{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:JAX3EZWVACLSAXR7YQL2M5LQHA","short_pith_number":"pith:JAX3EZWV","schema_version":"1.0","canonical_sha256":"482fb266d50097205e3fc417a67570380c0c05d3d77cd0adaf0abf5c129f1fb7","source":{"kind":"arxiv","id":"2504.09593","version":2},"attestation_state":"computed","paper":{"title":"ControlNET: A Firewall for RAG-based LLM System","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Cong Wang, Haoran Shi, Hongwei Yao, Yidou Chen, Yixin Jiang, Zhan Qin","submitted_at":"2025-04-13T14:18:35Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) has significantly enhanced the factual accuracy and domain adaptability of Large Language Models (LLMs). This advancement has enabled their widespread deployment across sensitive domains such as healthcare, finance, and enterprise applications. RAG mitigates hallucinations by integrating external knowledge, yet introduces privacy risk and security risk, notably data breaching risk and data poisoning risk. While recent studies have explored prompt injection and poisoning attacks, there remains a significant gap in comprehensive research on controlling inboun"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2504.09593","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2025-04-13T14:18:35Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"d92de1a66a5bf552f7b080cc338beb93b31a38c1d47327105fa61c68a256aceb","abstract_canon_sha256":"8f324983736d06f94ad7ae99362cfa034572bb53bd8a536787e02e573a082c2b"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:50:12.932558Z","signature_b64":"4b0VIGA7ZZUcwhmFpCzRfashQwNxzI5oqr7oRfwuyLld+d8NHCO+3mvKk7xmqGY9jScy7UnH1kKBIgGtjsZ7CQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"482fb266d50097205e3fc417a67570380c0c05d3d77cd0adaf0abf5c129f1fb7","last_reissued_at":"2026-07-05T10:50:12.932075Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:50:12.932075Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"ControlNET: A Firewall for RAG-based LLM System","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Cong Wang, Haoran Shi, Hongwei Yao, Yidou Chen, Yixin Jiang, Zhan Qin","submitted_at":"2025-04-13T14:18:35Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) has significantly enhanced the factual accuracy and domain adaptability of Large Language Models (LLMs). This advancement has enabled their widespread deployment across sensitive domains such as healthcare, finance, and enterprise applications. RAG mitigates hallucinations by integrating external knowledge, yet introduces privacy risk and security risk, notably data breaching risk and data poisoning risk. While recent studies have explored prompt injection and poisoning attacks, there remains a significant gap in comprehensive research on controlling inboun"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2504.09593","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2504.09593/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2504.09593","created_at":"2026-07-05T10:50:12.932136+00:00"},{"alias_kind":"arxiv_version","alias_value":"2504.09593v2","created_at":"2026-07-05T10:50:12.932136+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2504.09593","created_at":"2026-07-05T10:50:12.932136+00:00"},{"alias_kind":"pith_short_12","alias_value":"JAX3EZWVACLS","created_at":"2026-07-05T10:50:12.932136+00:00"},{"alias_kind":"pith_short_16","alias_value":"JAX3EZWVACLSAXR7","created_at":"2026-07-05T10:50:12.932136+00:00"},{"alias_kind":"pith_short_8","alias_value":"JAX3EZWV","created_at":"2026-07-05T10:50:12.932136+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.11047","citing_title":"Red-Teaming Agent Execution Contexts: Open-World Security Evaluation on OpenClaw","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2605.10614","citing_title":"PRISM: Generation-Time Detection and Mitigation of Secret Leakage in Multi-Agent LLM Pipelines","ref_index":24,"is_internal_anchor":false},{"citing_arxiv_id":"2604.20932","citing_title":"Adaptive Defense Orchestration for RAG: A Sentinel-Strategist Architecture against Multi-Vector Attacks","ref_index":32,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/JAX3EZWVACLSAXR7YQL2M5LQHA","json":"https://pith.science/pith/JAX3EZWVACLSAXR7YQL2M5LQHA.json","graph_json":"https://pith.science/api/pith-number/JAX3EZWVACLSAXR7YQL2M5LQHA/graph.json","events_json":"https://pith.science/api/pith-number/JAX3EZWVACLSAXR7YQL2M5LQHA/events.json","paper":"https://pith.science/paper/JAX3EZWV"},"agent_actions":{"view_html":"https://pith.science/pith/JAX3EZWVACLSAXR7YQL2M5LQHA","download_json":"https://pith.science/pith/JAX3EZWVACLSAXR7YQL2M5LQHA.json","view_paper":"https://pith.science/paper/JAX3EZWV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2504.09593&json=true","fetch_graph":"https://pith.science/api/pith-number/JAX3EZWVACLSAXR7YQL2M5LQHA/graph.json","fetch_events":"https://pith.science/api/pith-number/JAX3EZWVACLSAXR7YQL2M5LQHA/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/JAX3EZWVACLSAXR7YQL2M5LQHA/action/timestamp_anchor","attest_storage":"https://pith.science/pith/JAX3EZWVACLSAXR7YQL2M5LQHA/action/storage_attestation","attest_author":"https://pith.science/pith/JAX3EZWVACLSAXR7YQL2M5LQHA/action/author_attestation","sign_citation":"https://pith.science/pith/JAX3EZWVACLSAXR7YQL2M5LQHA/action/citation_signature","submit_replication":"https://pith.science/pith/JAX3EZWVACLSAXR7YQL2M5LQHA/action/replication_record"}},"created_at":"2026-07-05T10:50:12.932136+00:00","updated_at":"2026-07-05T10:50:12.932136+00:00"}