{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:KRFBPAN2CG4JV7S3FOJUZT5LAQ","short_pith_number":"pith:KRFBPAN2","canonical_record":{"source":{"id":"2606.09909","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-06T07:59:08Z","cross_cats_sorted":["cs.AI","cs.CV"],"title_canon_sha256":"ebaf1c8d69399531ebbd67613a0ee6e922f0b40999e5cd4a1c9e0f27c894f289","abstract_canon_sha256":"f2f829722681e9c4f1ef43c7ecfb4f8577cfae5a0d181a3083b4a27cf291796d"},"schema_version":"1.0"},"canonical_sha256":"544a1781ba11b89afe5b2b934ccfab04129ca99266562aae3d6419ecf990041f","source":{"kind":"arxiv","id":"2606.09909","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.09909","created_at":"2026-06-10T00:08:32Z"},{"alias_kind":"arxiv_version","alias_value":"2606.09909v1","created_at":"2026-06-10T00:08:32Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.09909","created_at":"2026-06-10T00:08:32Z"},{"alias_kind":"pith_short_12","alias_value":"KRFBPAN2CG4J","created_at":"2026-06-10T00:08:32Z"},{"alias_kind":"pith_short_16","alias_value":"KRFBPAN2CG4JV7S3","created_at":"2026-06-10T00:08:32Z"},{"alias_kind":"pith_short_8","alias_value":"KRFBPAN2","created_at":"2026-06-10T00:08:32Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:KRFBPAN2CG4JV7S3FOJUZT5LAQ","target":"record","payload":{"canonical_record":{"source":{"id":"2606.09909","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-06T07:59:08Z","cross_cats_sorted":["cs.AI","cs.CV"],"title_canon_sha256":"ebaf1c8d69399531ebbd67613a0ee6e922f0b40999e5cd4a1c9e0f27c894f289","abstract_canon_sha256":"f2f829722681e9c4f1ef43c7ecfb4f8577cfae5a0d181a3083b4a27cf291796d"},"schema_version":"1.0"},"canonical_sha256":"544a1781ba11b89afe5b2b934ccfab04129ca99266562aae3d6419ecf990041f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-10T00:08:32.555494Z","signature_b64":"+A9gaI0H7CH6Szw3Z+CUKP9dgz8a+YpXnnd440XgGda1qqLDGUBYRJgBxdNgh+qSgGchbLaSulfjtuoKgx03Cg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"544a1781ba11b89afe5b2b934ccfab04129ca99266562aae3d6419ecf990041f","last_reissued_at":"2026-06-10T00:08:32.554645Z","signature_status":"signed_v1","first_computed_at":"2026-06-10T00:08:32.554645Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.09909","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-10T00:08:32Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"T2/yXS7eV7/thbkrEHmUYq/eODbscedFtsz2bNsEZHKgppYWtmhy3yWPmr0yRxJE4j8AJp/C9wQIC55t5BxJDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-11T02:45:56.384221Z"},"content_sha256":"adf18bce546cac9a3b1d00b396932e09d9a1dcac6540b153e2418c09de446ce2","schema_version":"1.0","event_id":"sha256:adf18bce546cac9a3b1d00b396932e09d9a1dcac6540b153e2418c09de446ce2"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:KRFBPAN2CG4JV7S3FOJUZT5LAQ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Bypassing Copyright Protection in Diffusion-based Customization via Two-Stage Latent Feature Optimization","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CV"],"primary_cat":"cs.CR","authors_text":"Bin Chen, Hao Fang, Hao Wu, Hongyao Yu, Jiawei Kong, Shu-Tao Xia, Wenbo Yu, Zhiyong Wu, Ziang Xu","submitted_at":"2026-06-06T07:59:08Z","abstract_excerpt":"With the growing concerns over copyright infringement in diffusion-based customization, adversarial attacks have emerged as a prominent defense strategy to prevent malicious content forgery in personalized image generation. However, current defenses typically introduce persistent perturbations in the latent space of Latent Diffusion Models (LDMs), which remain susceptible to adaptive bypasses by adversaries. In this paper, we introduce Two-Stage Latent Feature Optimization (TS-LFO), an efficient and effective copyright-stealing attack against protected diffusion-based customization. We begin b"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.09909","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.09909/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-10T00:08:32Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"AcrILWFKC8q7+z6Lqp2TRz2I6KNVXs/y+nLqxgt7badpBq6I0/8w4bqUwi/DHoleBmu1tfqSqQ/rYcoS/+bZBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-11T02:45:56.384916Z"},"content_sha256":"747bd87d88e92c95d6e9e12b83fc108227cfcdfabec741f7f18763050a4fc39d","schema_version":"1.0","event_id":"sha256:747bd87d88e92c95d6e9e12b83fc108227cfcdfabec741f7f18763050a4fc39d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/KRFBPAN2CG4JV7S3FOJUZT5LAQ/bundle.json","state_url":"https://pith.science/pith/KRFBPAN2CG4JV7S3FOJUZT5LAQ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/KRFBPAN2CG4JV7S3FOJUZT5LAQ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-11T02:45:56Z","links":{"resolver":"https://pith.science/pith/KRFBPAN2CG4JV7S3FOJUZT5LAQ","bundle":"https://pith.science/pith/KRFBPAN2CG4JV7S3FOJUZT5LAQ/bundle.json","state":"https://pith.science/pith/KRFBPAN2CG4JV7S3FOJUZT5LAQ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/KRFBPAN2CG4JV7S3FOJUZT5LAQ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:KRFBPAN2CG4JV7S3FOJUZT5LAQ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"f2f829722681e9c4f1ef43c7ecfb4f8577cfae5a0d181a3083b4a27cf291796d","cross_cats_sorted":["cs.AI","cs.CV"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-06T07:59:08Z","title_canon_sha256":"ebaf1c8d69399531ebbd67613a0ee6e922f0b40999e5cd4a1c9e0f27c894f289"},"schema_version":"1.0","source":{"id":"2606.09909","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.09909","created_at":"2026-06-10T00:08:32Z"},{"alias_kind":"arxiv_version","alias_value":"2606.09909v1","created_at":"2026-06-10T00:08:32Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.09909","created_at":"2026-06-10T00:08:32Z"},{"alias_kind":"pith_short_12","alias_value":"KRFBPAN2CG4J","created_at":"2026-06-10T00:08:32Z"},{"alias_kind":"pith_short_16","alias_value":"KRFBPAN2CG4JV7S3","created_at":"2026-06-10T00:08:32Z"},{"alias_kind":"pith_short_8","alias_value":"KRFBPAN2","created_at":"2026-06-10T00:08:32Z"}],"graph_snapshots":[{"event_id":"sha256:747bd87d88e92c95d6e9e12b83fc108227cfcdfabec741f7f18763050a4fc39d","target":"graph","created_at":"2026-06-10T00:08:32Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.09909/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"With the growing concerns over copyright infringement in diffusion-based customization, adversarial attacks have emerged as a prominent defense strategy to prevent malicious content forgery in personalized image generation. However, current defenses typically introduce persistent perturbations in the latent space of Latent Diffusion Models (LDMs), which remain susceptible to adaptive bypasses by adversaries. In this paper, we introduce Two-Stage Latent Feature Optimization (TS-LFO), an efficient and effective copyright-stealing attack against protected diffusion-based customization. We begin b","authors_text":"Bin Chen, Hao Fang, Hao Wu, Hongyao Yu, Jiawei Kong, Shu-Tao Xia, Wenbo Yu, Zhiyong Wu, Ziang Xu","cross_cats":["cs.AI","cs.CV"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-06T07:59:08Z","title":"Bypassing Copyright Protection in Diffusion-based Customization via Two-Stage Latent Feature Optimization"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.09909","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:adf18bce546cac9a3b1d00b396932e09d9a1dcac6540b153e2418c09de446ce2","target":"record","created_at":"2026-06-10T00:08:32Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"f2f829722681e9c4f1ef43c7ecfb4f8577cfae5a0d181a3083b4a27cf291796d","cross_cats_sorted":["cs.AI","cs.CV"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-06T07:59:08Z","title_canon_sha256":"ebaf1c8d69399531ebbd67613a0ee6e922f0b40999e5cd4a1c9e0f27c894f289"},"schema_version":"1.0","source":{"id":"2606.09909","kind":"arxiv","version":1}},"canonical_sha256":"544a1781ba11b89afe5b2b934ccfab04129ca99266562aae3d6419ecf990041f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"544a1781ba11b89afe5b2b934ccfab04129ca99266562aae3d6419ecf990041f","first_computed_at":"2026-06-10T00:08:32.554645Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-10T00:08:32.554645Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"+A9gaI0H7CH6Szw3Z+CUKP9dgz8a+YpXnnd440XgGda1qqLDGUBYRJgBxdNgh+qSgGchbLaSulfjtuoKgx03Cg==","signature_status":"signed_v1","signed_at":"2026-06-10T00:08:32.555494Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.09909","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:adf18bce546cac9a3b1d00b396932e09d9a1dcac6540b153e2418c09de446ce2","sha256:747bd87d88e92c95d6e9e12b83fc108227cfcdfabec741f7f18763050a4fc39d"],"state_sha256":"6c85f50f1c2bbccba5953ca92633488c71023f0db32d111e505e4e526923c541"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"DBcHeeFGIgzKy0sgmGwtejoQQjHFLd9MjzclUp8KwwqOlpM7bMwDGLNmwWnz/NnTdVO0Ban9pB3W08zcj6W0Cw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-11T02:45:56.388758Z","bundle_sha256":"62255cf6b190ffc48c3e4b0dac6abac94980395597aa83399ce3250cbab38405"}}