{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:EOJTVBPBIDA3KXOX7HXECCRCZ5","short_pith_number":"pith:EOJTVBPB","canonical_record":{"source":{"id":"2606.08661","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-07T15:05:22Z","cross_cats_sorted":["cs.AI","cs.DB"],"title_canon_sha256":"81007068e2cc2f07a4b393d771c4f0f1056f2b6d3af80555a8e032b5a17ccba0","abstract_canon_sha256":"4aaa011aa887c76ffbf7c8619607d8d252d5e5eaba727f5a963dd42eb0ea7cce"},"schema_version":"1.0"},"canonical_sha256":"23933a85e140c1b55dd7f9ee410a22cf6e49d67f6d1669525b02f4380e3fb935","source":{"kind":"arxiv","id":"2606.08661","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.08661","created_at":"2026-06-09T01:05:43Z"},{"alias_kind":"arxiv_version","alias_value":"2606.08661v1","created_at":"2026-06-09T01:05:43Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.08661","created_at":"2026-06-09T01:05:43Z"},{"alias_kind":"pith_short_12","alias_value":"EOJTVBPBIDA3","created_at":"2026-06-09T01:05:43Z"},{"alias_kind":"pith_short_16","alias_value":"EOJTVBPBIDA3KXOX","created_at":"2026-06-09T01:05:43Z"},{"alias_kind":"pith_short_8","alias_value":"EOJTVBPB","created_at":"2026-06-09T01:05:43Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:EOJTVBPBIDA3KXOX7HXECCRCZ5","target":"record","payload":{"canonical_record":{"source":{"id":"2606.08661","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-07T15:05:22Z","cross_cats_sorted":["cs.AI","cs.DB"],"title_canon_sha256":"81007068e2cc2f07a4b393d771c4f0f1056f2b6d3af80555a8e032b5a17ccba0","abstract_canon_sha256":"4aaa011aa887c76ffbf7c8619607d8d252d5e5eaba727f5a963dd42eb0ea7cce"},"schema_version":"1.0"},"canonical_sha256":"23933a85e140c1b55dd7f9ee410a22cf6e49d67f6d1669525b02f4380e3fb935","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-09T01:05:43.062116Z","signature_b64":"K0s106ZLAzCVJBOogrcbpWGzHnHD7V/vB5SfDued7LVSlTOdHbwtxQEvW07mwWzDfzNC13/jCUdmUvftqQjMDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"23933a85e140c1b55dd7f9ee410a22cf6e49d67f6d1669525b02f4380e3fb935","last_reissued_at":"2026-06-09T01:05:43.061714Z","signature_status":"signed_v1","first_computed_at":"2026-06-09T01:05:43.061714Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.08661","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T01:05:43Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"icyoZsEKQW0in9Vb8B+IA94o7qu95P0XAqgGQ99bvhLyprA3cS0/em2AH40b58Y9sgtUuD91PvNN1v1OwvfcCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-01T13:42:18.703351Z"},"content_sha256":"283996099e17af807dd59bab74e8eaf5d08810ce4b76448e8b2c7a13baf87b6b","schema_version":"1.0","event_id":"sha256:283996099e17af807dd59bab74e8eaf5d08810ce4b76448e8b2c7a13baf87b6b"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:EOJTVBPBIDA3KXOX7HXECCRCZ5","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Data Agents Under Attack: Vulnerabilities in LLM-Driven Analytical Systems","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.DB"],"primary_cat":"cs.CR","authors_text":"Gao Cong, Guoliang Li, Haoyang Li, Kuncan Wang, Peizhuo Lv, Wei Dong, Ziting Wang","submitted_at":"2026-06-07T15:05:22Z","abstract_excerpt":"Data agents integrate LLM-driven reasoning with relational data access, executable analytical tools, and multi-step workflow orchestration, making them increasingly central to enterprise analytics. This integration introduces new security vulnerabilities across data resources, database execution, and agent reasoning, recombining concerns from database security and general-purpose LLM-agent security into failure modes that neither line of work captures on its own. To address this gap, we present a systematic security study of data agents. Our contributions are threefold. First, we develop a lay"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.08661","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.08661/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T01:05:43Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"d85KY+ZF2RtV5ZehfkJ6swdo8JrFIcuPWiHSXz8L9JKKoJ5MXXWw5IAPEEWO0noYuGv3rrtcGS7PaUDKzNmtBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-01T13:42:18.703751Z"},"content_sha256":"9e0ebe5bd0a5fffd87d15009d03cdd029c7f2b9e3a143ce223f71ac06acaaba0","schema_version":"1.0","event_id":"sha256:9e0ebe5bd0a5fffd87d15009d03cdd029c7f2b9e3a143ce223f71ac06acaaba0"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/EOJTVBPBIDA3KXOX7HXECCRCZ5/bundle.json","state_url":"https://pith.science/pith/EOJTVBPBIDA3KXOX7HXECCRCZ5/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/EOJTVBPBIDA3KXOX7HXECCRCZ5/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-01T13:42:18Z","links":{"resolver":"https://pith.science/pith/EOJTVBPBIDA3KXOX7HXECCRCZ5","bundle":"https://pith.science/pith/EOJTVBPBIDA3KXOX7HXECCRCZ5/bundle.json","state":"https://pith.science/pith/EOJTVBPBIDA3KXOX7HXECCRCZ5/state.json","well_known_bundle":"https://pith.science/.well-known/pith/EOJTVBPBIDA3KXOX7HXECCRCZ5/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:EOJTVBPBIDA3KXOX7HXECCRCZ5","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"4aaa011aa887c76ffbf7c8619607d8d252d5e5eaba727f5a963dd42eb0ea7cce","cross_cats_sorted":["cs.AI","cs.DB"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-07T15:05:22Z","title_canon_sha256":"81007068e2cc2f07a4b393d771c4f0f1056f2b6d3af80555a8e032b5a17ccba0"},"schema_version":"1.0","source":{"id":"2606.08661","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.08661","created_at":"2026-06-09T01:05:43Z"},{"alias_kind":"arxiv_version","alias_value":"2606.08661v1","created_at":"2026-06-09T01:05:43Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.08661","created_at":"2026-06-09T01:05:43Z"},{"alias_kind":"pith_short_12","alias_value":"EOJTVBPBIDA3","created_at":"2026-06-09T01:05:43Z"},{"alias_kind":"pith_short_16","alias_value":"EOJTVBPBIDA3KXOX","created_at":"2026-06-09T01:05:43Z"},{"alias_kind":"pith_short_8","alias_value":"EOJTVBPB","created_at":"2026-06-09T01:05:43Z"}],"graph_snapshots":[{"event_id":"sha256:9e0ebe5bd0a5fffd87d15009d03cdd029c7f2b9e3a143ce223f71ac06acaaba0","target":"graph","created_at":"2026-06-09T01:05:43Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.08661/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Data agents integrate LLM-driven reasoning with relational data access, executable analytical tools, and multi-step workflow orchestration, making them increasingly central to enterprise analytics. This integration introduces new security vulnerabilities across data resources, database execution, and agent reasoning, recombining concerns from database security and general-purpose LLM-agent security into failure modes that neither line of work captures on its own. To address this gap, we present a systematic security study of data agents. Our contributions are threefold. First, we develop a lay","authors_text":"Gao Cong, Guoliang Li, Haoyang Li, Kuncan Wang, Peizhuo Lv, Wei Dong, Ziting Wang","cross_cats":["cs.AI","cs.DB"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-07T15:05:22Z","title":"Data Agents Under Attack: Vulnerabilities in LLM-Driven Analytical Systems"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.08661","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:283996099e17af807dd59bab74e8eaf5d08810ce4b76448e8b2c7a13baf87b6b","target":"record","created_at":"2026-06-09T01:05:43Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"4aaa011aa887c76ffbf7c8619607d8d252d5e5eaba727f5a963dd42eb0ea7cce","cross_cats_sorted":["cs.AI","cs.DB"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-07T15:05:22Z","title_canon_sha256":"81007068e2cc2f07a4b393d771c4f0f1056f2b6d3af80555a8e032b5a17ccba0"},"schema_version":"1.0","source":{"id":"2606.08661","kind":"arxiv","version":1}},"canonical_sha256":"23933a85e140c1b55dd7f9ee410a22cf6e49d67f6d1669525b02f4380e3fb935","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"23933a85e140c1b55dd7f9ee410a22cf6e49d67f6d1669525b02f4380e3fb935","first_computed_at":"2026-06-09T01:05:43.061714Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-09T01:05:43.061714Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"K0s106ZLAzCVJBOogrcbpWGzHnHD7V/vB5SfDued7LVSlTOdHbwtxQEvW07mwWzDfzNC13/jCUdmUvftqQjMDw==","signature_status":"signed_v1","signed_at":"2026-06-09T01:05:43.062116Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.08661","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:283996099e17af807dd59bab74e8eaf5d08810ce4b76448e8b2c7a13baf87b6b","sha256:9e0ebe5bd0a5fffd87d15009d03cdd029c7f2b9e3a143ce223f71ac06acaaba0"],"state_sha256":"beeceaa97c9653c36e6e1808bf4215f114b8c7d8a524b64f2933795411f3e839"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"DCfH4+kafru5LJ8qGlWy+95Bulg+/UNkP+F1vycjFdAuEoodxRwY1UpWqgZ5b6vXthLSvQ1OuWgvrLGEs+IDCQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-01T13:42:18.706030Z","bundle_sha256":"9d21d84b277f5cd1d8904069c0e807503fc5b56626048a8c942e246770a6f6cb"}}