{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:B6GRTJHV7Z2YS35YQC72FNRDZO","short_pith_number":"pith:B6GRTJHV","canonical_record":{"source":{"id":"2606.09700","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-08T16:21:34Z","cross_cats_sorted":["cs.HC","cs.LG"],"title_canon_sha256":"d08112ed4797b87c3f1be3546e3872b871f3d869f7632ea54bac471020a25268","abstract_canon_sha256":"4c778c6bd35c762fae5526c27a31b20c6baf1816aba982706415f980b161b7ae"},"schema_version":"1.0"},"canonical_sha256":"0f8d19a4f5fe75896fb880bfa2b623cba21d9d959432e6eba9ca46df661a791f","source":{"kind":"arxiv","id":"2606.09700","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.09700","created_at":"2026-06-09T02:09:04Z"},{"alias_kind":"arxiv_version","alias_value":"2606.09700v1","created_at":"2026-06-09T02:09:04Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.09700","created_at":"2026-06-09T02:09:04Z"},{"alias_kind":"pith_short_12","alias_value":"B6GRTJHV7Z2Y","created_at":"2026-06-09T02:09:04Z"},{"alias_kind":"pith_short_16","alias_value":"B6GRTJHV7Z2YS35Y","created_at":"2026-06-09T02:09:04Z"},{"alias_kind":"pith_short_8","alias_value":"B6GRTJHV","created_at":"2026-06-09T02:09:04Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:B6GRTJHV7Z2YS35YQC72FNRDZO","target":"record","payload":{"canonical_record":{"source":{"id":"2606.09700","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-08T16:21:34Z","cross_cats_sorted":["cs.HC","cs.LG"],"title_canon_sha256":"d08112ed4797b87c3f1be3546e3872b871f3d869f7632ea54bac471020a25268","abstract_canon_sha256":"4c778c6bd35c762fae5526c27a31b20c6baf1816aba982706415f980b161b7ae"},"schema_version":"1.0"},"canonical_sha256":"0f8d19a4f5fe75896fb880bfa2b623cba21d9d959432e6eba9ca46df661a791f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-09T02:09:04.610894Z","signature_b64":"dbcvrO4gITeCJmgQfyT25srZ3JHb2rwrM9B4ghuL2BJQgyHOTJ+RxYbSkC7X6XaCEK7RsKM7HS9HiwSmDjHECg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0f8d19a4f5fe75896fb880bfa2b623cba21d9d959432e6eba9ca46df661a791f","last_reissued_at":"2026-06-09T02:09:04.609917Z","signature_status":"signed_v1","first_computed_at":"2026-06-09T02:09:04.609917Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.09700","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T02:09:04Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"aHLug+Ca1H/vr59fmaZUqHk97PZc+UD5XkeXdM1Vk1AGe9D0G245NijjDWNmX2yASj2SC1Uq92wvjkwZZUP0BA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-03T07:34:20.398739Z"},"content_sha256":"8a5d6f982805020b4612da22b245e0edcd573ad4ca84bf14dce0bb94136e40b6","schema_version":"1.0","event_id":"sha256:8a5d6f982805020b4612da22b245e0edcd573ad4ca84bf14dce0bb94136e40b6"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:B6GRTJHV7Z2YS35YQC72FNRDZO","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"What the Eyes See, the LLMs Miss: Exploiting Human Perception for Adversarial Text Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.HC","cs.LG"],"primary_cat":"cs.CR","authors_text":"Doowon Kim, Joshua Lee, Lu Malloy, Meisam Mohammady, Qin Yang, Xiaohan Chang, Yuan Hong","submitted_at":"2026-06-08T16:21:34Z","abstract_excerpt":"Large language model (LLM)-powered content moderation systems have become a critical defense against harmful online content. However, these systems primarily operate on tokenized text and largely ignore the visual cues that humans naturally rely on when interpreting content. We show that this discrepancy creates a fundamental perceptual mismatch: content that is readily recognized as harmful by humans can become effectively invisible to automated moderation systems. To study this vulnerability, we introduce a class of Human-Perceptible Adversarial Attacks (HPAA), in which harmful expressions a"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.09700","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.09700/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T02:09:04Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"OGgl3VfZcnLCwfdfndaxD4CwfJODBlbKQCMAveRzNDjmEWxRmU+K4Tyj+kUhFgBzaJE7F3Ic9r/jYDm5/rLoCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-03T07:34:20.399117Z"},"content_sha256":"23e26c0fb895d91f69c379796886d6a2c44139058e318c1a70263846dde7210f","schema_version":"1.0","event_id":"sha256:23e26c0fb895d91f69c379796886d6a2c44139058e318c1a70263846dde7210f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/B6GRTJHV7Z2YS35YQC72FNRDZO/bundle.json","state_url":"https://pith.science/pith/B6GRTJHV7Z2YS35YQC72FNRDZO/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/B6GRTJHV7Z2YS35YQC72FNRDZO/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-03T07:34:20Z","links":{"resolver":"https://pith.science/pith/B6GRTJHV7Z2YS35YQC72FNRDZO","bundle":"https://pith.science/pith/B6GRTJHV7Z2YS35YQC72FNRDZO/bundle.json","state":"https://pith.science/pith/B6GRTJHV7Z2YS35YQC72FNRDZO/state.json","well_known_bundle":"https://pith.science/.well-known/pith/B6GRTJHV7Z2YS35YQC72FNRDZO/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:B6GRTJHV7Z2YS35YQC72FNRDZO","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"4c778c6bd35c762fae5526c27a31b20c6baf1816aba982706415f980b161b7ae","cross_cats_sorted":["cs.HC","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-08T16:21:34Z","title_canon_sha256":"d08112ed4797b87c3f1be3546e3872b871f3d869f7632ea54bac471020a25268"},"schema_version":"1.0","source":{"id":"2606.09700","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.09700","created_at":"2026-06-09T02:09:04Z"},{"alias_kind":"arxiv_version","alias_value":"2606.09700v1","created_at":"2026-06-09T02:09:04Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.09700","created_at":"2026-06-09T02:09:04Z"},{"alias_kind":"pith_short_12","alias_value":"B6GRTJHV7Z2Y","created_at":"2026-06-09T02:09:04Z"},{"alias_kind":"pith_short_16","alias_value":"B6GRTJHV7Z2YS35Y","created_at":"2026-06-09T02:09:04Z"},{"alias_kind":"pith_short_8","alias_value":"B6GRTJHV","created_at":"2026-06-09T02:09:04Z"}],"graph_snapshots":[{"event_id":"sha256:23e26c0fb895d91f69c379796886d6a2c44139058e318c1a70263846dde7210f","target":"graph","created_at":"2026-06-09T02:09:04Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.09700/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language model (LLM)-powered content moderation systems have become a critical defense against harmful online content. However, these systems primarily operate on tokenized text and largely ignore the visual cues that humans naturally rely on when interpreting content. We show that this discrepancy creates a fundamental perceptual mismatch: content that is readily recognized as harmful by humans can become effectively invisible to automated moderation systems. To study this vulnerability, we introduce a class of Human-Perceptible Adversarial Attacks (HPAA), in which harmful expressions a","authors_text":"Doowon Kim, Joshua Lee, Lu Malloy, Meisam Mohammady, Qin Yang, Xiaohan Chang, Yuan Hong","cross_cats":["cs.HC","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-08T16:21:34Z","title":"What the Eyes See, the LLMs Miss: Exploiting Human Perception for Adversarial Text Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.09700","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8a5d6f982805020b4612da22b245e0edcd573ad4ca84bf14dce0bb94136e40b6","target":"record","created_at":"2026-06-09T02:09:04Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"4c778c6bd35c762fae5526c27a31b20c6baf1816aba982706415f980b161b7ae","cross_cats_sorted":["cs.HC","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-08T16:21:34Z","title_canon_sha256":"d08112ed4797b87c3f1be3546e3872b871f3d869f7632ea54bac471020a25268"},"schema_version":"1.0","source":{"id":"2606.09700","kind":"arxiv","version":1}},"canonical_sha256":"0f8d19a4f5fe75896fb880bfa2b623cba21d9d959432e6eba9ca46df661a791f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"0f8d19a4f5fe75896fb880bfa2b623cba21d9d959432e6eba9ca46df661a791f","first_computed_at":"2026-06-09T02:09:04.609917Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-09T02:09:04.609917Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"dbcvrO4gITeCJmgQfyT25srZ3JHb2rwrM9B4ghuL2BJQgyHOTJ+RxYbSkC7X6XaCEK7RsKM7HS9HiwSmDjHECg==","signature_status":"signed_v1","signed_at":"2026-06-09T02:09:04.610894Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.09700","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8a5d6f982805020b4612da22b245e0edcd573ad4ca84bf14dce0bb94136e40b6","sha256:23e26c0fb895d91f69c379796886d6a2c44139058e318c1a70263846dde7210f"],"state_sha256":"3bfe2aa58a893481a2c044ed6f3ec881fde8206901ad663f422b7d1aa6db890d"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wmkHhbZCv5T6oUsOOmfY4hR7oVgUEy4DWuXVkKtjzHtz4d44NGE0yHvp4Hv0UpezgIKbdSyy+EeN3kBxS5ESDA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-03T07:34:20.401194Z","bundle_sha256":"cb9b2188ac018d8dfddc187d23192c1a01f34d9295e1667bc9db16198484ff67"}}