{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:EBX7YPXOKVCHPPXJI6ZSUIVHI2","short_pith_number":"pith:EBX7YPXO","canonical_record":{"source":{"id":"2605.19227","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-19T00:55:18Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"21da0e6e52f6fb70077acdadcdb0f5b78da38ab4fe9a11553837ae93597a3a68","abstract_canon_sha256":"7885d2f3a4812c2be72cd485440b31a162c1482e8e5016e99bfcf6bd25dac870"},"schema_version":"1.0"},"canonical_sha256":"206ffc3eee554477bee947b32a22a74695b2ce664675023656003767c788f51f","source":{"kind":"arxiv","id":"2605.19227","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.19227","created_at":"2026-05-20T01:05:34Z"},{"alias_kind":"arxiv_version","alias_value":"2605.19227v1","created_at":"2026-05-20T01:05:34Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.19227","created_at":"2026-05-20T01:05:34Z"},{"alias_kind":"pith_short_12","alias_value":"EBX7YPXOKVCH","created_at":"2026-05-20T01:05:34Z"},{"alias_kind":"pith_short_16","alias_value":"EBX7YPXOKVCHPPXJ","created_at":"2026-05-20T01:05:34Z"},{"alias_kind":"pith_short_8","alias_value":"EBX7YPXO","created_at":"2026-05-20T01:05:34Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:EBX7YPXOKVCHPPXJI6ZSUIVHI2","target":"record","payload":{"canonical_record":{"source":{"id":"2605.19227","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-19T00:55:18Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"21da0e6e52f6fb70077acdadcdb0f5b78da38ab4fe9a11553837ae93597a3a68","abstract_canon_sha256":"7885d2f3a4812c2be72cd485440b31a162c1482e8e5016e99bfcf6bd25dac870"},"schema_version":"1.0"},"canonical_sha256":"206ffc3eee554477bee947b32a22a74695b2ce664675023656003767c788f51f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-20T01:05:34.477050Z","signature_b64":"FZCogM4owHz/gRdO4Ym5JSZ9owtUZ5qbzhM12HhpMboJ1DPTHwOzsoq9Q8RIIb78fb2QuZ9CyWYnTWtIrh9MBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"206ffc3eee554477bee947b32a22a74695b2ce664675023656003767c788f51f","last_reissued_at":"2026-05-20T01:05:34.476394Z","signature_status":"signed_v1","first_computed_at":"2026-05-20T01:05:34.476394Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.19227","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T01:05:34Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+rBOtXcWsvqlDNHcM4feBOkYzIDzKZwEEf6afSjwGbHVC2W6c49diEpz4xXwmHTECs2qEI4KE3n1R3OQ/JNDBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T00:38:33.932879Z"},"content_sha256":"1efd8323ea61fa58768f63e84fb471760b98fa688957f8cfbb9ecd91aa26f013","schema_version":"1.0","event_id":"sha256:1efd8323ea61fa58768f63e84fb471760b98fa688957f8cfbb9ecd91aa26f013"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:EBX7YPXOKVCHPPXJI6ZSUIVHI2","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Token by Token, Compromised: Backdoor Vulnerabilities in Unified Autoregressive Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Anna Rohrbach, Hossein Shakibania, Jonas Henry Grebe, Marcus Rohrbach, Tobias Braun","submitted_at":"2026-05-19T00:55:18Z","abstract_excerpt":"Unified autoregressive models (UAMs) are transformer models that generate text as well as image tokens within a single autoregressive pass. Shared parameters and a multimodal vocabulary simplify the training pipeline and facilitate flexible multimodal generation, yet might introduce new vulnerabilities. In particular, we are the first to show that this unified architecture enables multimodal backdoor attacks, where a trigger can propagate malicious effects across multiple output modalities. Specifically, we present the Token by Token Backdoor Attack (ToBAC), the first backdoor attack targeting"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.19227","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.19227/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T01:05:34Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Kdqg76+lIoWwMPTYUYMMAfglSPWFoc0Df76IfAKfTAMqnMCWfffDkx72ZiLCOushLZzbUYGE4CE41SdMSNfgBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-26T00:38:33.933610Z"},"content_sha256":"8f91e222e0937544e92e2be8eddeb45d7ff3f93f67230f1201137fcd984d5236","schema_version":"1.0","event_id":"sha256:8f91e222e0937544e92e2be8eddeb45d7ff3f93f67230f1201137fcd984d5236"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2/bundle.json","state_url":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-26T00:38:33Z","links":{"resolver":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2","bundle":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2/bundle.json","state":"https://pith.science/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2/state.json","well_known_bundle":"https://pith.science/.well-known/pith/EBX7YPXOKVCHPPXJI6ZSUIVHI2/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:EBX7YPXOKVCHPPXJI6ZSUIVHI2","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"7885d2f3a4812c2be72cd485440b31a162c1482e8e5016e99bfcf6bd25dac870","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-19T00:55:18Z","title_canon_sha256":"21da0e6e52f6fb70077acdadcdb0f5b78da38ab4fe9a11553837ae93597a3a68"},"schema_version":"1.0","source":{"id":"2605.19227","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.19227","created_at":"2026-05-20T01:05:34Z"},{"alias_kind":"arxiv_version","alias_value":"2605.19227v1","created_at":"2026-05-20T01:05:34Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.19227","created_at":"2026-05-20T01:05:34Z"},{"alias_kind":"pith_short_12","alias_value":"EBX7YPXOKVCH","created_at":"2026-05-20T01:05:34Z"},{"alias_kind":"pith_short_16","alias_value":"EBX7YPXOKVCHPPXJ","created_at":"2026-05-20T01:05:34Z"},{"alias_kind":"pith_short_8","alias_value":"EBX7YPXO","created_at":"2026-05-20T01:05:34Z"}],"graph_snapshots":[{"event_id":"sha256:8f91e222e0937544e92e2be8eddeb45d7ff3f93f67230f1201137fcd984d5236","target":"graph","created_at":"2026-05-20T01:05:34Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.19227/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Unified autoregressive models (UAMs) are transformer models that generate text as well as image tokens within a single autoregressive pass. Shared parameters and a multimodal vocabulary simplify the training pipeline and facilitate flexible multimodal generation, yet might introduce new vulnerabilities. In particular, we are the first to show that this unified architecture enables multimodal backdoor attacks, where a trigger can propagate malicious effects across multiple output modalities. Specifically, we present the Token by Token Backdoor Attack (ToBAC), the first backdoor attack targeting","authors_text":"Anna Rohrbach, Hossein Shakibania, Jonas Henry Grebe, Marcus Rohrbach, Tobias Braun","cross_cats":["cs.AI"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-19T00:55:18Z","title":"Token by Token, Compromised: Backdoor Vulnerabilities in Unified Autoregressive Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.19227","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:1efd8323ea61fa58768f63e84fb471760b98fa688957f8cfbb9ecd91aa26f013","target":"record","created_at":"2026-05-20T01:05:34Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"7885d2f3a4812c2be72cd485440b31a162c1482e8e5016e99bfcf6bd25dac870","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-19T00:55:18Z","title_canon_sha256":"21da0e6e52f6fb70077acdadcdb0f5b78da38ab4fe9a11553837ae93597a3a68"},"schema_version":"1.0","source":{"id":"2605.19227","kind":"arxiv","version":1}},"canonical_sha256":"206ffc3eee554477bee947b32a22a74695b2ce664675023656003767c788f51f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"206ffc3eee554477bee947b32a22a74695b2ce664675023656003767c788f51f","first_computed_at":"2026-05-20T01:05:34.476394Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T01:05:34.476394Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"FZCogM4owHz/gRdO4Ym5JSZ9owtUZ5qbzhM12HhpMboJ1DPTHwOzsoq9Q8RIIb78fb2QuZ9CyWYnTWtIrh9MBw==","signature_status":"signed_v1","signed_at":"2026-05-20T01:05:34.477050Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.19227","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:1efd8323ea61fa58768f63e84fb471760b98fa688957f8cfbb9ecd91aa26f013","sha256:8f91e222e0937544e92e2be8eddeb45d7ff3f93f67230f1201137fcd984d5236"],"state_sha256":"93a26b7ebbf9ce85ede5ee9d5de28df33b93deaebf0906fbc00d685506d8cab8"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"EBQb6luGrg7XC5g9NoYHNu5BJSX6HDul3kTHE6MQLooRLd5PQNALjd4x1/Q03zHuIkkrCFJiyp6qM+kFA4GSAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-26T00:38:33.937376Z","bundle_sha256":"3a24958ef619cbe9abe92c71f82b5adbc9df7f461556d6d9ce3ceafad8785d91"}}