{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:CYNSEPYQWHZFP2GTKEXDLG6VH2","short_pith_number":"pith:CYNSEPYQ","schema_version":"1.0","canonical_sha256":"161b223f10b1f257e8d3512e359bd53e989d5812807f197b8149b3c147ff5009","source":{"kind":"arxiv","id":"2607.07097","version":1},"attestation_state":"computed","paper":{"title":"Operational Reframing and Approval-Framed Delegation in Multi-Agent LLM Safety","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR","cs.MA"],"primary_cat":"cs.AI","authors_text":"Haoran Yu, Lifei Liu, Pin Qian, Su Wang, Xiaochong Jiang, Yihang Chen","submitted_at":"2026-07-08T07:31:37Z","abstract_excerpt":"Safety evaluations of multi-agent LLM systems often compare a direct prompt with a planner-executor pipeline and report the difference as a single \"pipeline effect.\" We argue that this aggregate is difficult to interpret because it conflates three mechanisms: harmful intent may be reframed as plausible operational work, the planner may refuse or transform the request, and the executor may act under delegation prompts implying prior approval. To separate these factors, we introduce a five-condition controlled contrast design, evaluated on 30 synthetic harmful scenarios and an exploratory extern"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2607.07097","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-07-08T07:31:37Z","cross_cats_sorted":["cs.CR","cs.MA"],"title_canon_sha256":"f8a342b209e110aa6904b2536bb3a8d4960dd1b4f5d1061325a24183870586c4","abstract_canon_sha256":"b51b3cd48a8d4edd8093ec6f408eee804431e12467160b8730a161cc7a2d26a5"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-09T01:20:14.390629Z","signature_b64":"UNbPPNvz1mpNocWWAoc6ncZBeLAjMEo/mMzziFM7W43/sTYiHxOGYyp85Ps9NJdzjXA7E0gLVnC2FgiZFXjZBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"161b223f10b1f257e8d3512e359bd53e989d5812807f197b8149b3c147ff5009","last_reissued_at":"2026-07-09T01:20:14.390233Z","signature_status":"signed_v1","first_computed_at":"2026-07-09T01:20:14.390233Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Operational Reframing and Approval-Framed Delegation in Multi-Agent LLM Safety","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR","cs.MA"],"primary_cat":"cs.AI","authors_text":"Haoran Yu, Lifei Liu, Pin Qian, Su Wang, Xiaochong Jiang, Yihang Chen","submitted_at":"2026-07-08T07:31:37Z","abstract_excerpt":"Safety evaluations of multi-agent LLM systems often compare a direct prompt with a planner-executor pipeline and report the difference as a single \"pipeline effect.\" We argue that this aggregate is difficult to interpret because it conflates three mechanisms: harmful intent may be reframed as plausible operational work, the planner may refuse or transform the request, and the executor may act under delegation prompts implying prior approval. To separate these factors, we introduce a five-condition controlled contrast design, evaluated on 30 synthetic harmful scenarios and an exploratory extern"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.07097","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2607.07097/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2607.07097","created_at":"2026-07-09T01:20:14.390290+00:00"},{"alias_kind":"arxiv_version","alias_value":"2607.07097v1","created_at":"2026-07-09T01:20:14.390290+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.07097","created_at":"2026-07-09T01:20:14.390290+00:00"},{"alias_kind":"pith_short_12","alias_value":"CYNSEPYQWHZF","created_at":"2026-07-09T01:20:14.390290+00:00"},{"alias_kind":"pith_short_16","alias_value":"CYNSEPYQWHZFP2GT","created_at":"2026-07-09T01:20:14.390290+00:00"},{"alias_kind":"pith_short_8","alias_value":"CYNSEPYQ","created_at":"2026-07-09T01:20:14.390290+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2608.02665","citing_title":"Single Canonical Prompts Underestimate LLM Safety's Surface-Form Sensitivity","ref_index":8,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/CYNSEPYQWHZFP2GTKEXDLG6VH2","json":"https://pith.science/pith/CYNSEPYQWHZFP2GTKEXDLG6VH2.json","graph_json":"https://pith.science/api/pith-number/CYNSEPYQWHZFP2GTKEXDLG6VH2/graph.json","events_json":"https://pith.science/api/pith-number/CYNSEPYQWHZFP2GTKEXDLG6VH2/events.json","paper":"https://pith.science/paper/CYNSEPYQ"},"agent_actions":{"view_html":"https://pith.science/pith/CYNSEPYQWHZFP2GTKEXDLG6VH2","download_json":"https://pith.science/pith/CYNSEPYQWHZFP2GTKEXDLG6VH2.json","view_paper":"https://pith.science/paper/CYNSEPYQ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2607.07097&json=true","fetch_graph":"https://pith.science/api/pith-number/CYNSEPYQWHZFP2GTKEXDLG6VH2/graph.json","fetch_events":"https://pith.science/api/pith-number/CYNSEPYQWHZFP2GTKEXDLG6VH2/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/CYNSEPYQWHZFP2GTKEXDLG6VH2/action/timestamp_anchor","attest_storage":"https://pith.science/pith/CYNSEPYQWHZFP2GTKEXDLG6VH2/action/storage_attestation","attest_author":"https://pith.science/pith/CYNSEPYQWHZFP2GTKEXDLG6VH2/action/author_attestation","sign_citation":"https://pith.science/pith/CYNSEPYQWHZFP2GTKEXDLG6VH2/action/citation_signature","submit_replication":"https://pith.science/pith/CYNSEPYQWHZFP2GTKEXDLG6VH2/action/replication_record"}},"created_at":"2026-07-09T01:20:14.390290+00:00","updated_at":"2026-07-09T01:20:14.390290+00:00"}