{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:MWHJ4A6MU5VHPKGMXMBIVB7DWC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"7db8b03553e85e18980bf144f88409bb3a4d7b23e6fbf7f78ac6e8c7eae9a5fd","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T13:39:15Z","title_canon_sha256":"9b191c6320c2c64f70c58e4b33faeb270971db14a83a8392fd68bf5a104b38fa"},"schema_version":"1.0","source":{"id":"2606.03647","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.03647","created_at":"2026-06-03T01:06:03Z"},{"alias_kind":"arxiv_version","alias_value":"2606.03647v1","created_at":"2026-06-03T01:06:03Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.03647","created_at":"2026-06-03T01:06:03Z"},{"alias_kind":"pith_short_12","alias_value":"MWHJ4A6MU5VH","created_at":"2026-06-03T01:06:03Z"},{"alias_kind":"pith_short_16","alias_value":"MWHJ4A6MU5VHPKGM","created_at":"2026-06-03T01:06:03Z"},{"alias_kind":"pith_short_8","alias_value":"MWHJ4A6M","created_at":"2026-06-03T01:06:03Z"}],"graph_snapshots":[{"event_id":"sha256:3318ac7b81fc4e64f7431d8136b114b710f43b0513c535eb704b8188498eacb3","target":"graph","created_at":"2026-06-03T01:06:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.03647/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Accurately evaluating adversarial robustness is a longstanding challenge. A flawed attack design can inflate robustness estimates, making deployment risk assessment and defense comparison unreliable. Historically, standardized attacks such as AutoAttack have largely resolved this for image classifiers, providing a reliable evaluation baseline for systematic comparison across defenses. However, no equivalent exists for LLM jailbreak evaluation yet, where designing such an attack is considerably more difficult. A reliable attack must, among other things, be black-box compatible, applicable to ar","authors_text":"David L\\\"udke, Jonas Dornbusch, Leo Schwinn, Stephan G\\\"unnemann, Vincent Limbach","cross_cats":["cs.AI","cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T13:39:15Z","title":"Black-box, Adaptive, Efficient, Transferable, Harmful, Applicable... Attacks Are All You Need to Break LLMs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.03647","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e0c20507df0c333b6d4368da0ae2024fc04a7f652d12cee0c40f59aae7bf8432","target":"record","created_at":"2026-06-03T01:06:03Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"7db8b03553e85e18980bf144f88409bb3a4d7b23e6fbf7f78ac6e8c7eae9a5fd","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T13:39:15Z","title_canon_sha256":"9b191c6320c2c64f70c58e4b33faeb270971db14a83a8392fd68bf5a104b38fa"},"schema_version":"1.0","source":{"id":"2606.03647","kind":"arxiv","version":1}},"canonical_sha256":"658e9e03cca76a77a8ccbb028a87e3b0a133b3f3ddac8253a41f0ba94952f235","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"658e9e03cca76a77a8ccbb028a87e3b0a133b3f3ddac8253a41f0ba94952f235","first_computed_at":"2026-06-03T01:06:03.445576Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-03T01:06:03.445576Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"qjMSF9TLrjXTyWzDMsY43zWDH8+9oBwgrvcIagVK7ZfUBKTzCDwLdXo8LoQ5fqwM6b7deily2D7hSD39vhqQAQ==","signature_status":"signed_v1","signed_at":"2026-06-03T01:06:03.446115Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.03647","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e0c20507df0c333b6d4368da0ae2024fc04a7f652d12cee0c40f59aae7bf8432","sha256:3318ac7b81fc4e64f7431d8136b114b710f43b0513c535eb704b8188498eacb3"],"state_sha256":"97e76958a14e8d1ca2f34a2fdd573a9808483336b809a818b16795bfe3cb15a4"}