{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:DM6PJLIYBTS6D7QLI6TZ4RAPEA","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b02bbda54adc7cb33fc33fe305a430b3784a257ff536b5adf76a7d3d0c7d1b21","cross_cats_sorted":["cs.AI","eess.AS"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SD","submitted_at":"2026-05-18T02:11:57Z","title_canon_sha256":"5d5de76db9dafd006b8ab0d84918dc1cb44ae3624312e5750294b2b1dce02187"},"schema_version":"1.0","source":{"id":"2605.30365","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.30365","created_at":"2026-06-01T00:02:06Z"},{"alias_kind":"arxiv_version","alias_value":"2605.30365v1","created_at":"2026-06-01T00:02:06Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.30365","created_at":"2026-06-01T00:02:06Z"},{"alias_kind":"pith_short_12","alias_value":"DM6PJLIYBTS6","created_at":"2026-06-01T00:02:06Z"},{"alias_kind":"pith_short_16","alias_value":"DM6PJLIYBTS6D7QL","created_at":"2026-06-01T00:02:06Z"},{"alias_kind":"pith_short_8","alias_value":"DM6PJLIY","created_at":"2026-06-01T00:02:06Z"}],"graph_snapshots":[{"event_id":"sha256:799d38256c58cbcbb4847ff3d18861884e10004c30e00f75ee5c08124b5bf64e","target":"graph","created_at":"2026-06-01T00:02:06Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.30365/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Retrieval-augmented text-to-music (TTM) systems augment underspecified user prompts using captions retrieved from a music caption dataset. This design introduces an integrity dependency on the music knowledge database. We show that an attacker can poison the database by injecting a small number of crafted music captions, causing the system to retrieve malicious captions that bias prompt augmentation and steer generation away from the user's intended function, without modifying the user prompt, retriever, or generator. To achieve the music caption poisoning attack, we propose a dual-layer capti","authors_text":"Hanqing Guo, Long Cheng, Nan Zhang, Shuhao Zhang, Yizhu Wen","cross_cats":["cs.AI","eess.AS"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SD","submitted_at":"2026-05-18T02:11:57Z","title":"Mental Damage: Caption Poisoning Attacks on Retrieval-Augmented Text-to-Music Generation"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.30365","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:650e761b1a8d8a385129c1e6673a58f01b1382e71544e0066dc8192ad5e185dc","target":"record","created_at":"2026-06-01T00:02:06Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b02bbda54adc7cb33fc33fe305a430b3784a257ff536b5adf76a7d3d0c7d1b21","cross_cats_sorted":["cs.AI","eess.AS"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SD","submitted_at":"2026-05-18T02:11:57Z","title_canon_sha256":"5d5de76db9dafd006b8ab0d84918dc1cb44ae3624312e5750294b2b1dce02187"},"schema_version":"1.0","source":{"id":"2605.30365","kind":"arxiv","version":1}},"canonical_sha256":"1b3cf4ad180ce5e1fe0b47a79e440f200d8310eb30b0a9e2c72ae722596b10cf","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"1b3cf4ad180ce5e1fe0b47a79e440f200d8310eb30b0a9e2c72ae722596b10cf","first_computed_at":"2026-06-01T00:02:06.960680Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-01T00:02:06.960680Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"TctqJtaO4uvn3bFzHRIQ1zG8sp0g4BpSxj/du/9xcQPJLMHSiQyW4cayh4V1ekfqBPawLog3HuVvsl32gG4iDw==","signature_status":"signed_v1","signed_at":"2026-06-01T00:02:06.961638Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.30365","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:650e761b1a8d8a385129c1e6673a58f01b1382e71544e0066dc8192ad5e185dc","sha256:799d38256c58cbcbb4847ff3d18861884e10004c30e00f75ee5c08124b5bf64e"],"state_sha256":"0de157b7be8bf51d984016dd5b09160de251226830479756d96577640a1617b3"}