{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:F6UQC3U6E6QOM5U564JNNBWHGG","short_pith_number":"pith:F6UQC3U6","canonical_record":{"source":{"id":"2601.19448","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-01-27T10:34:06Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"c07ab50972eb36f72cd4bc04d75d44e9cca3a655e4853b7e401b81f0011acec3","abstract_canon_sha256":"b9246d69f568d2cbd8cf7f3b82391e07817f0edfd7260023c18fc970d76a4881"},"schema_version":"1.0"},"canonical_sha256":"2fa9016e9e27a0e6769df712d686c7318b7ea41e27a4d11bff45b038e0aba202","source":{"kind":"arxiv","id":"2601.19448","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2601.19448","created_at":"2026-06-01T01:02:30Z"},{"alias_kind":"arxiv_version","alias_value":"2601.19448v2","created_at":"2026-06-01T01:02:30Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2601.19448","created_at":"2026-06-01T01:02:30Z"},{"alias_kind":"pith_short_12","alias_value":"F6UQC3U6E6QO","created_at":"2026-06-01T01:02:30Z"},{"alias_kind":"pith_short_16","alias_value":"F6UQC3U6E6QOM5U5","created_at":"2026-06-01T01:02:30Z"},{"alias_kind":"pith_short_8","alias_value":"F6UQC3U6","created_at":"2026-06-01T01:02:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:F6UQC3U6E6QOM5U564JNNBWHGG","target":"record","payload":{"canonical_record":{"source":{"id":"2601.19448","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-01-27T10:34:06Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"c07ab50972eb36f72cd4bc04d75d44e9cca3a655e4853b7e401b81f0011acec3","abstract_canon_sha256":"b9246d69f568d2cbd8cf7f3b82391e07817f0edfd7260023c18fc970d76a4881"},"schema_version":"1.0"},"canonical_sha256":"2fa9016e9e27a0e6769df712d686c7318b7ea41e27a4d11bff45b038e0aba202","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-01T01:02:30.417269Z","signature_b64":"3BgRc1A4iBQnvpAEwy1mSlVW1zJZkTlZKSrj0Y0z5Wl72+v2VKmyT6ukxHVggwpcz6zUogAtkkzr4y9FwcB2Dw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2fa9016e9e27a0e6769df712d686c7318b7ea41e27a4d11bff45b038e0aba202","last_reissued_at":"2026-06-01T01:02:30.416308Z","signature_status":"signed_v1","first_computed_at":"2026-06-01T01:02:30.416308Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2601.19448","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-01T01:02:30Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"weOyBnEYdqB2rOAYchfZQFoksWSWapYLVw1VHUYAh2+cHUrreO/F+dwcsGaWjEj4rx9tzr8gkrZOXtptEzjODg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T04:18:21.338453Z"},"content_sha256":"408346c6c1f3407746b0b533beed6a093670c41433b3a305adb62c29421c9558","schema_version":"1.0","event_id":"sha256:408346c6c1f3407746b0b533beed6a093670c41433b3a305adb62c29421c9558"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:F6UQC3U6E6QOM5U564JNNBWHGG","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"From Internal Diagnosis to External Auditing: A VLM-Driven Paradigm for Data-Free Online Backdoor Defense","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.LG","authors_text":"Binyan Xu, Di Tang, Fan Yang, Kehuan Zhang, Xilin Dai","submitted_at":"2026-01-27T10:34:06Z","abstract_excerpt":"Deep Neural Networks remain inherently vulnerable to backdoor attacks. Traditional test-time defenses largely operate under the paradigm of internal diagnosis methods like model repairing or input robustness, yet these approaches are often fragile under advanced attacks as they remain entangled with the victim model's corrupted parameters. We propose a paradigm shift from Internal Diagnosis to External Semantic Auditing, arguing that effective defense requires decoupling safety from the victim model via an independent, semantically grounded auditor. To this end, we present a framework harnessi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2601.19448","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2601.19448/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-01T01:02:30Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"l8ueJjtRi6E3A5XNLGp9dBp6AicQZIHptyzHttBFXxPQYgIDqf/R5Atr3MzEwSBrL5GcuGwBxnQoxKXbPO1iAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T04:18:21.338829Z"},"content_sha256":"eda50ee8b3e8f9336fb1ebac8cede320c198eb0cbc9f7b444f0819fc95249639","schema_version":"1.0","event_id":"sha256:eda50ee8b3e8f9336fb1ebac8cede320c198eb0cbc9f7b444f0819fc95249639"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/F6UQC3U6E6QOM5U564JNNBWHGG/bundle.json","state_url":"https://pith.science/pith/F6UQC3U6E6QOM5U564JNNBWHGG/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/F6UQC3U6E6QOM5U564JNNBWHGG/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-02T04:18:21Z","links":{"resolver":"https://pith.science/pith/F6UQC3U6E6QOM5U564JNNBWHGG","bundle":"https://pith.science/pith/F6UQC3U6E6QOM5U564JNNBWHGG/bundle.json","state":"https://pith.science/pith/F6UQC3U6E6QOM5U564JNNBWHGG/state.json","well_known_bundle":"https://pith.science/.well-known/pith/F6UQC3U6E6QOM5U564JNNBWHGG/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:F6UQC3U6E6QOM5U564JNNBWHGG","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b9246d69f568d2cbd8cf7f3b82391e07817f0edfd7260023c18fc970d76a4881","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-01-27T10:34:06Z","title_canon_sha256":"c07ab50972eb36f72cd4bc04d75d44e9cca3a655e4853b7e401b81f0011acec3"},"schema_version":"1.0","source":{"id":"2601.19448","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2601.19448","created_at":"2026-06-01T01:02:30Z"},{"alias_kind":"arxiv_version","alias_value":"2601.19448v2","created_at":"2026-06-01T01:02:30Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2601.19448","created_at":"2026-06-01T01:02:30Z"},{"alias_kind":"pith_short_12","alias_value":"F6UQC3U6E6QO","created_at":"2026-06-01T01:02:30Z"},{"alias_kind":"pith_short_16","alias_value":"F6UQC3U6E6QOM5U5","created_at":"2026-06-01T01:02:30Z"},{"alias_kind":"pith_short_8","alias_value":"F6UQC3U6","created_at":"2026-06-01T01:02:30Z"}],"graph_snapshots":[{"event_id":"sha256:eda50ee8b3e8f9336fb1ebac8cede320c198eb0cbc9f7b444f0819fc95249639","target":"graph","created_at":"2026-06-01T01:02:30Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2601.19448/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Deep Neural Networks remain inherently vulnerable to backdoor attacks. Traditional test-time defenses largely operate under the paradigm of internal diagnosis methods like model repairing or input robustness, yet these approaches are often fragile under advanced attacks as they remain entangled with the victim model's corrupted parameters. We propose a paradigm shift from Internal Diagnosis to External Semantic Auditing, arguing that effective defense requires decoupling safety from the victim model via an independent, semantically grounded auditor. To this end, we present a framework harnessi","authors_text":"Binyan Xu, Di Tang, Fan Yang, Kehuan Zhang, Xilin Dai","cross_cats":["cs.CR"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-01-27T10:34:06Z","title":"From Internal Diagnosis to External Auditing: A VLM-Driven Paradigm for Data-Free Online Backdoor Defense"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2601.19448","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:408346c6c1f3407746b0b533beed6a093670c41433b3a305adb62c29421c9558","target":"record","created_at":"2026-06-01T01:02:30Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b9246d69f568d2cbd8cf7f3b82391e07817f0edfd7260023c18fc970d76a4881","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-01-27T10:34:06Z","title_canon_sha256":"c07ab50972eb36f72cd4bc04d75d44e9cca3a655e4853b7e401b81f0011acec3"},"schema_version":"1.0","source":{"id":"2601.19448","kind":"arxiv","version":2}},"canonical_sha256":"2fa9016e9e27a0e6769df712d686c7318b7ea41e27a4d11bff45b038e0aba202","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"2fa9016e9e27a0e6769df712d686c7318b7ea41e27a4d11bff45b038e0aba202","first_computed_at":"2026-06-01T01:02:30.416308Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-01T01:02:30.416308Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"3BgRc1A4iBQnvpAEwy1mSlVW1zJZkTlZKSrj0Y0z5Wl72+v2VKmyT6ukxHVggwpcz6zUogAtkkzr4y9FwcB2Dw==","signature_status":"signed_v1","signed_at":"2026-06-01T01:02:30.417269Z","signed_message":"canonical_sha256_bytes"},"source_id":"2601.19448","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:408346c6c1f3407746b0b533beed6a093670c41433b3a305adb62c29421c9558","sha256:eda50ee8b3e8f9336fb1ebac8cede320c198eb0cbc9f7b444f0819fc95249639"],"state_sha256":"e0ac40dcde47e07fca87e782710ee96660a7ed1c2f271882e3978a8946fc14de"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wQYGjs2MxesqdW6p54qaVZbHeYd42IfHb31rUCHGMvV+aGWRLo84r1Bp2soROBcH5GYibS7KM0crMbm8mfZdDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-02T04:18:21.340790Z","bundle_sha256":"a5a63dc981d67cdd3e393426ca11bf297f64f9d2a83deb2ad32ac63c8da68b2d"}}