{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:EYDIHOPAOJXIYKVQD7U2K6Z5PV","short_pith_number":"pith:EYDIHOPA","canonical_record":{"source":{"id":"2606.29239","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-28T07:06:46Z","cross_cats_sorted":[],"title_canon_sha256":"bf886c08fcca65395c3e8bd987924b5675c88a99a706a95ed64b53cac9bfa5bf","abstract_canon_sha256":"764c42afa33807a34599a76d046e38befc0a7671e39d628e120e916f2e8f6449"},"schema_version":"1.0"},"canonical_sha256":"260683b9e0726e8c2ab01fe9a57b3d7d7857e1ce9e89709158e01378021f62a2","source":{"kind":"arxiv","id":"2606.29239","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.29239","created_at":"2026-06-30T01:17:58Z"},{"alias_kind":"arxiv_version","alias_value":"2606.29239v1","created_at":"2026-06-30T01:17:58Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.29239","created_at":"2026-06-30T01:17:58Z"},{"alias_kind":"pith_short_12","alias_value":"EYDIHOPAOJXI","created_at":"2026-06-30T01:17:58Z"},{"alias_kind":"pith_short_16","alias_value":"EYDIHOPAOJXIYKVQ","created_at":"2026-06-30T01:17:58Z"},{"alias_kind":"pith_short_8","alias_value":"EYDIHOPA","created_at":"2026-06-30T01:17:58Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:EYDIHOPAOJXIYKVQD7U2K6Z5PV","target":"record","payload":{"canonical_record":{"source":{"id":"2606.29239","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-28T07:06:46Z","cross_cats_sorted":[],"title_canon_sha256":"bf886c08fcca65395c3e8bd987924b5675c88a99a706a95ed64b53cac9bfa5bf","abstract_canon_sha256":"764c42afa33807a34599a76d046e38befc0a7671e39d628e120e916f2e8f6449"},"schema_version":"1.0"},"canonical_sha256":"260683b9e0726e8c2ab01fe9a57b3d7d7857e1ce9e89709158e01378021f62a2","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-30T01:17:58.570600Z","signature_b64":"tYKZZewYtuUYq0ZdBVGtlYzUmzNsln736W32XLbxej00C582h2r+Bmswb/knRgz/N7KZ8jxm9zAItIamukpnAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"260683b9e0726e8c2ab01fe9a57b3d7d7857e1ce9e89709158e01378021f62a2","last_reissued_at":"2026-06-30T01:17:58.569848Z","signature_status":"signed_v1","first_computed_at":"2026-06-30T01:17:58.569848Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.29239","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-30T01:17:58Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"lOh2XkcuMDCIEvSn8ChchamWPhyzX6ZtdTLi2HwB3pgXUSgj2QO9pGeMya7bT1W/0czr6Z8/ux7bsYTTBJFkBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T21:31:39.894416Z"},"content_sha256":"72a9897eeb67fa029b4e2ebb5bb83e4a43b5f90db24b84b475133e6f424343be","schema_version":"1.0","event_id":"sha256:72a9897eeb67fa029b4e2ebb5bb83e4a43b5f90db24b84b475133e6f424343be"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:EYDIHOPAOJXIYKVQD7U2K6Z5PV","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Breaking the Rounding Trap: Securing LLMs against Quantization-Conditioned Backdoors","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Anqi Du, Aoying Zheng, Yuxuan Chen, Zizhuang Deng","submitted_at":"2026-06-28T07:06:46Z","abstract_excerpt":"Model quantization is a key technique for reducing storage and inference costs when deploying large language models in practice. However, recent studies show that the discretization and rounding errors introduced by quantization can be exploited by adversaries to construct quantization-conditioned backdoor (QCB) attacks. Under such attacks, malicious behaviors remain dormant in the full-precision stage and are activated only after quantized deployment, thereby bypassing conventional security auditing and detection mechanisms. To address this threat, we propose a proactive pre-quantization defe"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.29239","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.29239/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-30T01:17:58Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"MdQXBpg3viWTDFEu78UFgbldOxSruzpsJFHTApqPA3MBa2nI3GbXSKdoeBUcWFbhSsttzwYl0mtDx67VS3ypBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T21:31:39.894789Z"},"content_sha256":"e5d965910fd76b303e1fd42a6fd36bf76bb0535bde264492d43504594c668b45","schema_version":"1.0","event_id":"sha256:e5d965910fd76b303e1fd42a6fd36bf76bb0535bde264492d43504594c668b45"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/EYDIHOPAOJXIYKVQD7U2K6Z5PV/bundle.json","state_url":"https://pith.science/pith/EYDIHOPAOJXIYKVQD7U2K6Z5PV/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/EYDIHOPAOJXIYKVQD7U2K6Z5PV/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-30T21:31:39Z","links":{"resolver":"https://pith.science/pith/EYDIHOPAOJXIYKVQD7U2K6Z5PV","bundle":"https://pith.science/pith/EYDIHOPAOJXIYKVQD7U2K6Z5PV/bundle.json","state":"https://pith.science/pith/EYDIHOPAOJXIYKVQD7U2K6Z5PV/state.json","well_known_bundle":"https://pith.science/.well-known/pith/EYDIHOPAOJXIYKVQD7U2K6Z5PV/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:EYDIHOPAOJXIYKVQD7U2K6Z5PV","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"764c42afa33807a34599a76d046e38befc0a7671e39d628e120e916f2e8f6449","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-28T07:06:46Z","title_canon_sha256":"bf886c08fcca65395c3e8bd987924b5675c88a99a706a95ed64b53cac9bfa5bf"},"schema_version":"1.0","source":{"id":"2606.29239","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.29239","created_at":"2026-06-30T01:17:58Z"},{"alias_kind":"arxiv_version","alias_value":"2606.29239v1","created_at":"2026-06-30T01:17:58Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.29239","created_at":"2026-06-30T01:17:58Z"},{"alias_kind":"pith_short_12","alias_value":"EYDIHOPAOJXI","created_at":"2026-06-30T01:17:58Z"},{"alias_kind":"pith_short_16","alias_value":"EYDIHOPAOJXIYKVQ","created_at":"2026-06-30T01:17:58Z"},{"alias_kind":"pith_short_8","alias_value":"EYDIHOPA","created_at":"2026-06-30T01:17:58Z"}],"graph_snapshots":[{"event_id":"sha256:e5d965910fd76b303e1fd42a6fd36bf76bb0535bde264492d43504594c668b45","target":"graph","created_at":"2026-06-30T01:17:58Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.29239/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Model quantization is a key technique for reducing storage and inference costs when deploying large language models in practice. However, recent studies show that the discretization and rounding errors introduced by quantization can be exploited by adversaries to construct quantization-conditioned backdoor (QCB) attacks. Under such attacks, malicious behaviors remain dormant in the full-precision stage and are activated only after quantized deployment, thereby bypassing conventional security auditing and detection mechanisms. To address this threat, we propose a proactive pre-quantization defe","authors_text":"Anqi Du, Aoying Zheng, Yuxuan Chen, Zizhuang Deng","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-28T07:06:46Z","title":"Breaking the Rounding Trap: Securing LLMs against Quantization-Conditioned Backdoors"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.29239","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:72a9897eeb67fa029b4e2ebb5bb83e4a43b5f90db24b84b475133e6f424343be","target":"record","created_at":"2026-06-30T01:17:58Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"764c42afa33807a34599a76d046e38befc0a7671e39d628e120e916f2e8f6449","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-28T07:06:46Z","title_canon_sha256":"bf886c08fcca65395c3e8bd987924b5675c88a99a706a95ed64b53cac9bfa5bf"},"schema_version":"1.0","source":{"id":"2606.29239","kind":"arxiv","version":1}},"canonical_sha256":"260683b9e0726e8c2ab01fe9a57b3d7d7857e1ce9e89709158e01378021f62a2","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"260683b9e0726e8c2ab01fe9a57b3d7d7857e1ce9e89709158e01378021f62a2","first_computed_at":"2026-06-30T01:17:58.569848Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-30T01:17:58.569848Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"tYKZZewYtuUYq0ZdBVGtlYzUmzNsln736W32XLbxej00C582h2r+Bmswb/knRgz/N7KZ8jxm9zAItIamukpnAQ==","signature_status":"signed_v1","signed_at":"2026-06-30T01:17:58.570600Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.29239","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:72a9897eeb67fa029b4e2ebb5bb83e4a43b5f90db24b84b475133e6f424343be","sha256:e5d965910fd76b303e1fd42a6fd36bf76bb0535bde264492d43504594c668b45"],"state_sha256":"bd3e9d29a8d3e5fff5c84e67fe4a5c3d7109fa97b5eb740a88dfda6f038db9cf"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"5QuMV84ldKwKF1YQXXOCeLRbMzdyHXVEoJ4H8Bx9Kot0qYz2D0j3jmry8r/Qxx06dJKy40GuA0IDIEqpa5EACg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-30T21:31:39.896836Z","bundle_sha256":"1222c86a30009468f346b041c7f9a5f9481e53677eddc435a5162f0470cecd14"}}