{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:DZYLXMSMQ5N6AHJQVV4VMZ4S4A","short_pith_number":"pith:DZYLXMSM","canonical_record":{"source":{"id":"2606.26627","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-25T05:44:18Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"bb1b4415697b0127cc60cd5eaea4c39c58da234be90be5a84358316c633b199f","abstract_canon_sha256":"e0b46a73d0130bf90aa825ecc970b4517c320e7506b7fbe8754c0f3e41d5856d"},"schema_version":"1.0"},"canonical_sha256":"1e70bbb24c875be01d30ad79566792e00ca790a579aca6020a3564c92786c431","source":{"kind":"arxiv","id":"2606.26627","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.26627","created_at":"2026-06-26T01:15:36Z"},{"alias_kind":"arxiv_version","alias_value":"2606.26627v1","created_at":"2026-06-26T01:15:36Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.26627","created_at":"2026-06-26T01:15:36Z"},{"alias_kind":"pith_short_12","alias_value":"DZYLXMSMQ5N6","created_at":"2026-06-26T01:15:36Z"},{"alias_kind":"pith_short_16","alias_value":"DZYLXMSMQ5N6AHJQ","created_at":"2026-06-26T01:15:36Z"},{"alias_kind":"pith_short_8","alias_value":"DZYLXMSM","created_at":"2026-06-26T01:15:36Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:DZYLXMSMQ5N6AHJQVV4VMZ4S4A","target":"record","payload":{"canonical_record":{"source":{"id":"2606.26627","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-25T05:44:18Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"bb1b4415697b0127cc60cd5eaea4c39c58da234be90be5a84358316c633b199f","abstract_canon_sha256":"e0b46a73d0130bf90aa825ecc970b4517c320e7506b7fbe8754c0f3e41d5856d"},"schema_version":"1.0"},"canonical_sha256":"1e70bbb24c875be01d30ad79566792e00ca790a579aca6020a3564c92786c431","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-26T01:15:36.570360Z","signature_b64":"WqLi6f76aY6M6ZSjG2/e9c+F5xSz5tI5DbKIYCzDTRG8twW0Kbz5ptMn2J0Qy8Mq1wnjlephw6gyS98ppsVNDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"1e70bbb24c875be01d30ad79566792e00ca790a579aca6020a3564c92786c431","last_reissued_at":"2026-06-26T01:15:36.570004Z","signature_status":"signed_v1","first_computed_at":"2026-06-26T01:15:36.570004Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.26627","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-26T01:15:36Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"9rcBbtNG0LUOMewiVAdmDe2Sdnyd+ID723uwHZ31EdaxHiYkDkOBFuUXieB/POrNJRVdv6EXb9gWFv6GXjtLCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T04:27:59.180838Z"},"content_sha256":"6844eaa0986837eca1eec879ff5668d4866f7382cd8f6b4115fbe579677f38e2","schema_version":"1.0","event_id":"sha256:6844eaa0986837eca1eec879ff5668d4866f7382cd8f6b4115fbe579677f38e2"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:DZYLXMSMQ5N6AHJQVV4VMZ4S4A","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ashwin Gerard Colaco, Nada Lahjouji","submitted_at":"2026-06-25T05:44:18Z","abstract_excerpt":"Large language model agents increasingly query databases, search document collections, call external APIs, remember past interactions, and act on a user's behalf. As they move from answering questions to operating over sensitive data, privacy becomes harder to enforce. An agent touches many data sources, runs multi-step workflows, keeps state across sessions, and acts with delegated permissions. Sensitive information can therefore leak not only through its final answer but through the queries it issues, the intermediate results it handles, the memory it writes, and the messages it exchanges wi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.26627","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.26627/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-26T01:15:36Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"6Q58E6ij2P7q8d/ML5XnyWgU9DYElcyLZdMOirvOzVoUZ3HurrnM7ZfxpGASHspNqOETwUesElSCvYBPCCSgDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T04:27:59.181246Z"},"content_sha256":"a8f0908931b1bf3ccd4fa803c53a492b284383bcf7483b73858b1aaa5d7c3341","schema_version":"1.0","event_id":"sha256:a8f0908931b1bf3ccd4fa803c53a492b284383bcf7483b73858b1aaa5d7c3341"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/DZYLXMSMQ5N6AHJQVV4VMZ4S4A/bundle.json","state_url":"https://pith.science/pith/DZYLXMSMQ5N6AHJQVV4VMZ4S4A/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/DZYLXMSMQ5N6AHJQVV4VMZ4S4A/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-27T04:27:59Z","links":{"resolver":"https://pith.science/pith/DZYLXMSMQ5N6AHJQVV4VMZ4S4A","bundle":"https://pith.science/pith/DZYLXMSMQ5N6AHJQVV4VMZ4S4A/bundle.json","state":"https://pith.science/pith/DZYLXMSMQ5N6AHJQVV4VMZ4S4A/state.json","well_known_bundle":"https://pith.science/.well-known/pith/DZYLXMSMQ5N6AHJQVV4VMZ4S4A/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:DZYLXMSMQ5N6AHJQVV4VMZ4S4A","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e0b46a73d0130bf90aa825ecc970b4517c320e7506b7fbe8754c0f3e41d5856d","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-25T05:44:18Z","title_canon_sha256":"bb1b4415697b0127cc60cd5eaea4c39c58da234be90be5a84358316c633b199f"},"schema_version":"1.0","source":{"id":"2606.26627","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.26627","created_at":"2026-06-26T01:15:36Z"},{"alias_kind":"arxiv_version","alias_value":"2606.26627v1","created_at":"2026-06-26T01:15:36Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.26627","created_at":"2026-06-26T01:15:36Z"},{"alias_kind":"pith_short_12","alias_value":"DZYLXMSMQ5N6","created_at":"2026-06-26T01:15:36Z"},{"alias_kind":"pith_short_16","alias_value":"DZYLXMSMQ5N6AHJQ","created_at":"2026-06-26T01:15:36Z"},{"alias_kind":"pith_short_8","alias_value":"DZYLXMSM","created_at":"2026-06-26T01:15:36Z"}],"graph_snapshots":[{"event_id":"sha256:a8f0908931b1bf3ccd4fa803c53a492b284383bcf7483b73858b1aaa5d7c3341","target":"graph","created_at":"2026-06-26T01:15:36Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.26627/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language model agents increasingly query databases, search document collections, call external APIs, remember past interactions, and act on a user's behalf. As they move from answering questions to operating over sensitive data, privacy becomes harder to enforce. An agent touches many data sources, runs multi-step workflows, keeps state across sessions, and acts with delegated permissions. Sensitive information can therefore leak not only through its final answer but through the queries it issues, the intermediate results it handles, the memory it writes, and the messages it exchanges wi","authors_text":"Ashwin Gerard Colaco, Nada Lahjouji","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-25T05:44:18Z","title":"Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.26627","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:6844eaa0986837eca1eec879ff5668d4866f7382cd8f6b4115fbe579677f38e2","target":"record","created_at":"2026-06-26T01:15:36Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e0b46a73d0130bf90aa825ecc970b4517c320e7506b7fbe8754c0f3e41d5856d","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-25T05:44:18Z","title_canon_sha256":"bb1b4415697b0127cc60cd5eaea4c39c58da234be90be5a84358316c633b199f"},"schema_version":"1.0","source":{"id":"2606.26627","kind":"arxiv","version":1}},"canonical_sha256":"1e70bbb24c875be01d30ad79566792e00ca790a579aca6020a3564c92786c431","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"1e70bbb24c875be01d30ad79566792e00ca790a579aca6020a3564c92786c431","first_computed_at":"2026-06-26T01:15:36.570004Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-26T01:15:36.570004Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"WqLi6f76aY6M6ZSjG2/e9c+F5xSz5tI5DbKIYCzDTRG8twW0Kbz5ptMn2J0Qy8Mq1wnjlephw6gyS98ppsVNDw==","signature_status":"signed_v1","signed_at":"2026-06-26T01:15:36.570360Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.26627","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:6844eaa0986837eca1eec879ff5668d4866f7382cd8f6b4115fbe579677f38e2","sha256:a8f0908931b1bf3ccd4fa803c53a492b284383bcf7483b73858b1aaa5d7c3341"],"state_sha256":"3fb79f5ad376652e2f8982d4d8edceecfe7cacbbe2ae2694f16b2e27bf2bb218"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7qG+sAZP2M/pUQjXQ16nNbrdsa0EMpRghG61+WvfS6nyBRkLj39qT3ZAbO7QMJDC/rHvJx//ADKjADHstKc8Cw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-27T04:27:59.184093Z","bundle_sha256":"c68a60b81d9905480025badd6a093201cf9b110d259eb85f01279fd66ec81487"}}