{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:FPLLGY2AZNKYJBTOJLCRLQ6IBK","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"7452c7fe1ae500894cab555b51f0fc02d50082adeb5a73116d37989b627ffdb4","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-02-04T15:28:53Z","title_canon_sha256":"1075bedc5a80dfc690bcb71158fe96c890def8340729405f99473902f373e2fa"},"schema_version":"1.0","source":{"id":"2602.04653","kind":"arxiv","version":4}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2602.04653","created_at":"2026-05-26T02:04:05Z"},{"alias_kind":"arxiv_version","alias_value":"2602.04653v4","created_at":"2026-05-26T02:04:05Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2602.04653","created_at":"2026-05-26T02:04:05Z"},{"alias_kind":"pith_short_12","alias_value":"FPLLGY2AZNKY","created_at":"2026-05-26T02:04:05Z"},{"alias_kind":"pith_short_16","alias_value":"FPLLGY2AZNKYJBTO","created_at":"2026-05-26T02:04:05Z"},{"alias_kind":"pith_short_8","alias_value":"FPLLGY2A","created_at":"2026-05-26T02:04:05Z"}],"graph_snapshots":[{"event_id":"sha256:a70aef6fc0d1d99b555905533400069d0cdf277c420232c40eadd28c63d6e409","target":"graph","created_at":"2026-05-26T02:04:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2602.04653/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Open-weight language models are increasingly used in production settings, raising new security challenges. One prominent threat is backdoor attacks, in which adversaries embed hidden behaviors that activate under specific conditions. Previous work has assumed that adversaries have access to training pipelines or deployment infrastructure. We propose a novel attack surface requiring neither: the \"chat template\". Chat templates are executable programs invoked at every inference call, often implemented in Jinja2, that occupy a privileged position between user input and model processing. We show t","authors_text":"Ariel Fogel, Eilon Cohen, Omer Hofman, Roman Vainshtein","cross_cats":["cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-02-04T15:28:53Z","title":"Inference-Time Backdoors via Chat Templates: From LLM Supply Chains to Agentic System Compromise"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2602.04653","kind":"arxiv","version":4},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4c4328f02e8c6da50ef98f4f0e64c5cbab3f7df035a6bc88f6489aaae258e1e6","target":"record","created_at":"2026-05-26T02:04:05Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"7452c7fe1ae500894cab555b51f0fc02d50082adeb5a73116d37989b627ffdb4","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-02-04T15:28:53Z","title_canon_sha256":"1075bedc5a80dfc690bcb71158fe96c890def8340729405f99473902f373e2fa"},"schema_version":"1.0","source":{"id":"2602.04653","kind":"arxiv","version":4}},"canonical_sha256":"2bd6b36340cb5584866e4ac515c3c80abb5b1578b703fcfe37a402e2536b8132","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"2bd6b36340cb5584866e4ac515c3c80abb5b1578b703fcfe37a402e2536b8132","first_computed_at":"2026-05-26T02:04:05.023204Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-26T02:04:05.023204Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"g3eY68fN8ntwhDLJI2XnZeZPuub2RboBowvnXDoptEftzRPfUhsFwc29gJiNGiHPn30itpEduF/BQREY9Zz4CQ==","signature_status":"signed_v1","signed_at":"2026-05-26T02:04:05.024269Z","signed_message":"canonical_sha256_bytes"},"source_id":"2602.04653","source_kind":"arxiv","source_version":4}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4c4328f02e8c6da50ef98f4f0e64c5cbab3f7df035a6bc88f6489aaae258e1e6","sha256:a70aef6fc0d1d99b555905533400069d0cdf277c420232c40eadd28c63d6e409"],"state_sha256":"072e2ca5ced29c09f8e181b55bbc120830e31ecf919383778e8373e1d795c8ac"}