{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:IZKX2E2Y6NFKXAPAT2FBKJT2KB","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"500ac0662507b8d446f57da44355fa9e55e2cfa09a4a536a4db3024eb70eb47b","cross_cats_sorted":["cs.CL","cs.IR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-27T08:06:10Z","title_canon_sha256":"f8cebbac9ed08957814b835d604608824fea9c35c170d90b1a05df208c4b2f2f"},"schema_version":"1.0","source":{"id":"2605.28112","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.28112","created_at":"2026-05-28T01:04:59Z"},{"alias_kind":"arxiv_version","alias_value":"2605.28112v1","created_at":"2026-05-28T01:04:59Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.28112","created_at":"2026-05-28T01:04:59Z"},{"alias_kind":"pith_short_12","alias_value":"IZKX2E2Y6NFK","created_at":"2026-05-28T01:04:59Z"},{"alias_kind":"pith_short_16","alias_value":"IZKX2E2Y6NFKXAPA","created_at":"2026-05-28T01:04:59Z"},{"alias_kind":"pith_short_8","alias_value":"IZKX2E2Y","created_at":"2026-05-28T01:04:59Z"}],"graph_snapshots":[{"event_id":"sha256:13e6afffc65cbaca43ee984e0fedb9b55a12a430dfaf1c27be3a39203537c981","target":"graph","created_at":"2026-05-28T01:04:59Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.28112/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Federated Retrieval-Augmented Generation (FedRAG) is attractive for privacy-sensitive applications because raw data remain local. As a result, routing must rely on client-provided semantic profiles, creating a new opportunity for manipulation. We introduce Routing Hijacking, a routing-stage attack in which a malicious client forges its profile to attract target queries despite having irrelevant underlying data. We show that this vulnerability is severe. Across three representative FedRAG routing architectures, Routing Hijacking consistently misroutes target queries and leads to downstream disr","authors_text":"Junjie Mu, Qiongxiu Li","cross_cats":["cs.CL","cs.IR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-27T08:06:10Z","title":"A Wolf in Sheep's Clothing: Targeted Routing Hijacking in Federated RAG"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.28112","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:901e4e1b047695420e89a8d6710e7c30ea8feeae1dd2f6333892a977f8a645e1","target":"record","created_at":"2026-05-28T01:04:59Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"500ac0662507b8d446f57da44355fa9e55e2cfa09a4a536a4db3024eb70eb47b","cross_cats_sorted":["cs.CL","cs.IR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-27T08:06:10Z","title_canon_sha256":"f8cebbac9ed08957814b835d604608824fea9c35c170d90b1a05df208c4b2f2f"},"schema_version":"1.0","source":{"id":"2605.28112","kind":"arxiv","version":1}},"canonical_sha256":"46557d1358f34aab81e09e8a15267a506502de3db2ff8cc26b709dc95e279d0a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"46557d1358f34aab81e09e8a15267a506502de3db2ff8cc26b709dc95e279d0a","first_computed_at":"2026-05-28T01:04:59.220727Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-28T01:04:59.220727Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"OIDtjnZxtlYT3CX9xtEV76ZidiXL58zN3xtU53RBrq9QWrLwsMpEv+Ew4wDKvqazoqCZXvSAAJuNMGD8GxiYBw==","signature_status":"signed_v1","signed_at":"2026-05-28T01:04:59.221229Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.28112","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:901e4e1b047695420e89a8d6710e7c30ea8feeae1dd2f6333892a977f8a645e1","sha256:13e6afffc65cbaca43ee984e0fedb9b55a12a430dfaf1c27be3a39203537c981"],"state_sha256":"12b8a2c77cc941956c190c1c77888df8927c4e97d9f35c7bf8723af666d22fde"}