{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:CLCWOT66CAH3AGS4LUSTUBVEET","short_pith_number":"pith:CLCWOT66","canonical_record":{"source":{"id":"2606.29030","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-06-27T17:57:25Z","cross_cats_sorted":["cs.ET"],"title_canon_sha256":"b7a8756db169dbaee550bbacb0b96e4018e5ab716aeb5ea093f974896b16a372","abstract_canon_sha256":"d768f9f38a54d1480eeb5dc834ac6ff34b484385bdc8e9ed19dc47fbd236c514"},"schema_version":"1.0"},"canonical_sha256":"12c5674fde100fb01a5c5d253a06a424c3e921d1a2f8f05e43b1a086924033e6","source":{"kind":"arxiv","id":"2606.29030","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.29030","created_at":"2026-06-30T01:17:50Z"},{"alias_kind":"arxiv_version","alias_value":"2606.29030v1","created_at":"2026-06-30T01:17:50Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.29030","created_at":"2026-06-30T01:17:50Z"},{"alias_kind":"pith_short_12","alias_value":"CLCWOT66CAH3","created_at":"2026-06-30T01:17:50Z"},{"alias_kind":"pith_short_16","alias_value":"CLCWOT66CAH3AGS4","created_at":"2026-06-30T01:17:50Z"},{"alias_kind":"pith_short_8","alias_value":"CLCWOT66","created_at":"2026-06-30T01:17:50Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:CLCWOT66CAH3AGS4LUSTUBVEET","target":"record","payload":{"canonical_record":{"source":{"id":"2606.29030","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-06-27T17:57:25Z","cross_cats_sorted":["cs.ET"],"title_canon_sha256":"b7a8756db169dbaee550bbacb0b96e4018e5ab716aeb5ea093f974896b16a372","abstract_canon_sha256":"d768f9f38a54d1480eeb5dc834ac6ff34b484385bdc8e9ed19dc47fbd236c514"},"schema_version":"1.0"},"canonical_sha256":"12c5674fde100fb01a5c5d253a06a424c3e921d1a2f8f05e43b1a086924033e6","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-30T01:17:50.005022Z","signature_b64":"E2DmMUgKWMRkl8jigZ+N5u48OfwGm5F9DFyF29vWwdhtqRCtCAunyvzPN1UZG5mTIAQvqVT8Ccqzlty+HVw+DA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"12c5674fde100fb01a5c5d253a06a424c3e921d1a2f8f05e43b1a086924033e6","last_reissued_at":"2026-06-30T01:17:50.004246Z","signature_status":"signed_v1","first_computed_at":"2026-06-30T01:17:50.004246Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.29030","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-30T01:17:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"b77DqogAvMt8Vp7zHpazQeEX4/SJwk+2ns0/vVStKYEc8zTDgpFHsL0Tc0csRcmyNkhxxA9jw8bqB5MICqEtAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-01T22:38:33.554600Z"},"content_sha256":"448a3310316eb27e8f254bcfb835262dc01994af5576643bc8cfb54a6b4c0a2c","schema_version":"1.0","event_id":"sha256:448a3310316eb27e8f254bcfb835262dc01994af5576643bc8cfb54a6b4c0a2c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:CLCWOT66CAH3AGS4LUSTUBVEET","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Memory as an Attack Surface in LLM Agents: A Study on Multiple-Choice Question Answering","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.ET"],"primary_cat":"cs.AI","authors_text":"Anindya Bijoy Das, Shahnewaz Karim Sakib","submitted_at":"2026-06-27T17:57:25Z","abstract_excerpt":"AI agents extend conventional large language model (LLM) applications by integrating language understanding with task execution, external tool use, and memory mechanisms. While memory allows agents to retain prior interactions and provide more personalized and context-aware responses, it also introduces a new vulnerability: information stored in memory can influence future outputs even when the current query is clean. In this paper, we investigate memory manipulation in LLM-based agents for multiple-choice question answering. We first design and implement an LLM-based AI agent with an external"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.29030","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.29030/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-30T01:17:50Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/Tio4R5jW4xYzeyqZ4zJLxrwzp5L+S987D81lTCKLEZEz99dQFSBci3a2P7W2Tm/vUU+rCmCddQXxoHHdImrDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-01T22:38:33.554976Z"},"content_sha256":"8ac7e8284aa7db60b8fec519bc369e1b95a67f45a8fd5fc04083eee9121d25f9","schema_version":"1.0","event_id":"sha256:8ac7e8284aa7db60b8fec519bc369e1b95a67f45a8fd5fc04083eee9121d25f9"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/CLCWOT66CAH3AGS4LUSTUBVEET/bundle.json","state_url":"https://pith.science/pith/CLCWOT66CAH3AGS4LUSTUBVEET/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/CLCWOT66CAH3AGS4LUSTUBVEET/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-01T22:38:33Z","links":{"resolver":"https://pith.science/pith/CLCWOT66CAH3AGS4LUSTUBVEET","bundle":"https://pith.science/pith/CLCWOT66CAH3AGS4LUSTUBVEET/bundle.json","state":"https://pith.science/pith/CLCWOT66CAH3AGS4LUSTUBVEET/state.json","well_known_bundle":"https://pith.science/.well-known/pith/CLCWOT66CAH3AGS4LUSTUBVEET/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:CLCWOT66CAH3AGS4LUSTUBVEET","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"d768f9f38a54d1480eeb5dc834ac6ff34b484385bdc8e9ed19dc47fbd236c514","cross_cats_sorted":["cs.ET"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-06-27T17:57:25Z","title_canon_sha256":"b7a8756db169dbaee550bbacb0b96e4018e5ab716aeb5ea093f974896b16a372"},"schema_version":"1.0","source":{"id":"2606.29030","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.29030","created_at":"2026-06-30T01:17:50Z"},{"alias_kind":"arxiv_version","alias_value":"2606.29030v1","created_at":"2026-06-30T01:17:50Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.29030","created_at":"2026-06-30T01:17:50Z"},{"alias_kind":"pith_short_12","alias_value":"CLCWOT66CAH3","created_at":"2026-06-30T01:17:50Z"},{"alias_kind":"pith_short_16","alias_value":"CLCWOT66CAH3AGS4","created_at":"2026-06-30T01:17:50Z"},{"alias_kind":"pith_short_8","alias_value":"CLCWOT66","created_at":"2026-06-30T01:17:50Z"}],"graph_snapshots":[{"event_id":"sha256:8ac7e8284aa7db60b8fec519bc369e1b95a67f45a8fd5fc04083eee9121d25f9","target":"graph","created_at":"2026-06-30T01:17:50Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.29030/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"AI agents extend conventional large language model (LLM) applications by integrating language understanding with task execution, external tool use, and memory mechanisms. While memory allows agents to retain prior interactions and provide more personalized and context-aware responses, it also introduces a new vulnerability: information stored in memory can influence future outputs even when the current query is clean. In this paper, we investigate memory manipulation in LLM-based agents for multiple-choice question answering. We first design and implement an LLM-based AI agent with an external","authors_text":"Anindya Bijoy Das, Shahnewaz Karim Sakib","cross_cats":["cs.ET"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-06-27T17:57:25Z","title":"Memory as an Attack Surface in LLM Agents: A Study on Multiple-Choice Question Answering"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.29030","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:448a3310316eb27e8f254bcfb835262dc01994af5576643bc8cfb54a6b4c0a2c","target":"record","created_at":"2026-06-30T01:17:50Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"d768f9f38a54d1480eeb5dc834ac6ff34b484385bdc8e9ed19dc47fbd236c514","cross_cats_sorted":["cs.ET"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.AI","submitted_at":"2026-06-27T17:57:25Z","title_canon_sha256":"b7a8756db169dbaee550bbacb0b96e4018e5ab716aeb5ea093f974896b16a372"},"schema_version":"1.0","source":{"id":"2606.29030","kind":"arxiv","version":1}},"canonical_sha256":"12c5674fde100fb01a5c5d253a06a424c3e921d1a2f8f05e43b1a086924033e6","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"12c5674fde100fb01a5c5d253a06a424c3e921d1a2f8f05e43b1a086924033e6","first_computed_at":"2026-06-30T01:17:50.004246Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-30T01:17:50.004246Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"E2DmMUgKWMRkl8jigZ+N5u48OfwGm5F9DFyF29vWwdhtqRCtCAunyvzPN1UZG5mTIAQvqVT8Ccqzlty+HVw+DA==","signature_status":"signed_v1","signed_at":"2026-06-30T01:17:50.005022Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.29030","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:448a3310316eb27e8f254bcfb835262dc01994af5576643bc8cfb54a6b4c0a2c","sha256:8ac7e8284aa7db60b8fec519bc369e1b95a67f45a8fd5fc04083eee9121d25f9"],"state_sha256":"aacb4d5e4394fbc42b58f8badfde826367f0ae6d64ce83e7fb72759d0209156b"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"x2Bm3K2Sfzw/i0Wnu2PQTxU9XXUyWDzmw3txZAipHZ4eFJMuqX8J/Tx+Sfr899mKf9/fitqD8k0Fq+fbUEZ5Ag==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-01T22:38:33.557161Z","bundle_sha256":"0b729f6a16d2c8bf179028b215790ee56846667b0b43a9158e736b56dab01ea8"}}