{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:HNFVYY7RUDFHM4ASQZ2RUSEJTB","short_pith_number":"pith:HNFVYY7R","canonical_record":{"source":{"id":"2605.24949","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-24T08:54:33Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"bf3adf9eba15437ae835d606b0b39ea55396eefe3494e7363b49ed5a4dc11a22","abstract_canon_sha256":"c76457ee80ddd6e5007a25f9fa6f45e0d523a4dc2f72a62f5f27b7656bdb93d9"},"schema_version":"1.0"},"canonical_sha256":"3b4b5c63f1a0ca76701286751a48899863bf676cc14c35245105933cd7a359cb","source":{"kind":"arxiv","id":"2605.24949","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.24949","created_at":"2026-05-26T01:04:07Z"},{"alias_kind":"arxiv_version","alias_value":"2605.24949v1","created_at":"2026-05-26T01:04:07Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.24949","created_at":"2026-05-26T01:04:07Z"},{"alias_kind":"pith_short_12","alias_value":"HNFVYY7RUDFH","created_at":"2026-05-26T01:04:07Z"},{"alias_kind":"pith_short_16","alias_value":"HNFVYY7RUDFHM4AS","created_at":"2026-05-26T01:04:07Z"},{"alias_kind":"pith_short_8","alias_value":"HNFVYY7R","created_at":"2026-05-26T01:04:07Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:HNFVYY7RUDFHM4ASQZ2RUSEJTB","target":"record","payload":{"canonical_record":{"source":{"id":"2605.24949","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-24T08:54:33Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"bf3adf9eba15437ae835d606b0b39ea55396eefe3494e7363b49ed5a4dc11a22","abstract_canon_sha256":"c76457ee80ddd6e5007a25f9fa6f45e0d523a4dc2f72a62f5f27b7656bdb93d9"},"schema_version":"1.0"},"canonical_sha256":"3b4b5c63f1a0ca76701286751a48899863bf676cc14c35245105933cd7a359cb","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T01:04:07.221445Z","signature_b64":"AmbSFcZlqJ1sx5Ig4/jA8f9qYM3OhptRW4Ql/Fs3gTlHwyzpsV5e4s6uvUYMsgD1iwrbIk7z/hoCtvFrwQXqDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3b4b5c63f1a0ca76701286751a48899863bf676cc14c35245105933cd7a359cb","last_reissued_at":"2026-05-26T01:04:07.220795Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T01:04:07.220795Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.24949","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T01:04:07Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"FsDEWvoylPWNmZa37D6yg10/0KHJ8RNIACTilb8gFw/HCP5EORg4LtOFozvZ5ShNLyxdr0fF6FaYm62lFLT3DA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T14:11:14.700729Z"},"content_sha256":"c75bfa968ea1a922eddc2a1e28084a3cdb5dc8f79558d8d0cbd94ab22894e0e7","schema_version":"1.0","event_id":"sha256:c75bfa968ea1a922eddc2a1e28084a3cdb5dc8f79558d8d0cbd94ab22894e0e7"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:HNFVYY7RUDFHM4ASQZ2RUSEJTB","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"APT-Agent: Automated Penetration Testing using Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"(2) CSIRO Data61), Alsharif Abuadbba (2), Dan Dongseong Kim (1) ((1) University of Queensland, Kristen Moore (2), William Guanting Li (1)","submitted_at":"2026-05-24T08:54:33Z","abstract_excerpt":"Penetration testing is essential to securing modern web infrastructures, yet traditional manual methods struggle to keep pace with their scale and complexity. Large Language Models (LLMs) offer new opportunities for automating these tasks, but existing approaches face two persistent challenges: hallucination of technical entities and insufficient long-term contextual memory. To address these issues, we present APT-Agent, a fully automated LLM-driven penetration testing framework that systematically orchestrates reconnaissance, exploitation, and exfiltration. APT-Agent introduces a hybrid recti"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.24949","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.24949/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T01:04:07Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"M5tl2/omnsSgqP9S6J6LQNCzAc5ITW/W36nLwTd9U8X+AvRYPJiIWIielZr+LN0uVHuD3LP0KPaFzk53xci1BQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T14:11:14.701114Z"},"content_sha256":"1b1b40aca33439c0e542763f58067ad42d0be9f2351994771a8b8f3ed009bc4a","schema_version":"1.0","event_id":"sha256:1b1b40aca33439c0e542763f58067ad42d0be9f2351994771a8b8f3ed009bc4a"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/HNFVYY7RUDFHM4ASQZ2RUSEJTB/bundle.json","state_url":"https://pith.science/pith/HNFVYY7RUDFHM4ASQZ2RUSEJTB/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/HNFVYY7RUDFHM4ASQZ2RUSEJTB/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-02T14:11:14Z","links":{"resolver":"https://pith.science/pith/HNFVYY7RUDFHM4ASQZ2RUSEJTB","bundle":"https://pith.science/pith/HNFVYY7RUDFHM4ASQZ2RUSEJTB/bundle.json","state":"https://pith.science/pith/HNFVYY7RUDFHM4ASQZ2RUSEJTB/state.json","well_known_bundle":"https://pith.science/.well-known/pith/HNFVYY7RUDFHM4ASQZ2RUSEJTB/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:HNFVYY7RUDFHM4ASQZ2RUSEJTB","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"c76457ee80ddd6e5007a25f9fa6f45e0d523a4dc2f72a62f5f27b7656bdb93d9","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-24T08:54:33Z","title_canon_sha256":"bf3adf9eba15437ae835d606b0b39ea55396eefe3494e7363b49ed5a4dc11a22"},"schema_version":"1.0","source":{"id":"2605.24949","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.24949","created_at":"2026-05-26T01:04:07Z"},{"alias_kind":"arxiv_version","alias_value":"2605.24949v1","created_at":"2026-05-26T01:04:07Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.24949","created_at":"2026-05-26T01:04:07Z"},{"alias_kind":"pith_short_12","alias_value":"HNFVYY7RUDFH","created_at":"2026-05-26T01:04:07Z"},{"alias_kind":"pith_short_16","alias_value":"HNFVYY7RUDFHM4AS","created_at":"2026-05-26T01:04:07Z"},{"alias_kind":"pith_short_8","alias_value":"HNFVYY7R","created_at":"2026-05-26T01:04:07Z"}],"graph_snapshots":[{"event_id":"sha256:1b1b40aca33439c0e542763f58067ad42d0be9f2351994771a8b8f3ed009bc4a","target":"graph","created_at":"2026-05-26T01:04:07Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.24949/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Penetration testing is essential to securing modern web infrastructures, yet traditional manual methods struggle to keep pace with their scale and complexity. Large Language Models (LLMs) offer new opportunities for automating these tasks, but existing approaches face two persistent challenges: hallucination of technical entities and insufficient long-term contextual memory. To address these issues, we present APT-Agent, a fully automated LLM-driven penetration testing framework that systematically orchestrates reconnaissance, exploitation, and exfiltration. APT-Agent introduces a hybrid recti","authors_text":"(2) CSIRO Data61), Alsharif Abuadbba (2), Dan Dongseong Kim (1) ((1) University of Queensland, Kristen Moore (2), William Guanting Li (1)","cross_cats":["cs.AI"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-24T08:54:33Z","title":"APT-Agent: Automated Penetration Testing using Large Language Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.24949","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:c75bfa968ea1a922eddc2a1e28084a3cdb5dc8f79558d8d0cbd94ab22894e0e7","target":"record","created_at":"2026-05-26T01:04:07Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"c76457ee80ddd6e5007a25f9fa6f45e0d523a4dc2f72a62f5f27b7656bdb93d9","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-24T08:54:33Z","title_canon_sha256":"bf3adf9eba15437ae835d606b0b39ea55396eefe3494e7363b49ed5a4dc11a22"},"schema_version":"1.0","source":{"id":"2605.24949","kind":"arxiv","version":1}},"canonical_sha256":"3b4b5c63f1a0ca76701286751a48899863bf676cc14c35245105933cd7a359cb","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"3b4b5c63f1a0ca76701286751a48899863bf676cc14c35245105933cd7a359cb","first_computed_at":"2026-05-26T01:04:07.220795Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-26T01:04:07.220795Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"AmbSFcZlqJ1sx5Ig4/jA8f9qYM3OhptRW4Ql/Fs3gTlHwyzpsV5e4s6uvUYMsgD1iwrbIk7z/hoCtvFrwQXqDQ==","signature_status":"signed_v1","signed_at":"2026-05-26T01:04:07.221445Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.24949","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:c75bfa968ea1a922eddc2a1e28084a3cdb5dc8f79558d8d0cbd94ab22894e0e7","sha256:1b1b40aca33439c0e542763f58067ad42d0be9f2351994771a8b8f3ed009bc4a"],"state_sha256":"9566d95a855827739e954f9950941a7c0a664bce074f0aa8c520fa5a0404b99e"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"v4sQuDQxVmKad83s/XVVEwqAf5NFdV6JqGixLXhL42+zsWlF22yelQPLCdn1One4CSPNhg/EDOORb9jsM4jpAA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-02T14:11:14.703300Z","bundle_sha256":"c6f6dbe27fb0260e83cee3fbe7ce7767e62407b89d4ce3f64f389c28db826430"}}