{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:JY5IVQJ2YWAUCBPE3EFKU5FZPP","short_pith_number":"pith:JY5IVQJ2","canonical_record":{"source":{"id":"2606.09749","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.RO","submitted_at":"2026-06-08T17:11:16Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"c48675a97aed6400fdfeb95ea3057191e7ad11bdb320d6f123b8bdc4d3681c32","abstract_canon_sha256":"818b097b6a246ca884cf44ccc10a700966b845e1ab104433ab2f524ad98159c9"},"schema_version":"1.0"},"canonical_sha256":"4e3a8ac13ac5814105e4d90aaa74b97bd003dbb9b0bef381d68c7710617f022f","source":{"kind":"arxiv","id":"2606.09749","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.09749","created_at":"2026-06-09T02:09:07Z"},{"alias_kind":"arxiv_version","alias_value":"2606.09749v1","created_at":"2026-06-09T02:09:07Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.09749","created_at":"2026-06-09T02:09:07Z"},{"alias_kind":"pith_short_12","alias_value":"JY5IVQJ2YWAU","created_at":"2026-06-09T02:09:07Z"},{"alias_kind":"pith_short_16","alias_value":"JY5IVQJ2YWAUCBPE","created_at":"2026-06-09T02:09:07Z"},{"alias_kind":"pith_short_8","alias_value":"JY5IVQJ2","created_at":"2026-06-09T02:09:07Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:JY5IVQJ2YWAUCBPE3EFKU5FZPP","target":"record","payload":{"canonical_record":{"source":{"id":"2606.09749","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.RO","submitted_at":"2026-06-08T17:11:16Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"c48675a97aed6400fdfeb95ea3057191e7ad11bdb320d6f123b8bdc4d3681c32","abstract_canon_sha256":"818b097b6a246ca884cf44ccc10a700966b845e1ab104433ab2f524ad98159c9"},"schema_version":"1.0"},"canonical_sha256":"4e3a8ac13ac5814105e4d90aaa74b97bd003dbb9b0bef381d68c7710617f022f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-09T02:09:07.499555Z","signature_b64":"38KZsXgwyO45tGfEZbqyD61GFfrp4703jtdL2W8kQaFmHcttwefviY07mnQmJ2WvScEmzkXrAPg6/APKQ+McBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4e3a8ac13ac5814105e4d90aaa74b97bd003dbb9b0bef381d68c7710617f022f","last_reissued_at":"2026-06-09T02:09:07.498620Z","signature_status":"signed_v1","first_computed_at":"2026-06-09T02:09:07.498620Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.09749","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T02:09:07Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"87uTrg1PFmdY/3qcFfKv7UXft8XKa3LhorZzzTG/C1dAMmnleXvY7hJwZDpymu/PCLauQ60npd2BzCnhIPQNCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-11T06:04:25.316968Z"},"content_sha256":"c0391defefc362921a92c0e2e6f85be5b1a7a1923847c9f3948c67979144085a","schema_version":"1.0","event_id":"sha256:c0391defefc362921a92c0e2e6f85be5b1a7a1923847c9f3948c67979144085a"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:JY5IVQJ2YWAUCBPE3EFKU5FZPP","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Your Model Already Knows: Attention-Guided Safety Filter for Vision-Language-Action Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.RO","authors_text":"Baharan Mirzasoleiman, Fan Zhang, Nader Sehatbakhsh, Seongbin Park, Shahriar Talebi","submitted_at":"2026-06-08T17:11:16Z","abstract_excerpt":"Vision-Language-Action (VLA) models have demonstrated impressive end-to-end performance across a variety of robotic manipulation tasks. However, these policies offer no guarantees against collisions with task-irrelevant objects in the scene. Existing safety filters sidestep this problem by querying a vision-language model (VLM) to identify obstacles and their locations. This, however, is too slow to run in the control loop and can only be invoked at episode initialization, leaving the filter unable to track moving obstacles. We discover that a small number of attention heads within a VLA model"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.09749","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.09749/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T02:09:07Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ic319eJ5aZ4NnNQyNCGbBtfEkUkbL4Vu8ztmh7N6/FbQ0QJFN5bhj1s+fe7zHGeUcLGwjH2ebQWdqeX+T6CJAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-11T06:04:25.317777Z"},"content_sha256":"edfcd5e03072d8415d40515e247f48fb3d13ab17125d25d755e418088d1e1aa5","schema_version":"1.0","event_id":"sha256:edfcd5e03072d8415d40515e247f48fb3d13ab17125d25d755e418088d1e1aa5"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/JY5IVQJ2YWAUCBPE3EFKU5FZPP/bundle.json","state_url":"https://pith.science/pith/JY5IVQJ2YWAUCBPE3EFKU5FZPP/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/JY5IVQJ2YWAUCBPE3EFKU5FZPP/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-11T06:04:25Z","links":{"resolver":"https://pith.science/pith/JY5IVQJ2YWAUCBPE3EFKU5FZPP","bundle":"https://pith.science/pith/JY5IVQJ2YWAUCBPE3EFKU5FZPP/bundle.json","state":"https://pith.science/pith/JY5IVQJ2YWAUCBPE3EFKU5FZPP/state.json","well_known_bundle":"https://pith.science/.well-known/pith/JY5IVQJ2YWAUCBPE3EFKU5FZPP/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:JY5IVQJ2YWAUCBPE3EFKU5FZPP","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"818b097b6a246ca884cf44ccc10a700966b845e1ab104433ab2f524ad98159c9","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.RO","submitted_at":"2026-06-08T17:11:16Z","title_canon_sha256":"c48675a97aed6400fdfeb95ea3057191e7ad11bdb320d6f123b8bdc4d3681c32"},"schema_version":"1.0","source":{"id":"2606.09749","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.09749","created_at":"2026-06-09T02:09:07Z"},{"alias_kind":"arxiv_version","alias_value":"2606.09749v1","created_at":"2026-06-09T02:09:07Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.09749","created_at":"2026-06-09T02:09:07Z"},{"alias_kind":"pith_short_12","alias_value":"JY5IVQJ2YWAU","created_at":"2026-06-09T02:09:07Z"},{"alias_kind":"pith_short_16","alias_value":"JY5IVQJ2YWAUCBPE","created_at":"2026-06-09T02:09:07Z"},{"alias_kind":"pith_short_8","alias_value":"JY5IVQJ2","created_at":"2026-06-09T02:09:07Z"}],"graph_snapshots":[{"event_id":"sha256:edfcd5e03072d8415d40515e247f48fb3d13ab17125d25d755e418088d1e1aa5","target":"graph","created_at":"2026-06-09T02:09:07Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.09749/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Vision-Language-Action (VLA) models have demonstrated impressive end-to-end performance across a variety of robotic manipulation tasks. However, these policies offer no guarantees against collisions with task-irrelevant objects in the scene. Existing safety filters sidestep this problem by querying a vision-language model (VLM) to identify obstacles and their locations. This, however, is too slow to run in the control loop and can only be invoked at episode initialization, leaving the filter unable to track moving obstacles. We discover that a small number of attention heads within a VLA model","authors_text":"Baharan Mirzasoleiman, Fan Zhang, Nader Sehatbakhsh, Seongbin Park, Shahriar Talebi","cross_cats":["cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.RO","submitted_at":"2026-06-08T17:11:16Z","title":"Your Model Already Knows: Attention-Guided Safety Filter for Vision-Language-Action Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.09749","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:c0391defefc362921a92c0e2e6f85be5b1a7a1923847c9f3948c67979144085a","target":"record","created_at":"2026-06-09T02:09:07Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"818b097b6a246ca884cf44ccc10a700966b845e1ab104433ab2f524ad98159c9","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.RO","submitted_at":"2026-06-08T17:11:16Z","title_canon_sha256":"c48675a97aed6400fdfeb95ea3057191e7ad11bdb320d6f123b8bdc4d3681c32"},"schema_version":"1.0","source":{"id":"2606.09749","kind":"arxiv","version":1}},"canonical_sha256":"4e3a8ac13ac5814105e4d90aaa74b97bd003dbb9b0bef381d68c7710617f022f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"4e3a8ac13ac5814105e4d90aaa74b97bd003dbb9b0bef381d68c7710617f022f","first_computed_at":"2026-06-09T02:09:07.498620Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-09T02:09:07.498620Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"38KZsXgwyO45tGfEZbqyD61GFfrp4703jtdL2W8kQaFmHcttwefviY07mnQmJ2WvScEmzkXrAPg6/APKQ+McBA==","signature_status":"signed_v1","signed_at":"2026-06-09T02:09:07.499555Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.09749","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:c0391defefc362921a92c0e2e6f85be5b1a7a1923847c9f3948c67979144085a","sha256:edfcd5e03072d8415d40515e247f48fb3d13ab17125d25d755e418088d1e1aa5"],"state_sha256":"5627f3b318d22a56543d6d035a8adb221caffea3276c1f8c524ca02d89eadc9c"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"AkCLereWF1RgMtxJJkLuunpRym5lF3aSrlDZnORWyFrr2ihYl+F02/L1o4SJUp1aEtfKghP1TJjGtwh2e0m9CA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-11T06:04:25.321928Z","bundle_sha256":"c579ba5aca3dc57b26d3518a621e8f0ecc0a5a6e158564a3e39d19e6cba43288"}}