{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:LGPRSZDAEEF234RVUB65YHCPA3","short_pith_number":"pith:LGPRSZDA","canonical_record":{"source":{"id":"2605.07961","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-08T16:24:54Z","cross_cats_sorted":["cs.CR","cs.NI"],"title_canon_sha256":"a3e38dc694b1bbd8aa381aa3a449760318fac293da863a9f6bc3153023bcb525","abstract_canon_sha256":"72e1b3bc0672a090a8414c8ef199b00cff891431cb96adb3a34084060c4ce064"},"schema_version":"1.0"},"canonical_sha256":"599f196460210badf235a07ddc1c4f06f7fe6cdf69ea5a1bf3d18efe48be86c2","source":{"kind":"arxiv","id":"2605.07961","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.07961","created_at":"2026-07-07T02:18:42Z"},{"alias_kind":"arxiv_version","alias_value":"2605.07961v2","created_at":"2026-07-07T02:18:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.07961","created_at":"2026-07-07T02:18:42Z"},{"alias_kind":"pith_short_12","alias_value":"LGPRSZDAEEF2","created_at":"2026-07-07T02:18:42Z"},{"alias_kind":"pith_short_16","alias_value":"LGPRSZDAEEF234RV","created_at":"2026-07-07T02:18:42Z"},{"alias_kind":"pith_short_8","alias_value":"LGPRSZDA","created_at":"2026-07-07T02:18:42Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:LGPRSZDAEEF234RVUB65YHCPA3","target":"record","payload":{"canonical_record":{"source":{"id":"2605.07961","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-08T16:24:54Z","cross_cats_sorted":["cs.CR","cs.NI"],"title_canon_sha256":"a3e38dc694b1bbd8aa381aa3a449760318fac293da863a9f6bc3153023bcb525","abstract_canon_sha256":"72e1b3bc0672a090a8414c8ef199b00cff891431cb96adb3a34084060c4ce064"},"schema_version":"1.0"},"canonical_sha256":"599f196460210badf235a07ddc1c4f06f7fe6cdf69ea5a1bf3d18efe48be86c2","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-07T02:18:42.317269Z","signature_b64":"VfaeSN7c9pR0e9OJn9OmF/sc9NpyjhPO/O9yx5m2NNbs4DcJR61nISL29wU+ALl3robR3E8UgEzqKWXhDW0qBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"599f196460210badf235a07ddc1c4f06f7fe6cdf69ea5a1bf3d18efe48be86c2","last_reissued_at":"2026-07-07T02:18:42.316590Z","signature_status":"signed_v1","first_computed_at":"2026-07-07T02:18:42.316590Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.07961","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-07T02:18:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"uzH3SMgf7dK+v6gOACxrOFJhVj2NnQ5uWfouB7kGS0QVhY3F62oUN93pJz6gVd85aup6x/oO6wt1xr8CV8+BBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-04T22:26:23.035732Z"},"content_sha256":"5d5b44ef1a13106679e3a7aefae1ede44c829f851d83a0e572653282bbf19850","schema_version":"1.0","event_id":"sha256:5d5b44ef1a13106679e3a7aefae1ede44c829f851d83a0e572653282bbf19850"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:LGPRSZDAEEF234RVUB65YHCPA3","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Graph Representation Learning Augmented Model Manipulation on Federated Fine-Tuning of LLMs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"A graph representation learning method allows attackers to generate malicious updates that corrupt federated fine-tuning of LLMs while evading detection.","cross_cats":["cs.CR","cs.NI"],"primary_cat":"cs.LG","authors_text":"Falko Dressler, Hanlin Cai, Haofan Dong, Houtianfu Wang, Kai Li, Ozgur B. Akan, Yichen Li","submitted_at":"2026-05-08T16:24:54Z","abstract_excerpt":"Federated fine-tuning (FFT) has emerged as a privacy-preserving paradigm for collaboratively adapting large language models (LLMs). Built upon federated learning, FFT enables distributed agents to jointly refine a shared pretrained LLM by aggregating local LLM updates without sharing local raw data. However, FFT-based LLMs remain vulnerable to model manipulation threats, in which adversarial participants upload manipulated LLM updates that corrupt the aggregation process and degrade the performance of the global LLM. In this paper, we propose an Augmented Model maniPulation (AugMP) strategy ag"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"Experimental results across multiple LLM backbones demonstrate that the AugMP strategy achieves the strongest manipulation performance among all competing baselines, reducing the global LLM accuracy by up to 26% and degrading the average accuracy of local LLM agents by up to 22%.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That a graph representation learning framework capturing feature correlations among benign LLM updates can reliably guide generation of malicious updates that embed adversarial objectives while preserving high statistical and geometric consistency with benign updates.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Graph representation learning plus iterative augmented Lagrangian optimization creates stronger, harder-to-detect model manipulation attacks on federated LLM fine-tuning, cutting global accuracy by up to 26%.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"A graph representation learning method allows attackers to generate malicious updates that corrupt federated fine-tuning of LLMs while evading detection.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"781a1beb3f0a0ddc2be1c250f3d43e87f353d43483958a840f43ee4da622b5ad"},"source":{"id":"2605.07961","kind":"arxiv","version":2},"verdict":{"id":"3ca25db9-95d0-4f56-8fdf-93dc91eda4c5","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-11T02:38:30.234355Z","strongest_claim":"Experimental results across multiple LLM backbones demonstrate that the AugMP strategy achieves the strongest manipulation performance among all competing baselines, reducing the global LLM accuracy by up to 26% and degrading the average accuracy of local LLM agents by up to 22%.","one_line_summary":"Graph representation learning plus iterative augmented Lagrangian optimization creates stronger, harder-to-detect model manipulation attacks on federated LLM fine-tuning, cutting global accuracy by up to 26%.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That a graph representation learning framework capturing feature correlations among benign LLM updates can reliably guide generation of malicious updates that embed adversarial objectives while preserving high statistical and geometric consistency with benign updates.","pith_extraction_headline":"A graph representation learning method allows attackers to generate malicious updates that corrupt federated fine-tuning of LLMs while evading detection."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.07961/integrity.json","findings":[],"available":true,"detectors_run":[{"name":"claim_evidence","ran_at":"2026-05-20T10:02:09.437585Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"ai_meta_artifact","ran_at":"2026-05-20T04:45:16.336128Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"doi_title_agreement","ran_at":"2026-05-19T15:31:18.113056Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"doi_compliance","ran_at":"2026-05-19T11:21:52.738057Z","status":"completed","version":"1.0.0","findings_count":0}],"snapshot_sha256":"6dc9b10277789a7bfdc05ee84e3703b1d7e9569a8cb84238be79d68b0630b5d5"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":1,"snapshot_sha256":"591f69ead3bb04618040d30c7bc63b9fa305e2c880904b19480bc687bb860732"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"3ca25db9-95d0-4f56-8fdf-93dc91eda4c5"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-07T02:18:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"OBtGTUr8J7WCZvgBsmBdat9rkQ3BQOuubLApe+D2c6EGIOik11HYwZp2fXQgCtKjs7vyZBxpwYYKttCAdu83Bg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-04T22:26:23.036455Z"},"content_sha256":"3752a211b3a3dccdffd38ef8e37905924a910308c3db2e13916d31c1c28c125b","schema_version":"1.0","event_id":"sha256:3752a211b3a3dccdffd38ef8e37905924a910308c3db2e13916d31c1c28c125b"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/LGPRSZDAEEF234RVUB65YHCPA3/bundle.json","state_url":"https://pith.science/pith/LGPRSZDAEEF234RVUB65YHCPA3/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/LGPRSZDAEEF234RVUB65YHCPA3/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-04T22:26:23Z","links":{"resolver":"https://pith.science/pith/LGPRSZDAEEF234RVUB65YHCPA3","bundle":"https://pith.science/pith/LGPRSZDAEEF234RVUB65YHCPA3/bundle.json","state":"https://pith.science/pith/LGPRSZDAEEF234RVUB65YHCPA3/state.json","well_known_bundle":"https://pith.science/.well-known/pith/LGPRSZDAEEF234RVUB65YHCPA3/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:LGPRSZDAEEF234RVUB65YHCPA3","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"72e1b3bc0672a090a8414c8ef199b00cff891431cb96adb3a34084060c4ce064","cross_cats_sorted":["cs.CR","cs.NI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-08T16:24:54Z","title_canon_sha256":"a3e38dc694b1bbd8aa381aa3a449760318fac293da863a9f6bc3153023bcb525"},"schema_version":"1.0","source":{"id":"2605.07961","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.07961","created_at":"2026-07-07T02:18:42Z"},{"alias_kind":"arxiv_version","alias_value":"2605.07961v2","created_at":"2026-07-07T02:18:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.07961","created_at":"2026-07-07T02:18:42Z"},{"alias_kind":"pith_short_12","alias_value":"LGPRSZDAEEF2","created_at":"2026-07-07T02:18:42Z"},{"alias_kind":"pith_short_16","alias_value":"LGPRSZDAEEF234RV","created_at":"2026-07-07T02:18:42Z"},{"alias_kind":"pith_short_8","alias_value":"LGPRSZDA","created_at":"2026-07-07T02:18:42Z"}],"graph_snapshots":[{"event_id":"sha256:3752a211b3a3dccdffd38ef8e37905924a910308c3db2e13916d31c1c28c125b","target":"graph","created_at":"2026-07-07T02:18:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"Experimental results across multiple LLM backbones demonstrate that the AugMP strategy achieves the strongest manipulation performance among all competing baselines, reducing the global LLM accuracy by up to 26% and degrading the average accuracy of local LLM agents by up to 22%."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That a graph representation learning framework capturing feature correlations among benign LLM updates can reliably guide generation of malicious updates that embed adversarial objectives while preserving high statistical and geometric consistency with benign updates."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"Graph representation learning plus iterative augmented Lagrangian optimization creates stronger, harder-to-detect model manipulation attacks on federated LLM fine-tuning, cutting global accuracy by up to 26%."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"A graph representation learning method allows attackers to generate malicious updates that corrupt federated fine-tuning of LLMs while evading detection."}],"snapshot_sha256":"781a1beb3f0a0ddc2be1c250f3d43e87f353d43483958a840f43ee4da622b5ad"},"formal_canon":{"evidence_count":1,"snapshot_sha256":"591f69ead3bb04618040d30c7bc63b9fa305e2c880904b19480bc687bb860732"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"claim_evidence","ran_at":"2026-05-20T10:02:09.437585Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"ai_meta_artifact","ran_at":"2026-05-20T04:45:16.336128Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"doi_title_agreement","ran_at":"2026-05-19T15:31:18.113056Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"doi_compliance","ran_at":"2026-05-19T11:21:52.738057Z","status":"completed","version":"1.0.0"}],"endpoint":"/pith/2605.07961/integrity.json","findings":[],"snapshot_sha256":"6dc9b10277789a7bfdc05ee84e3703b1d7e9569a8cb84238be79d68b0630b5d5","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Federated fine-tuning (FFT) has emerged as a privacy-preserving paradigm for collaboratively adapting large language models (LLMs). Built upon federated learning, FFT enables distributed agents to jointly refine a shared pretrained LLM by aggregating local LLM updates without sharing local raw data. However, FFT-based LLMs remain vulnerable to model manipulation threats, in which adversarial participants upload manipulated LLM updates that corrupt the aggregation process and degrade the performance of the global LLM. In this paper, we propose an Augmented Model maniPulation (AugMP) strategy ag","authors_text":"Falko Dressler, Hanlin Cai, Haofan Dong, Houtianfu Wang, Kai Li, Ozgur B. Akan, Yichen Li","cross_cats":["cs.CR","cs.NI"],"headline":"A graph representation learning method allows attackers to generate malicious updates that corrupt federated fine-tuning of LLMs while evading detection.","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-08T16:24:54Z","title":"Graph Representation Learning Augmented Model Manipulation on Federated Fine-Tuning of LLMs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.07961","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-11T02:38:30.234355Z","id":"3ca25db9-95d0-4f56-8fdf-93dc91eda4c5","model_set":{"reader":"grok-4.3"},"one_line_summary":"Graph representation learning plus iterative augmented Lagrangian optimization creates stronger, harder-to-detect model manipulation attacks on federated LLM fine-tuning, cutting global accuracy by up to 26%.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"A graph representation learning method allows attackers to generate malicious updates that corrupt federated fine-tuning of LLMs while evading detection.","strongest_claim":"Experimental results across multiple LLM backbones demonstrate that the AugMP strategy achieves the strongest manipulation performance among all competing baselines, reducing the global LLM accuracy by up to 26% and degrading the average accuracy of local LLM agents by up to 22%.","weakest_assumption":"That a graph representation learning framework capturing feature correlations among benign LLM updates can reliably guide generation of malicious updates that embed adversarial objectives while preserving high statistical and geometric consistency with benign updates."}},"verdict_id":"3ca25db9-95d0-4f56-8fdf-93dc91eda4c5"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5d5b44ef1a13106679e3a7aefae1ede44c829f851d83a0e572653282bbf19850","target":"record","created_at":"2026-07-07T02:18:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"72e1b3bc0672a090a8414c8ef199b00cff891431cb96adb3a34084060c4ce064","cross_cats_sorted":["cs.CR","cs.NI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.LG","submitted_at":"2026-05-08T16:24:54Z","title_canon_sha256":"a3e38dc694b1bbd8aa381aa3a449760318fac293da863a9f6bc3153023bcb525"},"schema_version":"1.0","source":{"id":"2605.07961","kind":"arxiv","version":2}},"canonical_sha256":"599f196460210badf235a07ddc1c4f06f7fe6cdf69ea5a1bf3d18efe48be86c2","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"599f196460210badf235a07ddc1c4f06f7fe6cdf69ea5a1bf3d18efe48be86c2","first_computed_at":"2026-07-07T02:18:42.316590Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-07T02:18:42.316590Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"VfaeSN7c9pR0e9OJn9OmF/sc9NpyjhPO/O9yx5m2NNbs4DcJR61nISL29wU+ALl3robR3E8UgEzqKWXhDW0qBg==","signature_status":"signed_v1","signed_at":"2026-07-07T02:18:42.317269Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.07961","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:5d5b44ef1a13106679e3a7aefae1ede44c829f851d83a0e572653282bbf19850","sha256:3752a211b3a3dccdffd38ef8e37905924a910308c3db2e13916d31c1c28c125b"],"state_sha256":"0467c5177788010983714ed940b5e01985c57beb4662ad6a48291a2a3614f639"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"tqKjDgLG/o01sINDeebN7qytmqhBzHyM6IbwrsQfBZP4rC2tPmGx6NQzjBiNE6s4iIJeGNbxyXcSMlvqQ89XCQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-04T22:26:23.040815Z","bundle_sha256":"91a316756b0dd80a1737aac2beefd481262b25b43c29a03b7e99e754f7cac3f6"}}