{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:F6GLZS5PVYPJ4NNWCDAIS7IZ7P","short_pith_number":"pith:F6GLZS5P","canonical_record":{"source":{"id":"2606.10846","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-09T13:28:53Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"2418a7f804c2d3625546f3b5c7133c1a191e8c695bec399706bdfbb12479d626","abstract_canon_sha256":"3d620c92dd48b0b7131ce87833e77ce564a210c60d26432654cc94b787653665"},"schema_version":"1.0"},"canonical_sha256":"2f8cbccbafae1e9e35b610c0897d19fbcc9da891cae9f07b0337973abf666d35","source":{"kind":"arxiv","id":"2606.10846","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.10846","created_at":"2026-06-10T01:10:43Z"},{"alias_kind":"arxiv_version","alias_value":"2606.10846v1","created_at":"2026-06-10T01:10:43Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.10846","created_at":"2026-06-10T01:10:43Z"},{"alias_kind":"pith_short_12","alias_value":"F6GLZS5PVYPJ","created_at":"2026-06-10T01:10:43Z"},{"alias_kind":"pith_short_16","alias_value":"F6GLZS5PVYPJ4NNW","created_at":"2026-06-10T01:10:43Z"},{"alias_kind":"pith_short_8","alias_value":"F6GLZS5P","created_at":"2026-06-10T01:10:43Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:F6GLZS5PVYPJ4NNWCDAIS7IZ7P","target":"record","payload":{"canonical_record":{"source":{"id":"2606.10846","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-09T13:28:53Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"2418a7f804c2d3625546f3b5c7133c1a191e8c695bec399706bdfbb12479d626","abstract_canon_sha256":"3d620c92dd48b0b7131ce87833e77ce564a210c60d26432654cc94b787653665"},"schema_version":"1.0"},"canonical_sha256":"2f8cbccbafae1e9e35b610c0897d19fbcc9da891cae9f07b0337973abf666d35","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-10T01:10:43.715743Z","signature_b64":"RETxJu31uG/BODhi1NZas+JBQLsSZ8ReB27yNRh/DFb3KD4fh+PLOzgdmuJxOLz6U+BxPDk98gz9VfHK42VKAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2f8cbccbafae1e9e35b610c0897d19fbcc9da891cae9f07b0337973abf666d35","last_reissued_at":"2026-06-10T01:10:43.714861Z","signature_status":"signed_v1","first_computed_at":"2026-06-10T01:10:43.714861Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.10846","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-10T01:10:43Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"n7s0lnTECmcDGRx4d9zOqGjBmoonUg5huSOzHWTbHy2rgzffgVhcJrZXFQQXoIbYBSeWmvOYC1nfedXHK4TyBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-11T13:19:03.297265Z"},"content_sha256":"47ef75c8e4c6437cf2fd18908d25d2fa1b08eb199404780661c334d0beb5cf2a","schema_version":"1.0","event_id":"sha256:47ef75c8e4c6437cf2fd18908d25d2fa1b08eb199404780661c334d0beb5cf2a"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:F6GLZS5PVYPJ4NNWCDAIS7IZ7P","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Securing Code Understanding: Detecting Natural Backdoor Vulnerability in Code Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.SE"],"primary_cat":"cs.CR","authors_text":"An Guo, Baowen Xu, Chunrong Fang, Haocheng Huang, Peizhuo Lv, Tingting Xu, Weisong Sun, Xiaofang Zhang, Yang Liu, Yiran Zhang, Yuan Xiao, Yuchen Chen, Zhenpeng Chen, Zhenyu Chen","submitted_at":"2026-06-09T13:28:53Z","abstract_excerpt":"Code Language Models (CodeLMs) have become integral to software engineering, significantly advancing code intelligence tasks. However, their widespread adoption has raised critical security concerns, particularly regarding susceptibility to backdoor attacks. Recent studies have uncovered naturally occurring backdoors, referred to as natural backdoors, in normally trained deep learning models. Despite posing threats as serious as those introduced through data poisoning, security implications of natural backdoor vulnerabilities in CodeLMs remain poorly understood.\n  In this paper, we conduct a t"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.10846","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.10846/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-10T01:10:43Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"84ihxCVJWZdEnMtMsoFFPiT61oMzpvAopE6wI+2wdV7+78SbIls0fv3BTmjSdspimjlqg6aioPTFSW4ZcwrABA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-11T13:19:03.297729Z"},"content_sha256":"44d810346356e6755aadc8d35a20f610fa8b910e5a3e190abaf7f9ff01585645","schema_version":"1.0","event_id":"sha256:44d810346356e6755aadc8d35a20f610fa8b910e5a3e190abaf7f9ff01585645"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/F6GLZS5PVYPJ4NNWCDAIS7IZ7P/bundle.json","state_url":"https://pith.science/pith/F6GLZS5PVYPJ4NNWCDAIS7IZ7P/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/F6GLZS5PVYPJ4NNWCDAIS7IZ7P/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-11T13:19:03Z","links":{"resolver":"https://pith.science/pith/F6GLZS5PVYPJ4NNWCDAIS7IZ7P","bundle":"https://pith.science/pith/F6GLZS5PVYPJ4NNWCDAIS7IZ7P/bundle.json","state":"https://pith.science/pith/F6GLZS5PVYPJ4NNWCDAIS7IZ7P/state.json","well_known_bundle":"https://pith.science/.well-known/pith/F6GLZS5PVYPJ4NNWCDAIS7IZ7P/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:F6GLZS5PVYPJ4NNWCDAIS7IZ7P","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"3d620c92dd48b0b7131ce87833e77ce564a210c60d26432654cc94b787653665","cross_cats_sorted":["cs.SE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-09T13:28:53Z","title_canon_sha256":"2418a7f804c2d3625546f3b5c7133c1a191e8c695bec399706bdfbb12479d626"},"schema_version":"1.0","source":{"id":"2606.10846","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.10846","created_at":"2026-06-10T01:10:43Z"},{"alias_kind":"arxiv_version","alias_value":"2606.10846v1","created_at":"2026-06-10T01:10:43Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.10846","created_at":"2026-06-10T01:10:43Z"},{"alias_kind":"pith_short_12","alias_value":"F6GLZS5PVYPJ","created_at":"2026-06-10T01:10:43Z"},{"alias_kind":"pith_short_16","alias_value":"F6GLZS5PVYPJ4NNW","created_at":"2026-06-10T01:10:43Z"},{"alias_kind":"pith_short_8","alias_value":"F6GLZS5P","created_at":"2026-06-10T01:10:43Z"}],"graph_snapshots":[{"event_id":"sha256:44d810346356e6755aadc8d35a20f610fa8b910e5a3e190abaf7f9ff01585645","target":"graph","created_at":"2026-06-10T01:10:43Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.10846/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Code Language Models (CodeLMs) have become integral to software engineering, significantly advancing code intelligence tasks. However, their widespread adoption has raised critical security concerns, particularly regarding susceptibility to backdoor attacks. Recent studies have uncovered naturally occurring backdoors, referred to as natural backdoors, in normally trained deep learning models. Despite posing threats as serious as those introduced through data poisoning, security implications of natural backdoor vulnerabilities in CodeLMs remain poorly understood.\n  In this paper, we conduct a t","authors_text":"An Guo, Baowen Xu, Chunrong Fang, Haocheng Huang, Peizhuo Lv, Tingting Xu, Weisong Sun, Xiaofang Zhang, Yang Liu, Yiran Zhang, Yuan Xiao, Yuchen Chen, Zhenpeng Chen, Zhenyu Chen","cross_cats":["cs.SE"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-09T13:28:53Z","title":"Securing Code Understanding: Detecting Natural Backdoor Vulnerability in Code Language Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.10846","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:47ef75c8e4c6437cf2fd18908d25d2fa1b08eb199404780661c334d0beb5cf2a","target":"record","created_at":"2026-06-10T01:10:43Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"3d620c92dd48b0b7131ce87833e77ce564a210c60d26432654cc94b787653665","cross_cats_sorted":["cs.SE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-09T13:28:53Z","title_canon_sha256":"2418a7f804c2d3625546f3b5c7133c1a191e8c695bec399706bdfbb12479d626"},"schema_version":"1.0","source":{"id":"2606.10846","kind":"arxiv","version":1}},"canonical_sha256":"2f8cbccbafae1e9e35b610c0897d19fbcc9da891cae9f07b0337973abf666d35","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"2f8cbccbafae1e9e35b610c0897d19fbcc9da891cae9f07b0337973abf666d35","first_computed_at":"2026-06-10T01:10:43.714861Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-10T01:10:43.714861Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"RETxJu31uG/BODhi1NZas+JBQLsSZ8ReB27yNRh/DFb3KD4fh+PLOzgdmuJxOLz6U+BxPDk98gz9VfHK42VKAw==","signature_status":"signed_v1","signed_at":"2026-06-10T01:10:43.715743Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.10846","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:47ef75c8e4c6437cf2fd18908d25d2fa1b08eb199404780661c334d0beb5cf2a","sha256:44d810346356e6755aadc8d35a20f610fa8b910e5a3e190abaf7f9ff01585645"],"state_sha256":"80ab8aec230aa428de30e797e039799ea5320678910f3902e197943d787d38dd"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"t9r/DCWk7QpK7mbFtpoK+gbeFC/wqfzfb5wSaDxbJbu2l6i2EJ7Txt90TZ6sEtr7zbC7Mc56j61WuqFxI+3xCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-11T13:19:03.300658Z","bundle_sha256":"1ecb19ebc51aae3ef503c99e94602ac5645bcab0b50e888867a9ae3322ae3412"}}