{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:IICVGMOS2YT2RR2FUJLKYUTMPN","short_pith_number":"pith:IICVGMOS","schema_version":"1.0","canonical_sha256":"42055331d2d627a8c745a256ac526c7b5ad95b776672bf13f60c4d083bbae259","source":{"kind":"arxiv","id":"2507.06323","version":1},"attestation_state":"computed","paper":{"title":"Bridging AI and Software Security: A Comparative Vulnerability Assessment of LLM Agent Deployment Paradigms","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ines Belhadj, Jihene Bennaceur, Ramzi Guesmi, Tarek Gasmi","submitted_at":"2025-07-08T18:24:28Z","abstract_excerpt":"Large Language Model (LLM) agents face security vulnerabilities spanning AI-specific and traditional software domains, yet current research addresses these separately. This study bridges this gap through comparative evaluation of Function Calling architecture and Model Context Protocol (MCP) deployment paradigms using a unified threat classification framework. We tested 3,250 attack scenarios across seven language models, evaluating simple, composed, and chained attacks targeting both AI-specific threats (prompt injection) and software vulnerabilities (JSON injection, denial-of-service). Funct"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2507.06323","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-07-08T18:24:28Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"90b5a040b4f5f3eb1cb55f8858dba9bddd29edd9b6d22f2ea071cd5d7e97cb65","abstract_canon_sha256":"81effba61f49e3ce8d2da6e1513223c83ba309e726a2787fa21794f02bb96962"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:34:13.630632Z","signature_b64":"/vFUmKLtOMqoY/oOfW5hR3jOL3Qv678i5AWYuQnT8tupxSTxJazChcFqEy3kP45f5AMNEOWxsPcrITti5GWMDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"42055331d2d627a8c745a256ac526c7b5ad95b776672bf13f60c4d083bbae259","last_reissued_at":"2026-07-05T11:34:13.630159Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:34:13.630159Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Bridging AI and Software Security: A Comparative Vulnerability Assessment of LLM Agent Deployment Paradigms","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ines Belhadj, Jihene Bennaceur, Ramzi Guesmi, Tarek Gasmi","submitted_at":"2025-07-08T18:24:28Z","abstract_excerpt":"Large Language Model (LLM) agents face security vulnerabilities spanning AI-specific and traditional software domains, yet current research addresses these separately. This study bridges this gap through comparative evaluation of Function Calling architecture and Model Context Protocol (MCP) deployment paradigms using a unified threat classification framework. We tested 3,250 attack scenarios across seven language models, evaluating simple, composed, and chained attacks targeting both AI-specific threats (prompt injection) and software vulnerabilities (JSON injection, denial-of-service). Funct"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2507.06323","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2507.06323/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2507.06323","created_at":"2026-07-05T11:34:13.630221+00:00"},{"alias_kind":"arxiv_version","alias_value":"2507.06323v1","created_at":"2026-07-05T11:34:13.630221+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2507.06323","created_at":"2026-07-05T11:34:13.630221+00:00"},{"alias_kind":"pith_short_12","alias_value":"IICVGMOS2YT2","created_at":"2026-07-05T11:34:13.630221+00:00"},{"alias_kind":"pith_short_16","alias_value":"IICVGMOS2YT2RR2F","created_at":"2026-07-05T11:34:13.630221+00:00"},{"alias_kind":"pith_short_8","alias_value":"IICVGMOS","created_at":"2026-07-05T11:34:13.630221+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.24069","citing_title":"When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents","ref_index":26,"is_internal_anchor":false},{"citing_arxiv_id":"2603.09002","citing_title":"Security Considerations for Multi-agent Systems","ref_index":65,"is_internal_anchor":false},{"citing_arxiv_id":"2604.07551","citing_title":"MCP-DPT: A Defense-Placement Taxonomy and Coverage Analysis for Model Context Protocol Security","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2604.20179","citing_title":"Taint-Style Vulnerability Detection and Confirmation for Node.js Packages Using LLM Agent Reasoning","ref_index":23,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/IICVGMOS2YT2RR2FUJLKYUTMPN","json":"https://pith.science/pith/IICVGMOS2YT2RR2FUJLKYUTMPN.json","graph_json":"https://pith.science/api/pith-number/IICVGMOS2YT2RR2FUJLKYUTMPN/graph.json","events_json":"https://pith.science/api/pith-number/IICVGMOS2YT2RR2FUJLKYUTMPN/events.json","paper":"https://pith.science/paper/IICVGMOS"},"agent_actions":{"view_html":"https://pith.science/pith/IICVGMOS2YT2RR2FUJLKYUTMPN","download_json":"https://pith.science/pith/IICVGMOS2YT2RR2FUJLKYUTMPN.json","view_paper":"https://pith.science/paper/IICVGMOS","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2507.06323&json=true","fetch_graph":"https://pith.science/api/pith-number/IICVGMOS2YT2RR2FUJLKYUTMPN/graph.json","fetch_events":"https://pith.science/api/pith-number/IICVGMOS2YT2RR2FUJLKYUTMPN/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/IICVGMOS2YT2RR2FUJLKYUTMPN/action/timestamp_anchor","attest_storage":"https://pith.science/pith/IICVGMOS2YT2RR2FUJLKYUTMPN/action/storage_attestation","attest_author":"https://pith.science/pith/IICVGMOS2YT2RR2FUJLKYUTMPN/action/author_attestation","sign_citation":"https://pith.science/pith/IICVGMOS2YT2RR2FUJLKYUTMPN/action/citation_signature","submit_replication":"https://pith.science/pith/IICVGMOS2YT2RR2FUJLKYUTMPN/action/replication_record"}},"created_at":"2026-07-05T11:34:13.630221+00:00","updated_at":"2026-07-05T11:34:13.630221+00:00"}