{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:AZ2NQUKUFMNSDILWS7ML7JRNTW","short_pith_number":"pith:AZ2NQUKU","canonical_record":{"source":{"id":"2605.22258","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-21T10:01:03Z","cross_cats_sorted":[],"title_canon_sha256":"61bd177df0de3a1297f793c2adac953e547356691a367db559583362264ba5ac","abstract_canon_sha256":"e44b85b17ea51d4dbdbd162e0591f5e06dc0b4b8a46b160b1b2aac5bd72da8b5"},"schema_version":"1.0"},"canonical_sha256":"0674d851542b1b21a17697d8bfa62d9da81a42286ec8635e1c65c06dac4b4638","source":{"kind":"arxiv","id":"2605.22258","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.22258","created_at":"2026-05-22T01:04:34Z"},{"alias_kind":"arxiv_version","alias_value":"2605.22258v1","created_at":"2026-05-22T01:04:34Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.22258","created_at":"2026-05-22T01:04:34Z"},{"alias_kind":"pith_short_12","alias_value":"AZ2NQUKUFMNS","created_at":"2026-05-22T01:04:34Z"},{"alias_kind":"pith_short_16","alias_value":"AZ2NQUKUFMNSDILW","created_at":"2026-05-22T01:04:34Z"},{"alias_kind":"pith_short_8","alias_value":"AZ2NQUKU","created_at":"2026-05-22T01:04:34Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:AZ2NQUKUFMNSDILWS7ML7JRNTW","target":"record","payload":{"canonical_record":{"source":{"id":"2605.22258","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-21T10:01:03Z","cross_cats_sorted":[],"title_canon_sha256":"61bd177df0de3a1297f793c2adac953e547356691a367db559583362264ba5ac","abstract_canon_sha256":"e44b85b17ea51d4dbdbd162e0591f5e06dc0b4b8a46b160b1b2aac5bd72da8b5"},"schema_version":"1.0"},"canonical_sha256":"0674d851542b1b21a17697d8bfa62d9da81a42286ec8635e1c65c06dac4b4638","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-22T01:04:34.868337Z","signature_b64":"sNsHmDh9E5RosXKLUC7j6+U2uXOVFUo199tg8O/xSfSOT0hhyjtCPLqYPfEB1Mg1HYca6W6U8YYKgZliud7yDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0674d851542b1b21a17697d8bfa62d9da81a42286ec8635e1c65c06dac4b4638","last_reissued_at":"2026-05-22T01:04:34.867515Z","signature_status":"signed_v1","first_computed_at":"2026-05-22T01:04:34.867515Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.22258","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:04:34Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Qp39PUYRU0QIYqo4PdfH5NoHXhbbRWRnqTWWF/BNOeFXpB3FX1dDeldTpxDo5/YlP49lGLss93VLDYkQtsLFCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T20:08:37.833712Z"},"content_sha256":"8b12e26d2851015a5f58ba6a1e4008bd78dd759aced4c1c30948ecc6243c8304","schema_version":"1.0","event_id":"sha256:8b12e26d2851015a5f58ba6a1e4008bd78dd759aced4c1c30948ecc6243c8304"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:AZ2NQUKUFMNSDILWS7ML7JRNTW","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Harder to Defend: Towards Chinese Toxicity Attacks via Implicit Enhancement and Obfuscation Rewriting","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CL","authors_text":"Bo Xu, Hongbo Wang, Hongfei Lin, Jingyi Kang, Junyu Lu, Linlin Zong, Roy Ka-Wei Lee","submitted_at":"2026-05-21T10:01:03Z","abstract_excerpt":"Large language models (LLMs) require robust toxicity evaluation beyond explicit wording. This setting remains underexplored in Chinese, where toxicity may combine semantic indirectness with surface obfuscation. We introduce Chinese Implicit Toxicity Attack (CITA), a controlled red-team evaluation and defense-data generation framework, not a deployable evasion tool. CITA uses three stages: (i) Harmful Intent Learning, (ii) Implicit Toxicity Enhancement, and (iii) Obfuscation Variant Rewriting, to preserve harmful intent, increase implicitness, and add controlled surface variants. On CITA-genera"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.22258","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.22258/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:04:34Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"QZLwjEjwZ19tlokJJS8wjha1KBN4mxgFEINEkoQWSOT8bl6E53fTKcVY9oTR+AA5KwgUfw+H7TQeGuuC6CRpDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T20:08:37.834125Z"},"content_sha256":"5fec3e13eaf4a6d5ac42c87928c2b12cb74568eebb4d74245367ba1a4e793402","schema_version":"1.0","event_id":"sha256:5fec3e13eaf4a6d5ac42c87928c2b12cb74568eebb4d74245367ba1a4e793402"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/AZ2NQUKUFMNSDILWS7ML7JRNTW/bundle.json","state_url":"https://pith.science/pith/AZ2NQUKUFMNSDILWS7ML7JRNTW/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/AZ2NQUKUFMNSDILWS7ML7JRNTW/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T20:08:37Z","links":{"resolver":"https://pith.science/pith/AZ2NQUKUFMNSDILWS7ML7JRNTW","bundle":"https://pith.science/pith/AZ2NQUKUFMNSDILWS7ML7JRNTW/bundle.json","state":"https://pith.science/pith/AZ2NQUKUFMNSDILWS7ML7JRNTW/state.json","well_known_bundle":"https://pith.science/.well-known/pith/AZ2NQUKUFMNSDILWS7ML7JRNTW/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:AZ2NQUKUFMNSDILWS7ML7JRNTW","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e44b85b17ea51d4dbdbd162e0591f5e06dc0b4b8a46b160b1b2aac5bd72da8b5","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-21T10:01:03Z","title_canon_sha256":"61bd177df0de3a1297f793c2adac953e547356691a367db559583362264ba5ac"},"schema_version":"1.0","source":{"id":"2605.22258","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.22258","created_at":"2026-05-22T01:04:34Z"},{"alias_kind":"arxiv_version","alias_value":"2605.22258v1","created_at":"2026-05-22T01:04:34Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.22258","created_at":"2026-05-22T01:04:34Z"},{"alias_kind":"pith_short_12","alias_value":"AZ2NQUKUFMNS","created_at":"2026-05-22T01:04:34Z"},{"alias_kind":"pith_short_16","alias_value":"AZ2NQUKUFMNSDILW","created_at":"2026-05-22T01:04:34Z"},{"alias_kind":"pith_short_8","alias_value":"AZ2NQUKU","created_at":"2026-05-22T01:04:34Z"}],"graph_snapshots":[{"event_id":"sha256:5fec3e13eaf4a6d5ac42c87928c2b12cb74568eebb4d74245367ba1a4e793402","target":"graph","created_at":"2026-05-22T01:04:34Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.22258/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language models (LLMs) require robust toxicity evaluation beyond explicit wording. This setting remains underexplored in Chinese, where toxicity may combine semantic indirectness with surface obfuscation. We introduce Chinese Implicit Toxicity Attack (CITA), a controlled red-team evaluation and defense-data generation framework, not a deployable evasion tool. CITA uses three stages: (i) Harmful Intent Learning, (ii) Implicit Toxicity Enhancement, and (iii) Obfuscation Variant Rewriting, to preserve harmful intent, increase implicitness, and add controlled surface variants. On CITA-genera","authors_text":"Bo Xu, Hongbo Wang, Hongfei Lin, Jingyi Kang, Junyu Lu, Linlin Zong, Roy Ka-Wei Lee","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-21T10:01:03Z","title":"Harder to Defend: Towards Chinese Toxicity Attacks via Implicit Enhancement and Obfuscation Rewriting"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.22258","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8b12e26d2851015a5f58ba6a1e4008bd78dd759aced4c1c30948ecc6243c8304","target":"record","created_at":"2026-05-22T01:04:34Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e44b85b17ea51d4dbdbd162e0591f5e06dc0b4b8a46b160b1b2aac5bd72da8b5","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-21T10:01:03Z","title_canon_sha256":"61bd177df0de3a1297f793c2adac953e547356691a367db559583362264ba5ac"},"schema_version":"1.0","source":{"id":"2605.22258","kind":"arxiv","version":1}},"canonical_sha256":"0674d851542b1b21a17697d8bfa62d9da81a42286ec8635e1c65c06dac4b4638","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"0674d851542b1b21a17697d8bfa62d9da81a42286ec8635e1c65c06dac4b4638","first_computed_at":"2026-05-22T01:04:34.867515Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-22T01:04:34.867515Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"sNsHmDh9E5RosXKLUC7j6+U2uXOVFUo199tg8O/xSfSOT0hhyjtCPLqYPfEB1Mg1HYca6W6U8YYKgZliud7yDg==","signature_status":"signed_v1","signed_at":"2026-05-22T01:04:34.868337Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.22258","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8b12e26d2851015a5f58ba6a1e4008bd78dd759aced4c1c30948ecc6243c8304","sha256:5fec3e13eaf4a6d5ac42c87928c2b12cb74568eebb4d74245367ba1a4e793402"],"state_sha256":"edc442edf94051f2a766b7790a51f0f61014bc4448a11bac1a02b68b7214bcca"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8eFg9s9007xAInHXM1ZkI3lf9lFGvTeSjqU3zxJK6yyAWT3FQ8E/SjM5N3s2fZGxThyVbGbs7MAfHZOMuUUICw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T20:08:37.837599Z","bundle_sha256":"e035a5b7d1ef0534760414799efa8bcb3e79a9283ab276d29bac0fc165e95f9c"}}