{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2024:E3FMHPYKOBRXVCAFS3V3IYMRUH","short_pith_number":"pith:E3FMHPYK","canonical_record":{"source":{"id":"2410.02644","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-10-03T16:30:47Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"a48aab8f8f3e0d29aec4de65795e8188095fbe1295da46d405e29ea2b0eb017e","abstract_canon_sha256":"1af3b4b1e4ccf3996a360a850431ff6a848ea1fcc1fe3dd571f84c8e4f587a0f"},"schema_version":"1.0"},"canonical_sha256":"26cac3bf0a70637a880596ebb46191a1d54d278b4307c450a6ff69f9aec62aab","source":{"kind":"arxiv","id":"2410.02644","version":4},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2410.02644","created_at":"2026-07-05T11:12:20Z"},{"alias_kind":"arxiv_version","alias_value":"2410.02644v4","created_at":"2026-07-05T11:12:20Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2410.02644","created_at":"2026-07-05T11:12:20Z"},{"alias_kind":"pith_short_12","alias_value":"E3FMHPYKOBRX","created_at":"2026-07-05T11:12:20Z"},{"alias_kind":"pith_short_16","alias_value":"E3FMHPYKOBRXVCAF","created_at":"2026-07-05T11:12:20Z"},{"alias_kind":"pith_short_8","alias_value":"E3FMHPYK","created_at":"2026-07-05T11:12:20Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2024:E3FMHPYKOBRXVCAFS3V3IYMRUH","target":"record","payload":{"canonical_record":{"source":{"id":"2410.02644","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-10-03T16:30:47Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"a48aab8f8f3e0d29aec4de65795e8188095fbe1295da46d405e29ea2b0eb017e","abstract_canon_sha256":"1af3b4b1e4ccf3996a360a850431ff6a848ea1fcc1fe3dd571f84c8e4f587a0f"},"schema_version":"1.0"},"canonical_sha256":"26cac3bf0a70637a880596ebb46191a1d54d278b4307c450a6ff69f9aec62aab","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:12:20.924079Z","signature_b64":"UIgNLxSIYmbbCQ67V54LxfOBcuXPCfLmE08wFkQMhtB4ABtoSi6GJjL/si5J3V/KAayhow1N6bTgW+lxEdmSAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"26cac3bf0a70637a880596ebb46191a1d54d278b4307c450a6ff69f9aec62aab","last_reissued_at":"2026-07-05T11:12:20.923552Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:12:20.923552Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2410.02644","source_version":4,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T11:12:20Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"S1+TibPoiiFLL4bfZ9MKfRsdjGt65kGN29g35NNPG0uWHWJzKSgRjA+SK1NugitcW7lXZO078a4sbExgcSXdBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-04T18:10:54.319983Z"},"content_sha256":"2afc11f9ccba16aaa0a7fdd0fb9b9e5cc2438125377a0c5de595e485b739be48","schema_version":"1.0","event_id":"sha256:2afc11f9ccba16aaa0a7fdd0fb9b9e5cc2438125377a0c5de595e485b739be48"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2024:E3FMHPYKOBRXVCAFS3V3IYMRUH","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"LLM-based agents show critical vulnerabilities across prompts, tools, and memory with attack success rates reaching 84.30 percent and current defenses offering limited protection.","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Chenlu Zhan, Hanrong Zhang, Hongwei Wang, Jingyuan Huang, Kai Mei, Yifei Yao, Yongfeng Zhang, Zhenting Wang","submitted_at":"2024-10-03T16:30:47Z","abstract_excerpt":"Although LLM-based agents, powered by Large Language Models (LLMs), can use external tools and memory mechanisms to solve complex real-world tasks, they may also introduce critical security vulnerabilities. However, the existing literature does not comprehensively evaluate attacks and defenses against LLM-based agents. To address this, we introduce Agent Security Bench (ASB), a comprehensive framework designed to formalize, benchmark, and evaluate the attacks and defenses of LLM-based agents, including 10 scenarios (e.g., e-commerce, autonomous driving, finance), 10 agents targeting the scenar"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"Our benchmark results reveal critical vulnerabilities in different stages of agent operation, including system prompt, user prompt handling, tool usage, and memory retrieval, with the highest average attack success rate of 84.30%, but limited effectiveness shown in current defenses.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the selected 10 scenarios, 10 agents, over 400 tools, and 27 attack/defense methods provide a comprehensive and representative coverage of real-world threats and defenses for LLM-based agents.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"ASB is a new benchmark that tests 10 prompt injection attacks, memory poisoning, a novel Plan-of-Thought backdoor attack, and 11 defenses on LLM agents across 13 models, finding attack success rates up to 84.3% and limited defense effectiveness.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"LLM-based agents show critical vulnerabilities across prompts, tools, and memory with attack success rates reaching 84.30 percent and current defenses offering limited protection.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"cf0bc1118937b3044645081589e6690b54cb6a168f1b630af671624b629c333f"},"source":{"id":"2410.02644","kind":"arxiv","version":4},"verdict":{"id":"63d4afe7-14c4-4d23-bf19-0b4028fa72de","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-12T13:30:45.975296Z","strongest_claim":"Our benchmark results reveal critical vulnerabilities in different stages of agent operation, including system prompt, user prompt handling, tool usage, and memory retrieval, with the highest average attack success rate of 84.30%, but limited effectiveness shown in current defenses.","one_line_summary":"ASB is a new benchmark that tests 10 prompt injection attacks, memory poisoning, a novel Plan-of-Thought backdoor attack, and 11 defenses on LLM agents across 13 models, finding attack success rates up to 84.3% and limited defense effectiveness.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the selected 10 scenarios, 10 agents, over 400 tools, and 27 attack/defense methods provide a comprehensive and representative coverage of real-world threats and defenses for LLM-based agents.","pith_extraction_headline":"LLM-based agents show critical vulnerabilities across prompts, tools, and memory with attack success rates reaching 84.30 percent and current defenses offering limited protection."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2410.02644/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":143,"sample":[{"doi":"","year":2024,"title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases , author=. 2024 , eprint=","work_id":"3c2e1e67-93f8-4a57-8c0c-32d65f251a27","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2023,"title":"The 2023 Conference on Empirical Methods in Natural Language Processing , year=","work_id":"9b46c20c-17a6-4157-aa3f-7e3e0b093146","ref_index":2,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"33rd USENIX Security Symposium (USENIX Security 24) , year =","work_id":"4ac90728-9594-4b49-9e9b-e1ab70d11e94","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2024,"title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models , author=. 2024 , eprint=","work_id":"39766c24-d8cc-4790-87c2-01885b3f3633","ref_index":4,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":null,"title":"Securing llm systems against prompt injection , author=","work_id":"97621ac6-6d61-4ad9-bf0a-1cba6e8223e6","ref_index":6,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":143,"snapshot_sha256":"0580b8a9fac86ff5e2687071a8a01bf09a3438f3f82462275eac254d2158249f","internal_anchors":11},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"63d4afe7-14c4-4d23-bf19-0b4028fa72de"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T11:12:20Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"mzN4GBIsFr8dKS2N9wpLEQUjf2idwxBoyrZqJ/ruuTDviJwHcSRYlBRDQGCa0UxA3DBz+Od7+BRjwYY80M9vAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-04T18:10:54.320849Z"},"content_sha256":"3e0889a0fd175dfe236856c934c5133c9d85ff3aa2db4f24a3e21a356a63790a","schema_version":"1.0","event_id":"sha256:3e0889a0fd175dfe236856c934c5133c9d85ff3aa2db4f24a3e21a356a63790a"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/E3FMHPYKOBRXVCAFS3V3IYMRUH/bundle.json","state_url":"https://pith.science/pith/E3FMHPYKOBRXVCAFS3V3IYMRUH/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/E3FMHPYKOBRXVCAFS3V3IYMRUH/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-04T18:10:54Z","links":{"resolver":"https://pith.science/pith/E3FMHPYKOBRXVCAFS3V3IYMRUH","bundle":"https://pith.science/pith/E3FMHPYKOBRXVCAFS3V3IYMRUH/bundle.json","state":"https://pith.science/pith/E3FMHPYKOBRXVCAFS3V3IYMRUH/state.json","well_known_bundle":"https://pith.science/.well-known/pith/E3FMHPYKOBRXVCAFS3V3IYMRUH/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2024:E3FMHPYKOBRXVCAFS3V3IYMRUH","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"1af3b4b1e4ccf3996a360a850431ff6a848ea1fcc1fe3dd571f84c8e4f587a0f","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-10-03T16:30:47Z","title_canon_sha256":"a48aab8f8f3e0d29aec4de65795e8188095fbe1295da46d405e29ea2b0eb017e"},"schema_version":"1.0","source":{"id":"2410.02644","kind":"arxiv","version":4}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2410.02644","created_at":"2026-07-05T11:12:20Z"},{"alias_kind":"arxiv_version","alias_value":"2410.02644v4","created_at":"2026-07-05T11:12:20Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2410.02644","created_at":"2026-07-05T11:12:20Z"},{"alias_kind":"pith_short_12","alias_value":"E3FMHPYKOBRX","created_at":"2026-07-05T11:12:20Z"},{"alias_kind":"pith_short_16","alias_value":"E3FMHPYKOBRXVCAF","created_at":"2026-07-05T11:12:20Z"},{"alias_kind":"pith_short_8","alias_value":"E3FMHPYK","created_at":"2026-07-05T11:12:20Z"}],"graph_snapshots":[{"event_id":"sha256:3e0889a0fd175dfe236856c934c5133c9d85ff3aa2db4f24a3e21a356a63790a","target":"graph","created_at":"2026-07-05T11:12:20Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"Our benchmark results reveal critical vulnerabilities in different stages of agent operation, including system prompt, user prompt handling, tool usage, and memory retrieval, with the highest average attack success rate of 84.30%, but limited effectiveness shown in current defenses."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That the selected 10 scenarios, 10 agents, over 400 tools, and 27 attack/defense methods provide a comprehensive and representative coverage of real-world threats and defenses for LLM-based agents."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"ASB is a new benchmark that tests 10 prompt injection attacks, memory poisoning, a novel Plan-of-Thought backdoor attack, and 11 defenses on LLM agents across 13 models, finding attack success rates up to 84.3% and limited defense effectiveness."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"LLM-based agents show critical vulnerabilities across prompts, tools, and memory with attack success rates reaching 84.30 percent and current defenses offering limited protection."}],"snapshot_sha256":"cf0bc1118937b3044645081589e6690b54cb6a168f1b630af671624b629c333f"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2410.02644/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Although LLM-based agents, powered by Large Language Models (LLMs), can use external tools and memory mechanisms to solve complex real-world tasks, they may also introduce critical security vulnerabilities. However, the existing literature does not comprehensively evaluate attacks and defenses against LLM-based agents. To address this, we introduce Agent Security Bench (ASB), a comprehensive framework designed to formalize, benchmark, and evaluate the attacks and defenses of LLM-based agents, including 10 scenarios (e.g., e-commerce, autonomous driving, finance), 10 agents targeting the scenar","authors_text":"Chenlu Zhan, Hanrong Zhang, Hongwei Wang, Jingyuan Huang, Kai Mei, Yifei Yao, Yongfeng Zhang, Zhenting Wang","cross_cats":["cs.AI"],"headline":"LLM-based agents show critical vulnerabilities across prompts, tools, and memory with attack success rates reaching 84.30 percent and current defenses offering limited protection.","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-10-03T16:30:47Z","title":"Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents"},"references":{"count":143,"internal_anchors":11,"resolved_work":143,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases , author=. 2024 , eprint=","work_id":"3c2e1e67-93f8-4a57-8c0c-32d65f251a27","year":2024},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":2,"title":"The 2023 Conference on Empirical Methods in Natural Language Processing , year=","work_id":"9b46c20c-17a6-4157-aa3f-7e3e0b093146","year":2023},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"33rd USENIX Security Symposium (USENIX Security 24) , year =","work_id":"4ac90728-9594-4b49-9e9b-e1ab70d11e94","year":null},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":4,"title":"BadChain: Backdoor Chain-of-Thought Prompting for Large Language Models , author=. 2024 , eprint=","work_id":"39766c24-d8cc-4790-87c2-01885b3f3633","year":2024},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":6,"title":"Securing llm systems against prompt injection , author=","work_id":"97621ac6-6d61-4ad9-bf0a-1cba6e8223e6","year":null}],"snapshot_sha256":"0580b8a9fac86ff5e2687071a8a01bf09a3438f3f82462275eac254d2158249f"},"source":{"id":"2410.02644","kind":"arxiv","version":4},"verdict":{"created_at":"2026-05-12T13:30:45.975296Z","id":"63d4afe7-14c4-4d23-bf19-0b4028fa72de","model_set":{"reader":"grok-4.3"},"one_line_summary":"ASB is a new benchmark that tests 10 prompt injection attacks, memory poisoning, a novel Plan-of-Thought backdoor attack, and 11 defenses on LLM agents across 13 models, finding attack success rates up to 84.3% and limited defense effectiveness.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"LLM-based agents show critical vulnerabilities across prompts, tools, and memory with attack success rates reaching 84.30 percent and current defenses offering limited protection.","strongest_claim":"Our benchmark results reveal critical vulnerabilities in different stages of agent operation, including system prompt, user prompt handling, tool usage, and memory retrieval, with the highest average attack success rate of 84.30%, but limited effectiveness shown in current defenses.","weakest_assumption":"That the selected 10 scenarios, 10 agents, over 400 tools, and 27 attack/defense methods provide a comprehensive and representative coverage of real-world threats and defenses for LLM-based agents."}},"verdict_id":"63d4afe7-14c4-4d23-bf19-0b4028fa72de"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2afc11f9ccba16aaa0a7fdd0fb9b9e5cc2438125377a0c5de595e485b739be48","target":"record","created_at":"2026-07-05T11:12:20Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"1af3b4b1e4ccf3996a360a850431ff6a848ea1fcc1fe3dd571f84c8e4f587a0f","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-10-03T16:30:47Z","title_canon_sha256":"a48aab8f8f3e0d29aec4de65795e8188095fbe1295da46d405e29ea2b0eb017e"},"schema_version":"1.0","source":{"id":"2410.02644","kind":"arxiv","version":4}},"canonical_sha256":"26cac3bf0a70637a880596ebb46191a1d54d278b4307c450a6ff69f9aec62aab","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"26cac3bf0a70637a880596ebb46191a1d54d278b4307c450a6ff69f9aec62aab","first_computed_at":"2026-07-05T11:12:20.923552Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T11:12:20.923552Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"UIgNLxSIYmbbCQ67V54LxfOBcuXPCfLmE08wFkQMhtB4ABtoSi6GJjL/si5J3V/KAayhow1N6bTgW+lxEdmSAw==","signature_status":"signed_v1","signed_at":"2026-07-05T11:12:20.924079Z","signed_message":"canonical_sha256_bytes"},"source_id":"2410.02644","source_kind":"arxiv","source_version":4}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2afc11f9ccba16aaa0a7fdd0fb9b9e5cc2438125377a0c5de595e485b739be48","sha256:3e0889a0fd175dfe236856c934c5133c9d85ff3aa2db4f24a3e21a356a63790a"],"state_sha256":"f1b64a650a016b3ecc47e065ed7d79b6b30bda02abaee30e5151ba03acf0d1ec"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4p2AONZuI0YN08KCPCjgiKjNSTjQcSbFW/CQVYIHqL0K7wmWviwrShgp/uNf+mQnNx3UUhxKTdTWAmAKHgSYCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-04T18:10:54.325031Z","bundle_sha256":"67f09c1aac543972d1173fd556bef80d7263c89a9360e2872f30357dbbff6ecc"}}