{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:EVOAK5DPMU732LSAUBXTZ44AGY","short_pith_number":"pith:EVOAK5DP","canonical_record":{"source":{"id":"2605.24421","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-23T06:21:10Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"16f68ddb20df2cd1c9be7769fdde38289bfb452cb6f7a34624f836c0efba658e","abstract_canon_sha256":"ceb4209e48685ef6a8f9b0193bdd6c57f0ed654f4acaf672958d96a9bcb77c70"},"schema_version":"1.0"},"canonical_sha256":"255c05746f653fbd2e40a06f3cf380361ce7cbec7630c99f07c8e5ef8cbaf90a","source":{"kind":"arxiv","id":"2605.24421","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.24421","created_at":"2026-05-26T01:03:38Z"},{"alias_kind":"arxiv_version","alias_value":"2605.24421v1","created_at":"2026-05-26T01:03:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.24421","created_at":"2026-05-26T01:03:38Z"},{"alias_kind":"pith_short_12","alias_value":"EVOAK5DPMU73","created_at":"2026-05-26T01:03:38Z"},{"alias_kind":"pith_short_16","alias_value":"EVOAK5DPMU732LSA","created_at":"2026-05-26T01:03:38Z"},{"alias_kind":"pith_short_8","alias_value":"EVOAK5DP","created_at":"2026-05-26T01:03:38Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:EVOAK5DPMU732LSAUBXTZ44AGY","target":"record","payload":{"canonical_record":{"source":{"id":"2605.24421","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-23T06:21:10Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"16f68ddb20df2cd1c9be7769fdde38289bfb452cb6f7a34624f836c0efba658e","abstract_canon_sha256":"ceb4209e48685ef6a8f9b0193bdd6c57f0ed654f4acaf672958d96a9bcb77c70"},"schema_version":"1.0"},"canonical_sha256":"255c05746f653fbd2e40a06f3cf380361ce7cbec7630c99f07c8e5ef8cbaf90a","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T01:03:38.875720Z","signature_b64":"GIK+elZqabkIhTXyecwfg+30N0UnGeB4hx9SWGsFU44MxiA3UShDbEi1yaDI5tW0+TTPqQyo6fbNJKkCHNyRAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"255c05746f653fbd2e40a06f3cf380361ce7cbec7630c99f07c8e5ef8cbaf90a","last_reissued_at":"2026-05-26T01:03:38.874925Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T01:03:38.874925Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.24421","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T01:03:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"s40PDGjc0ooErA44FHZWRgDW+hhJ52igSWrao3Mpyr2XTGeHJcWZ30pB2abqX1vOGpyLoP3Qz3gC4tGESNijBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T11:42:45.084625Z"},"content_sha256":"c6c96e9e00568b52d3791d3c2d195cafb9f9e8873eab83b343465d69c68d61e8","schema_version":"1.0","event_id":"sha256:c6c96e9e00568b52d3791d3c2d195cafb9f9e8873eab83b343465d69c68d61e8"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:EVOAK5DPMU732LSAUBXTZ44AGY","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Poisoning the Watchtower: Prompt Injection Attacks Against LLM-Augmented Security Operations Through Adversarial Log Content","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Archit Bhujang, Rohan Pandey","submitted_at":"2026-05-23T06:21:10Z","abstract_excerpt":"Large language models (LLMs) are increasingly used as analyst assistants in security operations centers (SOCs), where they ingest log and alert data to produce triage labels, incident summaries, or remediation advice. We study a structural failure mode of this design: many log fields are attacker controlled. User agents, URLs, payloads, DNS queries, and attempted usernames can therefore carry instructions to the model alongside evidence of the intrusion. We call this setting \\emph{log-substrate prompt injection}. We introduce a four-class taxonomy of log-substrate attacks: direct override (S1)"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.24421","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.24421/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T01:03:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"VZixCvpsQb1ZEBSYqo4/n+p7skC+RVVht6KUk080sHDocUC6jQoTM2HMNUDgPdIgXefojMB/lZFUTbzcIgsgDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T11:42:45.085039Z"},"content_sha256":"a12953df66963e0ee8e8c32d09bdbf57a9ee6ad2139f1c17c810e9a3816a0683","schema_version":"1.0","event_id":"sha256:a12953df66963e0ee8e8c32d09bdbf57a9ee6ad2139f1c17c810e9a3816a0683"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/EVOAK5DPMU732LSAUBXTZ44AGY/bundle.json","state_url":"https://pith.science/pith/EVOAK5DPMU732LSAUBXTZ44AGY/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/EVOAK5DPMU732LSAUBXTZ44AGY/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-02T11:42:45Z","links":{"resolver":"https://pith.science/pith/EVOAK5DPMU732LSAUBXTZ44AGY","bundle":"https://pith.science/pith/EVOAK5DPMU732LSAUBXTZ44AGY/bundle.json","state":"https://pith.science/pith/EVOAK5DPMU732LSAUBXTZ44AGY/state.json","well_known_bundle":"https://pith.science/.well-known/pith/EVOAK5DPMU732LSAUBXTZ44AGY/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:EVOAK5DPMU732LSAUBXTZ44AGY","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ceb4209e48685ef6a8f9b0193bdd6c57f0ed654f4acaf672958d96a9bcb77c70","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-23T06:21:10Z","title_canon_sha256":"16f68ddb20df2cd1c9be7769fdde38289bfb452cb6f7a34624f836c0efba658e"},"schema_version":"1.0","source":{"id":"2605.24421","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.24421","created_at":"2026-05-26T01:03:38Z"},{"alias_kind":"arxiv_version","alias_value":"2605.24421v1","created_at":"2026-05-26T01:03:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.24421","created_at":"2026-05-26T01:03:38Z"},{"alias_kind":"pith_short_12","alias_value":"EVOAK5DPMU73","created_at":"2026-05-26T01:03:38Z"},{"alias_kind":"pith_short_16","alias_value":"EVOAK5DPMU732LSA","created_at":"2026-05-26T01:03:38Z"},{"alias_kind":"pith_short_8","alias_value":"EVOAK5DP","created_at":"2026-05-26T01:03:38Z"}],"graph_snapshots":[{"event_id":"sha256:a12953df66963e0ee8e8c32d09bdbf57a9ee6ad2139f1c17c810e9a3816a0683","target":"graph","created_at":"2026-05-26T01:03:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.24421/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language models (LLMs) are increasingly used as analyst assistants in security operations centers (SOCs), where they ingest log and alert data to produce triage labels, incident summaries, or remediation advice. We study a structural failure mode of this design: many log fields are attacker controlled. User agents, URLs, payloads, DNS queries, and attempted usernames can therefore carry instructions to the model alongside evidence of the intrusion. We call this setting \\emph{log-substrate prompt injection}. We introduce a four-class taxonomy of log-substrate attacks: direct override (S1)","authors_text":"Archit Bhujang, Rohan Pandey","cross_cats":["cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-23T06:21:10Z","title":"Poisoning the Watchtower: Prompt Injection Attacks Against LLM-Augmented Security Operations Through Adversarial Log Content"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.24421","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:c6c96e9e00568b52d3791d3c2d195cafb9f9e8873eab83b343465d69c68d61e8","target":"record","created_at":"2026-05-26T01:03:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ceb4209e48685ef6a8f9b0193bdd6c57f0ed654f4acaf672958d96a9bcb77c70","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-23T06:21:10Z","title_canon_sha256":"16f68ddb20df2cd1c9be7769fdde38289bfb452cb6f7a34624f836c0efba658e"},"schema_version":"1.0","source":{"id":"2605.24421","kind":"arxiv","version":1}},"canonical_sha256":"255c05746f653fbd2e40a06f3cf380361ce7cbec7630c99f07c8e5ef8cbaf90a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"255c05746f653fbd2e40a06f3cf380361ce7cbec7630c99f07c8e5ef8cbaf90a","first_computed_at":"2026-05-26T01:03:38.874925Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-26T01:03:38.874925Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"GIK+elZqabkIhTXyecwfg+30N0UnGeB4hx9SWGsFU44MxiA3UShDbEi1yaDI5tW0+TTPqQyo6fbNJKkCHNyRAQ==","signature_status":"signed_v1","signed_at":"2026-05-26T01:03:38.875720Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.24421","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:c6c96e9e00568b52d3791d3c2d195cafb9f9e8873eab83b343465d69c68d61e8","sha256:a12953df66963e0ee8e8c32d09bdbf57a9ee6ad2139f1c17c810e9a3816a0683"],"state_sha256":"93d5ad90ecf54893cc5bd3e59965860631880bec10eca8d146885cb353b9bcc3"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"OW0h23ha7nmLemyg+geKRBUBLSo2L5H8CPk7N658/Jn2JmMjpqgbx4a4FdWSeIBCdGtO9JvtQk4InMTSIvoHCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-02T11:42:45.087185Z","bundle_sha256":"461e6304d6a358f5ab131aa054359a0be87f859e8b5cab25ba9da53eb05dc63e"}}