{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:FRZMVQK4YY2WODYPCVEKVF5YHU","short_pith_number":"pith:FRZMVQK4","canonical_record":{"source":{"id":"2606.04317","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-03T00:47:11Z","cross_cats_sorted":["cs.LG","cs.SE"],"title_canon_sha256":"42cbec26d6077d19372ca69f7bf1f22c77a43b83139a1a638708455e755ea71c","abstract_canon_sha256":"67d6dc8922553b069d9a7df08af264cc39cc4190f7b4bd21e4a9e967971d64df"},"schema_version":"1.0"},"canonical_sha256":"2c72cac15cc635670f0f1548aa97b83d0de66b6c47a8dc9f1bfa251ac448a416","source":{"kind":"arxiv","id":"2606.04317","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.04317","created_at":"2026-06-04T01:09:03Z"},{"alias_kind":"arxiv_version","alias_value":"2606.04317v1","created_at":"2026-06-04T01:09:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.04317","created_at":"2026-06-04T01:09:03Z"},{"alias_kind":"pith_short_12","alias_value":"FRZMVQK4YY2W","created_at":"2026-06-04T01:09:03Z"},{"alias_kind":"pith_short_16","alias_value":"FRZMVQK4YY2WODYP","created_at":"2026-06-04T01:09:03Z"},{"alias_kind":"pith_short_8","alias_value":"FRZMVQK4","created_at":"2026-06-04T01:09:03Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:FRZMVQK4YY2WODYPCVEKVF5YHU","target":"record","payload":{"canonical_record":{"source":{"id":"2606.04317","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-03T00:47:11Z","cross_cats_sorted":["cs.LG","cs.SE"],"title_canon_sha256":"42cbec26d6077d19372ca69f7bf1f22c77a43b83139a1a638708455e755ea71c","abstract_canon_sha256":"67d6dc8922553b069d9a7df08af264cc39cc4190f7b4bd21e4a9e967971d64df"},"schema_version":"1.0"},"canonical_sha256":"2c72cac15cc635670f0f1548aa97b83d0de66b6c47a8dc9f1bfa251ac448a416","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-04T01:09:03.428053Z","signature_b64":"hpQrpNXVPzGfWRHEW0ozcapshHVt8p6aHeOyj6yKQHvqhogGLs34i3aPS/9rg8PKMfOfNLPIn6R0bjfmL6BFDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2c72cac15cc635670f0f1548aa97b83d0de66b6c47a8dc9f1bfa251ac448a416","last_reissued_at":"2026-06-04T01:09:03.427604Z","signature_status":"signed_v1","first_computed_at":"2026-06-04T01:09:03.427604Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.04317","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-04T01:09:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"a1iSX2IYIjxX4JzBxrEQGebAgm+MzeiOHRaGSo68uFJZe+azJ+mQAVFsuKe0V6YXUvNqYQRkrU8mq0iJDu56BQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T15:19:01.090767Z"},"content_sha256":"958d0b0687879952195d00c087011dd694f7195dd9dca7063974e6de705c10ad","schema_version":"1.0","event_id":"sha256:958d0b0687879952195d00c087011dd694f7195dd9dca7063974e6de705c10ad"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:FRZMVQK4YY2WODYPCVEKVF5YHU","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Toward a Generalized Defense Across Sparse, Continuous, and Structured Parameter Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG","cs.SE"],"primary_cat":"cs.CR","authors_text":"Bin Duan, Guowei Yang, Zeyu Bai","submitted_at":"2026-06-03T00:47:11Z","abstract_excerpt":"Deep neural networks are increasingly deployed across heterogeneous and partially untrusted environments, where models are distributed through cloud storage, CI/CD pipelines, containerized services, and edge execution platforms. This broad deployment landscape exposes model parameters to various integrity risks. Unlike input-space adversarial attacks, parameter attacks directly tamper with the model's internal parameters and persist across all subsequent inferences. Existing defenses either require retraining, incur significant accuracy degradation, or are limited to specific attack classes. H"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.04317","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.04317/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-04T01:09:03Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"nq8ANIVsTc11Dj4S3D6Sbo50GnBg6cOZTM1NeTkuDAJQNL16ym8auevPgKzPzepfydKjqkB46l52MZhio7+cBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-05T15:19:01.091153Z"},"content_sha256":"d845dc87e0db16c0af277e346c7f05eabdab3e523fea1a875fefe068246821bb","schema_version":"1.0","event_id":"sha256:d845dc87e0db16c0af277e346c7f05eabdab3e523fea1a875fefe068246821bb"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/FRZMVQK4YY2WODYPCVEKVF5YHU/bundle.json","state_url":"https://pith.science/pith/FRZMVQK4YY2WODYPCVEKVF5YHU/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/FRZMVQK4YY2WODYPCVEKVF5YHU/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-05T15:19:01Z","links":{"resolver":"https://pith.science/pith/FRZMVQK4YY2WODYPCVEKVF5YHU","bundle":"https://pith.science/pith/FRZMVQK4YY2WODYPCVEKVF5YHU/bundle.json","state":"https://pith.science/pith/FRZMVQK4YY2WODYPCVEKVF5YHU/state.json","well_known_bundle":"https://pith.science/.well-known/pith/FRZMVQK4YY2WODYPCVEKVF5YHU/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:FRZMVQK4YY2WODYPCVEKVF5YHU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"67d6dc8922553b069d9a7df08af264cc39cc4190f7b4bd21e4a9e967971d64df","cross_cats_sorted":["cs.LG","cs.SE"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-03T00:47:11Z","title_canon_sha256":"42cbec26d6077d19372ca69f7bf1f22c77a43b83139a1a638708455e755ea71c"},"schema_version":"1.0","source":{"id":"2606.04317","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.04317","created_at":"2026-06-04T01:09:03Z"},{"alias_kind":"arxiv_version","alias_value":"2606.04317v1","created_at":"2026-06-04T01:09:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.04317","created_at":"2026-06-04T01:09:03Z"},{"alias_kind":"pith_short_12","alias_value":"FRZMVQK4YY2W","created_at":"2026-06-04T01:09:03Z"},{"alias_kind":"pith_short_16","alias_value":"FRZMVQK4YY2WODYP","created_at":"2026-06-04T01:09:03Z"},{"alias_kind":"pith_short_8","alias_value":"FRZMVQK4","created_at":"2026-06-04T01:09:03Z"}],"graph_snapshots":[{"event_id":"sha256:d845dc87e0db16c0af277e346c7f05eabdab3e523fea1a875fefe068246821bb","target":"graph","created_at":"2026-06-04T01:09:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.04317/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Deep neural networks are increasingly deployed across heterogeneous and partially untrusted environments, where models are distributed through cloud storage, CI/CD pipelines, containerized services, and edge execution platforms. This broad deployment landscape exposes model parameters to various integrity risks. Unlike input-space adversarial attacks, parameter attacks directly tamper with the model's internal parameters and persist across all subsequent inferences. Existing defenses either require retraining, incur significant accuracy degradation, or are limited to specific attack classes. H","authors_text":"Bin Duan, Guowei Yang, Zeyu Bai","cross_cats":["cs.LG","cs.SE"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-03T00:47:11Z","title":"Toward a Generalized Defense Across Sparse, Continuous, and Structured Parameter Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.04317","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:958d0b0687879952195d00c087011dd694f7195dd9dca7063974e6de705c10ad","target":"record","created_at":"2026-06-04T01:09:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"67d6dc8922553b069d9a7df08af264cc39cc4190f7b4bd21e4a9e967971d64df","cross_cats_sorted":["cs.LG","cs.SE"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-03T00:47:11Z","title_canon_sha256":"42cbec26d6077d19372ca69f7bf1f22c77a43b83139a1a638708455e755ea71c"},"schema_version":"1.0","source":{"id":"2606.04317","kind":"arxiv","version":1}},"canonical_sha256":"2c72cac15cc635670f0f1548aa97b83d0de66b6c47a8dc9f1bfa251ac448a416","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"2c72cac15cc635670f0f1548aa97b83d0de66b6c47a8dc9f1bfa251ac448a416","first_computed_at":"2026-06-04T01:09:03.427604Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-04T01:09:03.427604Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"hpQrpNXVPzGfWRHEW0ozcapshHVt8p6aHeOyj6yKQHvqhogGLs34i3aPS/9rg8PKMfOfNLPIn6R0bjfmL6BFDQ==","signature_status":"signed_v1","signed_at":"2026-06-04T01:09:03.428053Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.04317","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:958d0b0687879952195d00c087011dd694f7195dd9dca7063974e6de705c10ad","sha256:d845dc87e0db16c0af277e346c7f05eabdab3e523fea1a875fefe068246821bb"],"state_sha256":"88e98d0b3d72009585cf3ef60e6b2e44bcaaee4da48a9215496158ea9f9c5796"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"NyQXOoyqYeU728KOL+5rl2NWC2nHO6+jOWhdsxN77omEHbpyPucTE2QJleO735uGYR0BESDIqOmUyPHXu79vCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-05T15:19:01.093365Z","bundle_sha256":"29a630f26515cd187a1df09908952bc1d468dca8c6e5bf11bc41a599a13b3455"}}