568872d4be5a4d183478b9d1c228a","schema_version":"1.0","event_id":"sha256:6ee1e11ac4e8d237868b7faa3fd9ef4fdad568872d4be5a4d183478b9d1c228a"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/7UJUQX6QN553OVO67PHABCVTNO/bundle.json","state_url":"https://pith.science/pith/7UJUQX6QN553OVO67PHABCVTNO/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/7UJUQX6QN553OVO67PHABCVTNO/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-01T07:20:22Z","links":{"resolver":"https://pith.science/pith/7UJUQX6QN553OVO67PHABCVTNO","bundle":"https://pith.science/pith/7UJUQX6QN553OVO67PHABCVTNO/bundle.json","state":"https://pith.science/pith/7UJUQX6QN553OVO67PHABCVTNO/state.json","well_known_bundle":"https://pith.science/.well-known/pith/7UJUQX6QN553OVO67PHABCVTNO/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:7UJUQX6QN553OVO67PHABCVTNO","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"906a55fb7ac4880b484252eda628d015f1dd1ea5407427faa24153768ff26cb9","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2025-10-27T03:37:41Z","title_canon_sha256":"33ead21849095eccde0a573c721b014f208e33edb19aa64da535a77a75ef1d94"},"schema_version":"1.0","source":{"id":"2510.22963","kind":"arxiv","version":4}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2510.22963","created_at":"2026-06-23T01:12:47Z"},{"alias_kind":"arxiv_version","alias_value":"2510.22963v4","created_at":"2026-06-23T01:12:47Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2510.22963","created_at":"2026-06-23T01:12:47Z"},{"alias_kind":"pith_short_12","alias_value":"7UJUQX6QN553","created_at":"2026-06-23T01:12:47Z"},{"alias_kind":"pith_short_16","alias_value":"7UJUQX6QN553OVO6","created_at":"2026-06-23T01:12:47Z"},{"alias_kind":"pith_short_8","alias_value":"7UJUQX6Q","created_at":"2026-06-23T01:12:47Z"}],"graph_snapshots":[{"event_id":"sha256:6ee1e11ac4e8d237868b7faa3fd9ef4fdad568872d4be5a4d183478b9d1c228a","target":"graph","created_at":"2026-06-23T01:12:47Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2510.22963/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Prompt compression is increasingly deployed in LLM agents to reduce latency and cost, but it also determines what the backend LLM ultimately sees. We show that, when trusted and untrusted inputs are compressed under a shared budget, this lossy transformation creates a new attack surface: by perturbing only untrusted inputs before compression, an adversary can cause the compressor to discard task-critical evidence or safety guardrails before inference. Unlike prompt injection, jailbreaks, or RAG poisoning, the attack target is the compressor rather than the backend LLM; the perturbation need no","authors_text":"Dongdong She, Yuchong Xie, Zesen Liu, Zhixiang Zhang","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2025-10-27T03:37:41Z","title":"When Compression Becomes an Attack Surface: Black-Box Attacks on Prompt-Compressed LLM Agents"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2510.22963","kind":"arxiv","version":4},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:d956c053f24d51b0eb6620188cd79f939c39f11228cfc6d572ad3b2f7c5253ab","target":"record","created_at":"2026-06-23T01:12:47Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"906a55fb7ac4880b484252eda628d015f1dd1ea5407427faa24153768ff26cb9","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2025-10-27T03:37:41Z","title_canon_sha256":"33ead21849095eccde0a573c721b014f208e33edb19aa64da535a77a75ef1d94"},"schema_version":"1.0","source":{"id":"2510.22963","kind":"arxiv","version":4}},"canonical_sha256":"fd13485fd06f7bb755defbce008ab36bbf59b3dd22dd0d6ca5a2f0474304dcc7","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"fd13485fd06f7bb755defbce008ab36bbf59b3dd22dd0d6ca5a2f0474304dcc7","first_computed_at":"2026-06-23T01:12:47.939839Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-23T01:12:47.939839Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"jI6JgDkm6rH66sYPVLdjcAs1/JWesuUzf2eWSedAj7QfW4G4Ial4Y3fYwsenZowx95l3ERbC/woIr6NsbyAIDg==","signature_status":"signed_v1","signed_at":"2026-06-23T01:12:47.940420Z","signed_message":"canonical_sha256_bytes"},"source_id":"2510.22963","source_kind":"arxiv","source_version":4}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:d956c053f24d51b0eb6620188cd79f939c39f11228cfc6d572ad3b2f7c5253ab","sha256:6ee1e11ac4e8d237868b7faa3fd9ef4fdad568872d4be5a4d183478b9d1c228a"],"state_sha256":"3c8a296859168a161ca82671d153133231ed5c021ab78c44cc21fac0bd1339ab"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hAyHRVVBVkK856iPKb4Mn8Q59WPMg5mzPxbpMgqviisiJ/Z0pDbei55ontYYPfvfyT/pEXsR6doaXLIFvCzEDw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-01T07:20:22.845869Z","bundle_sha256":"fc3c3c4400cac437725c33f3b3c28af90057f80a6ebf5176ff3abdd2ade14108"}}