{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:LL5EG7L63ZO7UCZ6SB4S6OLLDB","short_pith_number":"pith:LL5EG7L6","canonical_record":{"source":{"id":"2606.31639","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-30T13:21:43Z","cross_cats_sorted":["cs.AI","cs.GT","cs.LO"],"title_canon_sha256":"e8a0cdfb6da3a5353ded0f10b5fd7f7805394779f40328fd76bb280d46ad1782","abstract_canon_sha256":"f0cb88ca233e48c678d1991d784106b5512d50f38f16d1feff1535ad537b0bd3"},"schema_version":"1.0"},"canonical_sha256":"5afa437d7ede5dfa0b3e90792f396b185610e1fa9e78bf66514101bebfde8d5a","source":{"kind":"arxiv","id":"2606.31639","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.31639","created_at":"2026-07-01T01:18:10Z"},{"alias_kind":"arxiv_version","alias_value":"2606.31639v1","created_at":"2026-07-01T01:18:10Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.31639","created_at":"2026-07-01T01:18:10Z"},{"alias_kind":"pith_short_12","alias_value":"LL5EG7L63ZO7","created_at":"2026-07-01T01:18:10Z"},{"alias_kind":"pith_short_16","alias_value":"LL5EG7L63ZO7UCZ6","created_at":"2026-07-01T01:18:10Z"},{"alias_kind":"pith_short_8","alias_value":"LL5EG7L6","created_at":"2026-07-01T01:18:10Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:LL5EG7L63ZO7UCZ6SB4S6OLLDB","target":"record","payload":{"canonical_record":{"source":{"id":"2606.31639","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-30T13:21:43Z","cross_cats_sorted":["cs.AI","cs.GT","cs.LO"],"title_canon_sha256":"e8a0cdfb6da3a5353ded0f10b5fd7f7805394779f40328fd76bb280d46ad1782","abstract_canon_sha256":"f0cb88ca233e48c678d1991d784106b5512d50f38f16d1feff1535ad537b0bd3"},"schema_version":"1.0"},"canonical_sha256":"5afa437d7ede5dfa0b3e90792f396b185610e1fa9e78bf66514101bebfde8d5a","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-01T01:18:10.240863Z","signature_b64":"a16Cz56bPAZsJbyDh1icjDqHb+yV/aLEw5FnkfMS2jnhreXCj5HpRYNmT6odKFx4U7dLXG3sxzagaJeVyIgjDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5afa437d7ede5dfa0b3e90792f396b185610e1fa9e78bf66514101bebfde8d5a","last_reissued_at":"2026-07-01T01:18:10.240433Z","signature_status":"signed_v1","first_computed_at":"2026-07-01T01:18:10.240433Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.31639","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-01T01:18:10Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"S3Qwc6pm6wFgfFbBqfNJ8fetV49495KkXlKaXNa3hatzFH11jDgpVkmwiQQK1WAUIFHZu9Ll5i16VrnPxF1hAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T09:59:13.822601Z"},"content_sha256":"f8e2ee8a1baff74115815ebf91016304f1eaa38971bb18d1604f12e6536dd93f","schema_version":"1.0","event_id":"sha256:f8e2ee8a1baff74115815ebf91016304f1eaa38971bb18d1604f12e6536dd93f"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:LL5EG7L63ZO7UCZ6SB4S6OLLDB","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.GT","cs.LO"],"primary_cat":"cs.CR","authors_text":"Bo Tang, Seyed Bagher Hashemi Natanzi","submitted_at":"2026-06-30T13:21:43Z","abstract_excerpt":"Large language models are no longer only text generators. They are increasingly embedded in retrieval pipelines, enterprise assistants, coding environments, robotic systems, security-operation workflows, and autonomous agents that can read private data, call tools, write files, execute code, and act across organizational boundaries. This shift changes the security problem: risks do not arise from the model weights alone, but from the full lifecycle and application stack through which data, prompts, model outputs, tools, memories, and user authority interact. This paper systematizes the literat"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.31639","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.31639/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-01T01:18:10Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"CgOf1FzN9W9QeKqRv+Z5trd8cJ4uf9+kVt8bQE+nGzhM5l+pCeEBxVQQxLRsL0URqn6lMinnKrcCOIM7/o3PAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T09:59:13.822981Z"},"content_sha256":"dbb2ec005f48016ae8ba02b7dcfe6ddd8878a5ca2224c26a1149391b374f1ecd","schema_version":"1.0","event_id":"sha256:dbb2ec005f48016ae8ba02b7dcfe6ddd8878a5ca2224c26a1149391b374f1ecd"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/LL5EG7L63ZO7UCZ6SB4S6OLLDB/bundle.json","state_url":"https://pith.science/pith/LL5EG7L63ZO7UCZ6SB4S6OLLDB/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/LL5EG7L63ZO7UCZ6SB4S6OLLDB/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-02T09:59:13Z","links":{"resolver":"https://pith.science/pith/LL5EG7L63ZO7UCZ6SB4S6OLLDB","bundle":"https://pith.science/pith/LL5EG7L63ZO7UCZ6SB4S6OLLDB/bundle.json","state":"https://pith.science/pith/LL5EG7L63ZO7UCZ6SB4S6OLLDB/state.json","well_known_bundle":"https://pith.science/.well-known/pith/LL5EG7L63ZO7UCZ6SB4S6OLLDB/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:LL5EG7L63ZO7UCZ6SB4S6OLLDB","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"f0cb88ca233e48c678d1991d784106b5512d50f38f16d1feff1535ad537b0bd3","cross_cats_sorted":["cs.AI","cs.GT","cs.LO"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-30T13:21:43Z","title_canon_sha256":"e8a0cdfb6da3a5353ded0f10b5fd7f7805394779f40328fd76bb280d46ad1782"},"schema_version":"1.0","source":{"id":"2606.31639","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.31639","created_at":"2026-07-01T01:18:10Z"},{"alias_kind":"arxiv_version","alias_value":"2606.31639v1","created_at":"2026-07-01T01:18:10Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.31639","created_at":"2026-07-01T01:18:10Z"},{"alias_kind":"pith_short_12","alias_value":"LL5EG7L63ZO7","created_at":"2026-07-01T01:18:10Z"},{"alias_kind":"pith_short_16","alias_value":"LL5EG7L63ZO7UCZ6","created_at":"2026-07-01T01:18:10Z"},{"alias_kind":"pith_short_8","alias_value":"LL5EG7L6","created_at":"2026-07-01T01:18:10Z"}],"graph_snapshots":[{"event_id":"sha256:dbb2ec005f48016ae8ba02b7dcfe6ddd8878a5ca2224c26a1149391b374f1ecd","target":"graph","created_at":"2026-07-01T01:18:10Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.31639/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language models are no longer only text generators. They are increasingly embedded in retrieval pipelines, enterprise assistants, coding environments, robotic systems, security-operation workflows, and autonomous agents that can read private data, call tools, write files, execute code, and act across organizational boundaries. This shift changes the security problem: risks do not arise from the model weights alone, but from the full lifecycle and application stack through which data, prompts, model outputs, tools, memories, and user authority interact. This paper systematizes the literat","authors_text":"Bo Tang, Seyed Bagher Hashemi Natanzi","cross_cats":["cs.AI","cs.GT","cs.LO"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-30T13:21:43Z","title":"A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.31639","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f8e2ee8a1baff74115815ebf91016304f1eaa38971bb18d1604f12e6536dd93f","target":"record","created_at":"2026-07-01T01:18:10Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"f0cb88ca233e48c678d1991d784106b5512d50f38f16d1feff1535ad537b0bd3","cross_cats_sorted":["cs.AI","cs.GT","cs.LO"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-30T13:21:43Z","title_canon_sha256":"e8a0cdfb6da3a5353ded0f10b5fd7f7805394779f40328fd76bb280d46ad1782"},"schema_version":"1.0","source":{"id":"2606.31639","kind":"arxiv","version":1}},"canonical_sha256":"5afa437d7ede5dfa0b3e90792f396b185610e1fa9e78bf66514101bebfde8d5a","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"5afa437d7ede5dfa0b3e90792f396b185610e1fa9e78bf66514101bebfde8d5a","first_computed_at":"2026-07-01T01:18:10.240433Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-01T01:18:10.240433Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"a16Cz56bPAZsJbyDh1icjDqHb+yV/aLEw5FnkfMS2jnhreXCj5HpRYNmT6odKFx4U7dLXG3sxzagaJeVyIgjDQ==","signature_status":"signed_v1","signed_at":"2026-07-01T01:18:10.240863Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.31639","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f8e2ee8a1baff74115815ebf91016304f1eaa38971bb18d1604f12e6536dd93f","sha256:dbb2ec005f48016ae8ba02b7dcfe6ddd8878a5ca2224c26a1149391b374f1ecd"],"state_sha256":"d07975ce155c4f23f355bc794b6f77813b7812fa77a8b46f2d07de980a72aa06"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"wfuuRAzlTijaWzmP0amOYmtUIlf6uOhqSFLlakvqGpLHFatE8zO0svQrAHj1G0RivanLNo4jGn0OxlrEprZkDw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-02T09:59:13.825029Z","bundle_sha256":"13275f08dfaa8c34393a77b40f481b794cd87764103ca74fcb0f3e0d751189c8"}}