{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:CDHHOKVQXSR24EGP2HSBAX3SEX","short_pith_number":"pith:CDHHOKVQ","canonical_record":{"source":{"id":"2607.01277","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T06:36:29Z","cross_cats_sorted":[],"title_canon_sha256":"fa4b9a87475cbf6b49df757703329eab61c281690621e4447b7aa2d6bf0436b2","abstract_canon_sha256":"547645c8b9b34df022bf1816a95cc315b14058ab99dca636025820dfe6f1407e"},"schema_version":"1.0"},"canonical_sha256":"10ce772ab0bca3ae10cfd1e4105f7225fa6e20b156ad524f3e6f8876b44a3f7f","source":{"kind":"arxiv","id":"2607.01277","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2607.01277","created_at":"2026-07-03T00:16:56Z"},{"alias_kind":"arxiv_version","alias_value":"2607.01277v1","created_at":"2026-07-03T00:16:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.01277","created_at":"2026-07-03T00:16:56Z"},{"alias_kind":"pith_short_12","alias_value":"CDHHOKVQXSR2","created_at":"2026-07-03T00:16:56Z"},{"alias_kind":"pith_short_16","alias_value":"CDHHOKVQXSR24EGP","created_at":"2026-07-03T00:16:56Z"},{"alias_kind":"pith_short_8","alias_value":"CDHHOKVQ","created_at":"2026-07-03T00:16:56Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:CDHHOKVQXSR24EGP2HSBAX3SEX","target":"record","payload":{"canonical_record":{"source":{"id":"2607.01277","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T06:36:29Z","cross_cats_sorted":[],"title_canon_sha256":"fa4b9a87475cbf6b49df757703329eab61c281690621e4447b7aa2d6bf0436b2","abstract_canon_sha256":"547645c8b9b34df022bf1816a95cc315b14058ab99dca636025820dfe6f1407e"},"schema_version":"1.0"},"canonical_sha256":"10ce772ab0bca3ae10cfd1e4105f7225fa6e20b156ad524f3e6f8876b44a3f7f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-03T00:16:56.103152Z","signature_b64":"mN1RbBLogRZVAZz6+vVENoqL0g4Sn9NX0Z7LaxaNhJ3Pn8vforYX7LEmZKnb4qScU9Ru/i4YCOm6ZKVvUaSkCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"10ce772ab0bca3ae10cfd1e4105f7225fa6e20b156ad524f3e6f8876b44a3f7f","last_reissued_at":"2026-07-03T00:16:56.102750Z","signature_status":"signed_v1","first_computed_at":"2026-07-03T00:16:56.102750Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2607.01277","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-03T00:16:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Fs9Cj1CJ8xl33POhtquQySkD1ZlhjXqd/cTjGT2GJwD9kV4Ak0k/HYmbjt6emzbUe1YZufiERyJ/5Hgc3ZbcBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-04T09:47:29.771948Z"},"content_sha256":"dc6b970318c21396e65d408934226dbe34b295dc31e6695d6de70fa96d44f40a","schema_version":"1.0","event_id":"sha256:dc6b970318c21396e65d408934226dbe34b295dc31e6695d6de70fa96d44f40a"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:CDHHOKVQXSR24EGP2HSBAX3SEX","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Cognitive Firewall: A Proactive, Zero-Trust, Multi-Gate Framework for LLM Safety","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Jiacheng Li, Michele Guida, Noorbakhsh Amiri Golilarz, Ruslan Shikhhamzayev, Shahram Rahimi, Sindhuja Penchala, Stefano Iannucci","submitted_at":"2026-07-01T06:36:29Z","abstract_excerpt":"Large language models (LLMs) can be induced to produce harmful content through multi turn strategies in which no single user message appears clearly unsafe. Existing runtime safeguards commonly evaluate prompts or responses as isolated messages, which limits their ability to recover ac-cumulated intent, verify asserted authority, or detect harmful objectives decomposed across a dialogue. This paper presents the Cognitive Firewall, a proactive runtime oversight framework that interposes an independent oversight model between a user and a protected target mod l. The framework decomposes safety a"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.01277","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2607.01277/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-03T00:16:56Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"xAhwq+3q6f30x9WdbgWKHI3jXD6AiZvX7+VZloPn4xcdYZyMVbpsaqzSK30eaOQMBaKkuxZ9pN+2+SfpHbvNDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-04T09:47:29.772338Z"},"content_sha256":"547abc09d35eb14135c45fd08dd193a4e4d829caf9a403bff318b774386b4d35","schema_version":"1.0","event_id":"sha256:547abc09d35eb14135c45fd08dd193a4e4d829caf9a403bff318b774386b4d35"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/CDHHOKVQXSR24EGP2HSBAX3SEX/bundle.json","state_url":"https://pith.science/pith/CDHHOKVQXSR24EGP2HSBAX3SEX/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/CDHHOKVQXSR24EGP2HSBAX3SEX/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-04T09:47:29Z","links":{"resolver":"https://pith.science/pith/CDHHOKVQXSR24EGP2HSBAX3SEX","bundle":"https://pith.science/pith/CDHHOKVQXSR24EGP2HSBAX3SEX/bundle.json","state":"https://pith.science/pith/CDHHOKVQXSR24EGP2HSBAX3SEX/state.json","well_known_bundle":"https://pith.science/.well-known/pith/CDHHOKVQXSR24EGP2HSBAX3SEX/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:CDHHOKVQXSR24EGP2HSBAX3SEX","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"547645c8b9b34df022bf1816a95cc315b14058ab99dca636025820dfe6f1407e","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T06:36:29Z","title_canon_sha256":"fa4b9a87475cbf6b49df757703329eab61c281690621e4447b7aa2d6bf0436b2"},"schema_version":"1.0","source":{"id":"2607.01277","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2607.01277","created_at":"2026-07-03T00:16:56Z"},{"alias_kind":"arxiv_version","alias_value":"2607.01277v1","created_at":"2026-07-03T00:16:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.01277","created_at":"2026-07-03T00:16:56Z"},{"alias_kind":"pith_short_12","alias_value":"CDHHOKVQXSR2","created_at":"2026-07-03T00:16:56Z"},{"alias_kind":"pith_short_16","alias_value":"CDHHOKVQXSR24EGP","created_at":"2026-07-03T00:16:56Z"},{"alias_kind":"pith_short_8","alias_value":"CDHHOKVQ","created_at":"2026-07-03T00:16:56Z"}],"graph_snapshots":[{"event_id":"sha256:547abc09d35eb14135c45fd08dd193a4e4d829caf9a403bff318b774386b4d35","target":"graph","created_at":"2026-07-03T00:16:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2607.01277/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language models (LLMs) can be induced to produce harmful content through multi turn strategies in which no single user message appears clearly unsafe. Existing runtime safeguards commonly evaluate prompts or responses as isolated messages, which limits their ability to recover ac-cumulated intent, verify asserted authority, or detect harmful objectives decomposed across a dialogue. This paper presents the Cognitive Firewall, a proactive runtime oversight framework that interposes an independent oversight model between a user and a protected target mod l. The framework decomposes safety a","authors_text":"Jiacheng Li, Michele Guida, Noorbakhsh Amiri Golilarz, Ruslan Shikhhamzayev, Shahram Rahimi, Sindhuja Penchala, Stefano Iannucci","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T06:36:29Z","title":"Cognitive Firewall: A Proactive, Zero-Trust, Multi-Gate Framework for LLM Safety"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.01277","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:dc6b970318c21396e65d408934226dbe34b295dc31e6695d6de70fa96d44f40a","target":"record","created_at":"2026-07-03T00:16:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"547645c8b9b34df022bf1816a95cc315b14058ab99dca636025820dfe6f1407e","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T06:36:29Z","title_canon_sha256":"fa4b9a87475cbf6b49df757703329eab61c281690621e4447b7aa2d6bf0436b2"},"schema_version":"1.0","source":{"id":"2607.01277","kind":"arxiv","version":1}},"canonical_sha256":"10ce772ab0bca3ae10cfd1e4105f7225fa6e20b156ad524f3e6f8876b44a3f7f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"10ce772ab0bca3ae10cfd1e4105f7225fa6e20b156ad524f3e6f8876b44a3f7f","first_computed_at":"2026-07-03T00:16:56.102750Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-03T00:16:56.102750Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"mN1RbBLogRZVAZz6+vVENoqL0g4Sn9NX0Z7LaxaNhJ3Pn8vforYX7LEmZKnb4qScU9Ru/i4YCOm6ZKVvUaSkCQ==","signature_status":"signed_v1","signed_at":"2026-07-03T00:16:56.103152Z","signed_message":"canonical_sha256_bytes"},"source_id":"2607.01277","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:dc6b970318c21396e65d408934226dbe34b295dc31e6695d6de70fa96d44f40a","sha256:547abc09d35eb14135c45fd08dd193a4e4d829caf9a403bff318b774386b4d35"],"state_sha256":"a4a25edcfd7fd1945133c5b7a262f4eba2f33893124d855c86b778b5a88c3bfa"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Ibw/Wr6laEivt15Dks/HbK9x/ZrINB+z5BljpCZX05qbZol9goAQGdKmFou/DIfhpiAMFygj8f9brb5NEOiXAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-04T09:47:29.774411Z","bundle_sha256":"1d52e376d15956bad3a328ce2f0084a836a29157caf6b945597d0b224aee55bb"}}