{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:7UXUUP7HMZU6USS5TBDFIZNOQZ","short_pith_number":"pith:7UXUUP7H","schema_version":"1.0","canonical_sha256":"fd2f4a3fe76669ea4a5d98465465ae86475f2d0390967e7397420add45c18a63","source":{"kind":"arxiv","id":"2606.29389","version":1},"attestation_state":"computed","paper":{"title":"Exploring the Cryptographic Limits of Transformer Networks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Andis Draguns, Christian Schroeder de Witt, Isaac Robinson, Philip Torr, Stefan Domunco","submitted_at":"2026-06-28T13:26:01Z","abstract_excerpt":"In recent work it has been shown that colluding AI agents can use steganographic methods to exchange malicious information. Whether a transformer can implement steganographic methods depends on what cryptographic functions it can implement, since a transformer that can implement a cryptographic function within its layers has source-free randomness access. Despite existing circuit-complexity results, no prior work maps specific cryptographic constructions to transformer architectures. As Merrill et al. have shown that saturated transformers can be seen as threshold circuits, we first generate t"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2606.29389","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-28T13:26:01Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"c61fce82e6e83f0fa7a0fd2f6b2d552bd98ae359f0ceee84529d211bbabac727","abstract_canon_sha256":"319e477d2132eedfc74ccb74b556dc37dbaf6c3459aee55351d79a5554cfd437"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-30T01:18:04.430837Z","signature_b64":"OIMH+gVgTkiRsjAjP2H0J05aW+e0dbYcxouBlkkbN+Hlhdo/nkpDFrwikh14KTDojgh2RyEfkAZltl0xzV56Aw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"fd2f4a3fe76669ea4a5d98465465ae86475f2d0390967e7397420add45c18a63","last_reissued_at":"2026-06-30T01:18:04.430320Z","signature_status":"signed_v1","first_computed_at":"2026-06-30T01:18:04.430320Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Exploring the Cryptographic Limits of Transformer Networks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Andis Draguns, Christian Schroeder de Witt, Isaac Robinson, Philip Torr, Stefan Domunco","submitted_at":"2026-06-28T13:26:01Z","abstract_excerpt":"In recent work it has been shown that colluding AI agents can use steganographic methods to exchange malicious information. Whether a transformer can implement steganographic methods depends on what cryptographic functions it can implement, since a transformer that can implement a cryptographic function within its layers has source-free randomness access. Despite existing circuit-complexity results, no prior work maps specific cryptographic constructions to transformer architectures. As Merrill et al. have shown that saturated transformers can be seen as threshold circuits, we first generate t"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.29389","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.29389/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2606.29389","created_at":"2026-06-30T01:18:04.430414+00:00"},{"alias_kind":"arxiv_version","alias_value":"2606.29389v1","created_at":"2026-06-30T01:18:04.430414+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.29389","created_at":"2026-06-30T01:18:04.430414+00:00"},{"alias_kind":"pith_short_12","alias_value":"7UXUUP7HMZU6","created_at":"2026-06-30T01:18:04.430414+00:00"},{"alias_kind":"pith_short_16","alias_value":"7UXUUP7HMZU6USS5","created_at":"2026-06-30T01:18:04.430414+00:00"},{"alias_kind":"pith_short_8","alias_value":"7UXUUP7H","created_at":"2026-06-30T01:18:04.430414+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ","json":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ.json","graph_json":"https://pith.science/api/pith-number/7UXUUP7HMZU6USS5TBDFIZNOQZ/graph.json","events_json":"https://pith.science/api/pith-number/7UXUUP7HMZU6USS5TBDFIZNOQZ/events.json","paper":"https://pith.science/paper/7UXUUP7H"},"agent_actions":{"view_html":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ","download_json":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ.json","view_paper":"https://pith.science/paper/7UXUUP7H","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2606.29389&json=true","fetch_graph":"https://pith.science/api/pith-number/7UXUUP7HMZU6USS5TBDFIZNOQZ/graph.json","fetch_events":"https://pith.science/api/pith-number/7UXUUP7HMZU6USS5TBDFIZNOQZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ/action/storage_attestation","attest_author":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ/action/author_attestation","sign_citation":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ/action/citation_signature","submit_replication":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ/action/replication_record"}},"created_at":"2026-06-30T01:18:04.430414+00:00","updated_at":"2026-06-30T01:18:04.430414+00:00"}