{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:HVO5U3AXE325V6ZJ6CEIUSDBH2","short_pith_number":"pith:HVO5U3AX","canonical_record":{"source":{"id":"2605.29251","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-28T02:12:41Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"b37eccd8c00a5be3e8ab8079008ed77769d8e8edab2907c0b576eb51454df287","abstract_canon_sha256":"746d026c04e871406abf551b1c2d1c373164c463bc77f7db425b259da0d65ed6"},"schema_version":"1.0"},"canonical_sha256":"3d5dda6c1726f5dafb29f0888a48613e9241af0b0731b8f03128132d94daa812","source":{"kind":"arxiv","id":"2605.29251","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.29251","created_at":"2026-05-29T01:05:27Z"},{"alias_kind":"arxiv_version","alias_value":"2605.29251v1","created_at":"2026-05-29T01:05:27Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.29251","created_at":"2026-05-29T01:05:27Z"},{"alias_kind":"pith_short_12","alias_value":"HVO5U3AXE325","created_at":"2026-05-29T01:05:27Z"},{"alias_kind":"pith_short_16","alias_value":"HVO5U3AXE325V6ZJ","created_at":"2026-05-29T01:05:27Z"},{"alias_kind":"pith_short_8","alias_value":"HVO5U3AX","created_at":"2026-05-29T01:05:27Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:HVO5U3AXE325V6ZJ6CEIUSDBH2","target":"record","payload":{"canonical_record":{"source":{"id":"2605.29251","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-28T02:12:41Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"b37eccd8c00a5be3e8ab8079008ed77769d8e8edab2907c0b576eb51454df287","abstract_canon_sha256":"746d026c04e871406abf551b1c2d1c373164c463bc77f7db425b259da0d65ed6"},"schema_version":"1.0"},"canonical_sha256":"3d5dda6c1726f5dafb29f0888a48613e9241af0b0731b8f03128132d94daa812","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-29T01:05:27.245060Z","signature_b64":"RcjlvV2MwZRVfqhQDdZJqieMez7nYdbjTvURZIiMjlzIEqCSSJuanekeO92RAPkM1lRGFd0rPk3zz/R14VfFDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3d5dda6c1726f5dafb29f0888a48613e9241af0b0731b8f03128132d94daa812","last_reissued_at":"2026-05-29T01:05:27.244406Z","signature_status":"signed_v1","first_computed_at":"2026-05-29T01:05:27.244406Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.29251","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T01:05:27Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7U0FRvEz0HiIkS3abgta8+Qj/2SmSv/w2ug0DAqAc06W/yhr8CP20OEffLsBTO37c3K1wwRaXnm/cL6GCCscAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-04T15:36:15.485651Z"},"content_sha256":"cbd004945344e98267b5542321fbb01c1d604ada04f5cb434f39d72b62425ad8","schema_version":"1.0","event_id":"sha256:cbd004945344e98267b5542321fbb01c1d604ada04f5cb434f39d72b62425ad8"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:HVO5U3AXE325V6ZJ6CEIUSDBH2","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Provably Secure Agent Guardrail","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.AI","authors_text":"Benlong Wu, Han Fang, Kejiang Chen, Nenghai Yu, Weiming Zhang","submitted_at":"2026-05-28T02:12:41Z","abstract_excerpt":"As large language models transition from bounded generative engines to agents with expansive execution privileges, AI going out of control precipitates a fundamental crisis in artificial intelligence security. Existing defense architectures heavily rely on empirical semantic guardrails and probabilistic large model adjudicators, mechanisms that fail to provide deterministic security lower bounds when facing complex semantic symbol decoupling attacks. To overcome this empirical semantic guardrail dilemma, this paper proposes a new security paradigm for agents based on the fundamental limitation"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.29251","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.29251/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T01:05:27Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"zIPyp6ZUhOCdJKtaH8CQwE5h/vyokTn6kRVufN9R+dhte2cy4vezXvu/sQkt1gG8h6TBu1bA9L8m3R4a1YdtAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-04T15:36:15.486188Z"},"content_sha256":"666ccd380e2c7566748ba0fad5fff3609c473f002145098db6646d3741279ab7","schema_version":"1.0","event_id":"sha256:666ccd380e2c7566748ba0fad5fff3609c473f002145098db6646d3741279ab7"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/HVO5U3AXE325V6ZJ6CEIUSDBH2/bundle.json","state_url":"https://pith.science/pith/HVO5U3AXE325V6ZJ6CEIUSDBH2/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/HVO5U3AXE325V6ZJ6CEIUSDBH2/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-04T15:36:15Z","links":{"resolver":"https://pith.science/pith/HVO5U3AXE325V6ZJ6CEIUSDBH2","bundle":"https://pith.science/pith/HVO5U3AXE325V6ZJ6CEIUSDBH2/bundle.json","state":"https://pith.science/pith/HVO5U3AXE325V6ZJ6CEIUSDBH2/state.json","well_known_bundle":"https://pith.science/.well-known/pith/HVO5U3AXE325V6ZJ6CEIUSDBH2/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:HVO5U3AXE325V6ZJ6CEIUSDBH2","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"746d026c04e871406abf551b1c2d1c373164c463bc77f7db425b259da0d65ed6","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-28T02:12:41Z","title_canon_sha256":"b37eccd8c00a5be3e8ab8079008ed77769d8e8edab2907c0b576eb51454df287"},"schema_version":"1.0","source":{"id":"2605.29251","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.29251","created_at":"2026-05-29T01:05:27Z"},{"alias_kind":"arxiv_version","alias_value":"2605.29251v1","created_at":"2026-05-29T01:05:27Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.29251","created_at":"2026-05-29T01:05:27Z"},{"alias_kind":"pith_short_12","alias_value":"HVO5U3AXE325","created_at":"2026-05-29T01:05:27Z"},{"alias_kind":"pith_short_16","alias_value":"HVO5U3AXE325V6ZJ","created_at":"2026-05-29T01:05:27Z"},{"alias_kind":"pith_short_8","alias_value":"HVO5U3AX","created_at":"2026-05-29T01:05:27Z"}],"graph_snapshots":[{"event_id":"sha256:666ccd380e2c7566748ba0fad5fff3609c473f002145098db6646d3741279ab7","target":"graph","created_at":"2026-05-29T01:05:27Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.29251/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"As large language models transition from bounded generative engines to agents with expansive execution privileges, AI going out of control precipitates a fundamental crisis in artificial intelligence security. Existing defense architectures heavily rely on empirical semantic guardrails and probabilistic large model adjudicators, mechanisms that fail to provide deterministic security lower bounds when facing complex semantic symbol decoupling attacks. To overcome this empirical semantic guardrail dilemma, this paper proposes a new security paradigm for agents based on the fundamental limitation","authors_text":"Benlong Wu, Han Fang, Kejiang Chen, Nenghai Yu, Weiming Zhang","cross_cats":["cs.CR"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-28T02:12:41Z","title":"Provably Secure Agent Guardrail"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.29251","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:cbd004945344e98267b5542321fbb01c1d604ada04f5cb434f39d72b62425ad8","target":"record","created_at":"2026-05-29T01:05:27Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"746d026c04e871406abf551b1c2d1c373164c463bc77f7db425b259da0d65ed6","cross_cats_sorted":["cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-28T02:12:41Z","title_canon_sha256":"b37eccd8c00a5be3e8ab8079008ed77769d8e8edab2907c0b576eb51454df287"},"schema_version":"1.0","source":{"id":"2605.29251","kind":"arxiv","version":1}},"canonical_sha256":"3d5dda6c1726f5dafb29f0888a48613e9241af0b0731b8f03128132d94daa812","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"3d5dda6c1726f5dafb29f0888a48613e9241af0b0731b8f03128132d94daa812","first_computed_at":"2026-05-29T01:05:27.244406Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-29T01:05:27.244406Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"RcjlvV2MwZRVfqhQDdZJqieMez7nYdbjTvURZIiMjlzIEqCSSJuanekeO92RAPkM1lRGFd0rPk3zz/R14VfFDQ==","signature_status":"signed_v1","signed_at":"2026-05-29T01:05:27.245060Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.29251","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:cbd004945344e98267b5542321fbb01c1d604ada04f5cb434f39d72b62425ad8","sha256:666ccd380e2c7566748ba0fad5fff3609c473f002145098db6646d3741279ab7"],"state_sha256":"36171a729709f1a45825a284cef4f6fc13a72cff2e1ccdf516a791317a1bf14b"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"QYOSW+ENoykEMEiguOmgCpY2BhEKAySPLv4YtP76tiRPIdRj7jbPQ8fmJEIWNGNe2l9w+VsWTjGPfDAbp7AMBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-04T15:36:15.489566Z","bundle_sha256":"60280369e472d42a7342265c40d45da5b65f54cf83ef2b47ae9458d1b5cb20e6"}}