{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:KMLQ56I37CZNMGNQRGV5XZAPBD","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"6b25c8070d7141e624553f0e9aeae04448dd8e91b728139628d7b223f5e0710d","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-18T18:06:20Z","title_canon_sha256":"15681b95b9e54fee7e4ab3aab28d90078d762f939abe982099e1e58d9a5980b8"},"schema_version":"1.0","source":{"id":"2605.18988","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.18988","created_at":"2026-05-20T00:06:41Z"},{"alias_kind":"arxiv_version","alias_value":"2605.18988v1","created_at":"2026-05-20T00:06:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.18988","created_at":"2026-05-20T00:06:41Z"},{"alias_kind":"pith_short_12","alias_value":"KMLQ56I37CZN","created_at":"2026-05-20T00:06:41Z"},{"alias_kind":"pith_short_16","alias_value":"KMLQ56I37CZNMGNQ","created_at":"2026-05-20T00:06:41Z"},{"alias_kind":"pith_short_8","alias_value":"KMLQ56I3","created_at":"2026-05-20T00:06:41Z"}],"graph_snapshots":[{"event_id":"sha256:8fe83ab951a81324f0ae3f33e0053a717474faf71e648f826914fc5f4b8b2bad","target":"graph","created_at":"2026-05-20T00:06:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.18988/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"The expansion of Multimodal Large Language Models (MLLMs) and their integration into autonomous agentic workflows has introduced a non-stationary attack surface. Empirical observations indicate that adversaries employ progressive, cross-modal perturbations that evade turn-specific guardrails by distributing malicious intent across longitudinal conversational trajectories. Static defense mechanisms, constrained by the Markov property, evaluate inputs in isolation and fail to detect cumulative structural poisoning. To handle this limitation, this paper formulates safety verification as a dynamic","authors_text":"Doohee You","cross_cats":["cs.AI"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-18T18:06:20Z","title":"Surviving the Unseen: Predictive Defense for Novel Multi-Turn Multimodal Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.18988","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:2b326d0eef28e32515ddff4c386ba4feef21048ef713db590ca85e7442948359","target":"record","created_at":"2026-05-20T00:06:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"6b25c8070d7141e624553f0e9aeae04448dd8e91b728139628d7b223f5e0710d","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-18T18:06:20Z","title_canon_sha256":"15681b95b9e54fee7e4ab3aab28d90078d762f939abe982099e1e58d9a5980b8"},"schema_version":"1.0","source":{"id":"2605.18988","kind":"arxiv","version":1}},"canonical_sha256":"53170ef91bf8b2d619b089abdbe40f08cdf3cae15af96db90b41442fed82e527","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"53170ef91bf8b2d619b089abdbe40f08cdf3cae15af96db90b41442fed82e527","first_computed_at":"2026-05-20T00:06:41.327837Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:06:41.327837Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"DmJgAiifnTUuv9sDhBkDolVjaJjghX7GO+65tUYm8IWyT4pncHNC+E8KFNatiF4oDT8w6UqWmTvYZveZc9+ECA==","signature_status":"signed_v1","signed_at":"2026-05-20T00:06:41.328713Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.18988","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:2b326d0eef28e32515ddff4c386ba4feef21048ef713db590ca85e7442948359","sha256:8fe83ab951a81324f0ae3f33e0053a717474faf71e648f826914fc5f4b8b2bad"],"state_sha256":"3cbce27d00eba28c7c3713622b1bcddb292f13436779c609e1072040462bcd8f"}