{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:7WMM5URAYGU46URGER542NMCST","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"41892e5b4dd2b168f76a324908dd0e5c10a66fbf8687237427e3d353a21ae01f","cross_cats_sorted":["cs.AI","cs.CR","cs.CV"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2025-02-25T04:23:59Z","title_canon_sha256":"aa6412854c3bdd091cd50c961f79e17773bf5944a9083578fae7d809d380891b"},"schema_version":"1.0","source":{"id":"2502.17832","kind":"arxiv","version":4}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2502.17832","created_at":"2026-05-28T01:04:26Z"},{"alias_kind":"arxiv_version","alias_value":"2502.17832v4","created_at":"2026-05-28T01:04:26Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2502.17832","created_at":"2026-05-28T01:04:26Z"},{"alias_kind":"pith_short_12","alias_value":"7WMM5URAYGU4","created_at":"2026-05-28T01:04:26Z"},{"alias_kind":"pith_short_16","alias_value":"7WMM5URAYGU46URG","created_at":"2026-05-28T01:04:26Z"},{"alias_kind":"pith_short_8","alias_value":"7WMM5URA","created_at":"2026-05-28T01:04:26Z"}],"graph_snapshots":[{"event_id":"sha256:5d8666d2de96bd262f38a7b3c3b9a243c0dcd9b1bad34411d5f98deeb0048588","target":"graph","created_at":"2026-05-28T01:04:26Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2502.17832/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Retrieval-augmented generation (RAG) has become a common practice in multimodal large language models (MLLM) to enhance factual grounding and reduce hallucination. Yet, its reliance on retrieval exposes MLLMs to knowledge poisoning attacks, in which adversaries deliberately inject malicious multimodal content into external knowledge bases to steer models toward generating incorrect or even harmful responses. We present MM-PoisonRAG, a framework to systematically study the vulnerability of multimodal RAG under knowledge poisoning. Specifically, we design two novel attack strategies: Localized P","authors_text":"Daniel Kang, Dimitrios Bralios, Heng Ji, Hyeonjeong Ha, Jeonghwan Kim, Kai-Wei Chang, Nanyun Peng, Qiusi Zhan, Saikrishna Sanniboina","cross_cats":["cs.AI","cs.CR","cs.CV"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2025-02-25T04:23:59Z","title":"MM-PoisonRAG: Disrupting Multimodal RAG with Local and Global Poisoning Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2502.17832","kind":"arxiv","version":4},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:3ac94646ccb4cd6d19aa7f3172a6961d122264b94ddb830d20cf964a7b31e4f8","target":"record","created_at":"2026-05-28T01:04:26Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"41892e5b4dd2b168f76a324908dd0e5c10a66fbf8687237427e3d353a21ae01f","cross_cats_sorted":["cs.AI","cs.CR","cs.CV"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2025-02-25T04:23:59Z","title_canon_sha256":"aa6412854c3bdd091cd50c961f79e17773bf5944a9083578fae7d809d380891b"},"schema_version":"1.0","source":{"id":"2502.17832","kind":"arxiv","version":4}},"canonical_sha256":"fd98ced220c1a9cf5226247bcd358294d9002ea391e607934a51c792ceb7f300","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"fd98ced220c1a9cf5226247bcd358294d9002ea391e607934a51c792ceb7f300","first_computed_at":"2026-05-28T01:04:26.932461Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-28T01:04:26.932461Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"0mElkx2GGVA6f3ZM+EuVIqkZNi+0xX+Nf2GCo86OHKJV6q5RglhE08fMtcaOPF4KPEGkNAzf9A9Km+zL12w2CQ==","signature_status":"signed_v1","signed_at":"2026-05-28T01:04:26.933124Z","signed_message":"canonical_sha256_bytes"},"source_id":"2502.17832","source_kind":"arxiv","source_version":4}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:3ac94646ccb4cd6d19aa7f3172a6961d122264b94ddb830d20cf964a7b31e4f8","sha256:5d8666d2de96bd262f38a7b3c3b9a243c0dcd9b1bad34411d5f98deeb0048588"],"state_sha256":"6d23db1bd3b3c6c76b94be92904d82a14e0aef31e55f45aa2ae0f272f4407bbd"}