{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:7UXUUP7HMZU6USS5TBDFIZNOQZ","short_pith_number":"pith:7UXUUP7H","canonical_record":{"source":{"id":"2606.29389","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-28T13:26:01Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"c61fce82e6e83f0fa7a0fd2f6b2d552bd98ae359f0ceee84529d211bbabac727","abstract_canon_sha256":"319e477d2132eedfc74ccb74b556dc37dbaf6c3459aee55351d79a5554cfd437"},"schema_version":"1.0"},"canonical_sha256":"fd2f4a3fe76669ea4a5d98465465ae86475f2d0390967e7397420add45c18a63","source":{"kind":"arxiv","id":"2606.29389","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.29389","created_at":"2026-06-30T01:18:04Z"},{"alias_kind":"arxiv_version","alias_value":"2606.29389v1","created_at":"2026-06-30T01:18:04Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.29389","created_at":"2026-06-30T01:18:04Z"},{"alias_kind":"pith_short_12","alias_value":"7UXUUP7HMZU6","created_at":"2026-06-30T01:18:04Z"},{"alias_kind":"pith_short_16","alias_value":"7UXUUP7HMZU6USS5","created_at":"2026-06-30T01:18:04Z"},{"alias_kind":"pith_short_8","alias_value":"7UXUUP7H","created_at":"2026-06-30T01:18:04Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:7UXUUP7HMZU6USS5TBDFIZNOQZ","target":"record","payload":{"canonical_record":{"source":{"id":"2606.29389","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-28T13:26:01Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"c61fce82e6e83f0fa7a0fd2f6b2d552bd98ae359f0ceee84529d211bbabac727","abstract_canon_sha256":"319e477d2132eedfc74ccb74b556dc37dbaf6c3459aee55351d79a5554cfd437"},"schema_version":"1.0"},"canonical_sha256":"fd2f4a3fe76669ea4a5d98465465ae86475f2d0390967e7397420add45c18a63","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-30T01:18:04.430837Z","signature_b64":"OIMH+gVgTkiRsjAjP2H0J05aW+e0dbYcxouBlkkbN+Hlhdo/nkpDFrwikh14KTDojgh2RyEfkAZltl0xzV56Aw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"fd2f4a3fe76669ea4a5d98465465ae86475f2d0390967e7397420add45c18a63","last_reissued_at":"2026-06-30T01:18:04.430320Z","signature_status":"signed_v1","first_computed_at":"2026-06-30T01:18:04.430320Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.29389","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-30T01:18:04Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"LRUJD4cxmfBti2h6BPn2hTG6z7SqKCVfCt3LD1Ug4RHH/mqP/CDrtjOhQWiamMr6ZubRJpli+haPQm64moUxAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T13:59:08.363825Z"},"content_sha256":"b9cd9f2fceb359bab3781e3bd4f042d376f3a2a316c45436d69008ebf28c392e","schema_version":"1.0","event_id":"sha256:b9cd9f2fceb359bab3781e3bd4f042d376f3a2a316c45436d69008ebf28c392e"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:7UXUUP7HMZU6USS5TBDFIZNOQZ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Exploring the Cryptographic Limits of Transformer Networks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Andis Draguns, Christian Schroeder de Witt, Isaac Robinson, Philip Torr, Stefan Domunco","submitted_at":"2026-06-28T13:26:01Z","abstract_excerpt":"In recent work it has been shown that colluding AI agents can use steganographic methods to exchange malicious information. Whether a transformer can implement steganographic methods depends on what cryptographic functions it can implement, since a transformer that can implement a cryptographic function within its layers has source-free randomness access. Despite existing circuit-complexity results, no prior work maps specific cryptographic constructions to transformer architectures. As Merrill et al. have shown that saturated transformers can be seen as threshold circuits, we first generate t"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.29389","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.29389/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-30T01:18:04Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/QYFAxTfsu+mXXuUBNumb4YK5tEJCJu5VpK8Mu4sSn1DThICS/eNJIvR07rsT4+gaMVtsUqazl8TqPwau9l7Dw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T13:59:08.364193Z"},"content_sha256":"b79196771514e8d0bdb3fb61dd8f6d092c2b8ffb1ecf9408ffc345645abb67de","schema_version":"1.0","event_id":"sha256:b79196771514e8d0bdb3fb61dd8f6d092c2b8ffb1ecf9408ffc345645abb67de"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ/bundle.json","state_url":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-30T13:59:08Z","links":{"resolver":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ","bundle":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ/bundle.json","state":"https://pith.science/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/7UXUUP7HMZU6USS5TBDFIZNOQZ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:7UXUUP7HMZU6USS5TBDFIZNOQZ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"319e477d2132eedfc74ccb74b556dc37dbaf6c3459aee55351d79a5554cfd437","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-28T13:26:01Z","title_canon_sha256":"c61fce82e6e83f0fa7a0fd2f6b2d552bd98ae359f0ceee84529d211bbabac727"},"schema_version":"1.0","source":{"id":"2606.29389","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.29389","created_at":"2026-06-30T01:18:04Z"},{"alias_kind":"arxiv_version","alias_value":"2606.29389v1","created_at":"2026-06-30T01:18:04Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.29389","created_at":"2026-06-30T01:18:04Z"},{"alias_kind":"pith_short_12","alias_value":"7UXUUP7HMZU6","created_at":"2026-06-30T01:18:04Z"},{"alias_kind":"pith_short_16","alias_value":"7UXUUP7HMZU6USS5","created_at":"2026-06-30T01:18:04Z"},{"alias_kind":"pith_short_8","alias_value":"7UXUUP7H","created_at":"2026-06-30T01:18:04Z"}],"graph_snapshots":[{"event_id":"sha256:b79196771514e8d0bdb3fb61dd8f6d092c2b8ffb1ecf9408ffc345645abb67de","target":"graph","created_at":"2026-06-30T01:18:04Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.29389/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"In recent work it has been shown that colluding AI agents can use steganographic methods to exchange malicious information. Whether a transformer can implement steganographic methods depends on what cryptographic functions it can implement, since a transformer that can implement a cryptographic function within its layers has source-free randomness access. Despite existing circuit-complexity results, no prior work maps specific cryptographic constructions to transformer architectures. As Merrill et al. have shown that saturated transformers can be seen as threshold circuits, we first generate t","authors_text":"Andis Draguns, Christian Schroeder de Witt, Isaac Robinson, Philip Torr, Stefan Domunco","cross_cats":["cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-28T13:26:01Z","title":"Exploring the Cryptographic Limits of Transformer Networks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.29389","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:b9cd9f2fceb359bab3781e3bd4f042d376f3a2a316c45436d69008ebf28c392e","target":"record","created_at":"2026-06-30T01:18:04Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"319e477d2132eedfc74ccb74b556dc37dbaf6c3459aee55351d79a5554cfd437","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-28T13:26:01Z","title_canon_sha256":"c61fce82e6e83f0fa7a0fd2f6b2d552bd98ae359f0ceee84529d211bbabac727"},"schema_version":"1.0","source":{"id":"2606.29389","kind":"arxiv","version":1}},"canonical_sha256":"fd2f4a3fe76669ea4a5d98465465ae86475f2d0390967e7397420add45c18a63","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"fd2f4a3fe76669ea4a5d98465465ae86475f2d0390967e7397420add45c18a63","first_computed_at":"2026-06-30T01:18:04.430320Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-30T01:18:04.430320Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"OIMH+gVgTkiRsjAjP2H0J05aW+e0dbYcxouBlkkbN+Hlhdo/nkpDFrwikh14KTDojgh2RyEfkAZltl0xzV56Aw==","signature_status":"signed_v1","signed_at":"2026-06-30T01:18:04.430837Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.29389","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:b9cd9f2fceb359bab3781e3bd4f042d376f3a2a316c45436d69008ebf28c392e","sha256:b79196771514e8d0bdb3fb61dd8f6d092c2b8ffb1ecf9408ffc345645abb67de"],"state_sha256":"31d4d3567590ff0d9daf046d502e19f38008e2454391782b3beeb08b66b0c87e"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hoFIScH+aPf49zmTLZrIvzGHOZ5k/U+/fFvWQKDXh7kMsBb0/Sqz7n3KJNpDBhrV07MpyqB7byFX168XWTplDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-30T13:59:08.366143Z","bundle_sha256":"e1460d61958b43495dbb17447e04f521478cd0d13e344257fd41f01cd7285e94"}}