{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:MWXLUWAF4MCFLDY3XNE6OOCCEK","short_pith_number":"pith:MWXLUWAF","canonical_record":{"source":{"id":"2510.00586","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2025-10-01T07:07:22Z","cross_cats_sorted":["cs.CL","cs.CR"],"title_canon_sha256":"b580ce71cbbc896764092d70fa61f919de751eaa5b1f2cac8b16322b95cc2564","abstract_canon_sha256":"3d53ddb79132ed92a0111fbf61a22ee44b7368910da265dc30cce9c9cd0c20b4"},"schema_version":"1.0"},"canonical_sha256":"65aeba5805e304558f1bbb49e738422286bdc39ac33f7a2f04ff4a822eeb91f3","source":{"kind":"arxiv","id":"2510.00586","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2510.00586","created_at":"2026-06-26T01:15:46Z"},{"alias_kind":"arxiv_version","alias_value":"2510.00586v3","created_at":"2026-06-26T01:15:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2510.00586","created_at":"2026-06-26T01:15:46Z"},{"alias_kind":"pith_short_12","alias_value":"MWXLUWAF4MCF","created_at":"2026-06-26T01:15:46Z"},{"alias_kind":"pith_short_16","alias_value":"MWXLUWAF4MCFLDY3","created_at":"2026-06-26T01:15:46Z"},{"alias_kind":"pith_short_8","alias_value":"MWXLUWAF","created_at":"2026-06-26T01:15:46Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:MWXLUWAF4MCFLDY3XNE6OOCCEK","target":"record","payload":{"canonical_record":{"source":{"id":"2510.00586","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2025-10-01T07:07:22Z","cross_cats_sorted":["cs.CL","cs.CR"],"title_canon_sha256":"b580ce71cbbc896764092d70fa61f919de751eaa5b1f2cac8b16322b95cc2564","abstract_canon_sha256":"3d53ddb79132ed92a0111fbf61a22ee44b7368910da265dc30cce9c9cd0c20b4"},"schema_version":"1.0"},"canonical_sha256":"65aeba5805e304558f1bbb49e738422286bdc39ac33f7a2f04ff4a822eeb91f3","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-26T01:15:46.181249Z","signature_b64":"CNU0c3coVKZol2Pp0i899SRNIIMbOmNhnmISJMr2qMBIhf8J5pnAwuUsDeEvNJA2bGaOPFnxpIRgIKy195wZCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"65aeba5805e304558f1bbb49e738422286bdc39ac33f7a2f04ff4a822eeb91f3","last_reissued_at":"2026-06-26T01:15:46.180771Z","signature_status":"signed_v1","first_computed_at":"2026-06-26T01:15:46.180771Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2510.00586","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-26T01:15:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ufiUj2JDmWKGwOGECeJ0r2LR9ULXk2h49IEkssGDtQqkbI9ufC6ixHzkTxeXXGEsnGq97jbTsmscNL4splrvDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T09:47:41.985530Z"},"content_sha256":"4dc75ee50150ab071e35f755c316efda6d6e7b2cb835451cccc1cfc199281739","schema_version":"1.0","event_id":"sha256:4dc75ee50150ab071e35f755c316efda6d6e7b2cb835451cccc1cfc199281739"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:MWXLUWAF4MCFLDY3XNE6OOCCEK","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Eyes-on-Me: Scalable RAG Poisoning through Transferable Attention-Steering Attractors","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"Cheng-Lin Yang, Sian-Yao Huang, Yen-Shan Chen, Yun-Nung Chen","submitted_at":"2025-10-01T07:07:22Z","abstract_excerpt":"Existing data poisoning attacks on retrieval-augmented generation (RAG) systems scale poorly because they require costly optimization of poisoned documents for each target phrase. We introduce Eyes-on-Me, a modular attack that decomposes an adversarial document into reusable **Attention Attractors** and **Focus Regions**. Attractors are optimized to direct attention to the Focus Region. Attackers can then insert semantic baits for the retriever or malicious instructions for the generator, adapting to new targets at near zero cost. This is achieved by steering a small subset of attention heads "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2510.00586","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2510.00586/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-26T01:15:46Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+tEPUsDS/3jWyyeFLSbi/sdTecOB1Gvg5GtO4oeIni/mOLLD/en4130JMzC8ahd4Rz3rLA4Viyui30TnebTPDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T09:47:41.985913Z"},"content_sha256":"11f7a22f4f19d63f631152a3fae1bf4717da204a00cb8953769d417146678fa4","schema_version":"1.0","event_id":"sha256:11f7a22f4f19d63f631152a3fae1bf4717da204a00cb8953769d417146678fa4"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/MWXLUWAF4MCFLDY3XNE6OOCCEK/bundle.json","state_url":"https://pith.science/pith/MWXLUWAF4MCFLDY3XNE6OOCCEK/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/MWXLUWAF4MCFLDY3XNE6OOCCEK/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-30T09:47:41Z","links":{"resolver":"https://pith.science/pith/MWXLUWAF4MCFLDY3XNE6OOCCEK","bundle":"https://pith.science/pith/MWXLUWAF4MCFLDY3XNE6OOCCEK/bundle.json","state":"https://pith.science/pith/MWXLUWAF4MCFLDY3XNE6OOCCEK/state.json","well_known_bundle":"https://pith.science/.well-known/pith/MWXLUWAF4MCFLDY3XNE6OOCCEK/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:MWXLUWAF4MCFLDY3XNE6OOCCEK","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"3d53ddb79132ed92a0111fbf61a22ee44b7368910da265dc30cce9c9cd0c20b4","cross_cats_sorted":["cs.CL","cs.CR"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2025-10-01T07:07:22Z","title_canon_sha256":"b580ce71cbbc896764092d70fa61f919de751eaa5b1f2cac8b16322b95cc2564"},"schema_version":"1.0","source":{"id":"2510.00586","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2510.00586","created_at":"2026-06-26T01:15:46Z"},{"alias_kind":"arxiv_version","alias_value":"2510.00586v3","created_at":"2026-06-26T01:15:46Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2510.00586","created_at":"2026-06-26T01:15:46Z"},{"alias_kind":"pith_short_12","alias_value":"MWXLUWAF4MCF","created_at":"2026-06-26T01:15:46Z"},{"alias_kind":"pith_short_16","alias_value":"MWXLUWAF4MCFLDY3","created_at":"2026-06-26T01:15:46Z"},{"alias_kind":"pith_short_8","alias_value":"MWXLUWAF","created_at":"2026-06-26T01:15:46Z"}],"graph_snapshots":[{"event_id":"sha256:11f7a22f4f19d63f631152a3fae1bf4717da204a00cb8953769d417146678fa4","target":"graph","created_at":"2026-06-26T01:15:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2510.00586/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Existing data poisoning attacks on retrieval-augmented generation (RAG) systems scale poorly because they require costly optimization of poisoned documents for each target phrase. We introduce Eyes-on-Me, a modular attack that decomposes an adversarial document into reusable **Attention Attractors** and **Focus Regions**. Attractors are optimized to direct attention to the Focus Region. Attackers can then insert semantic baits for the retriever or malicious instructions for the generator, adapting to new targets at near zero cost. This is achieved by steering a small subset of attention heads ","authors_text":"Cheng-Lin Yang, Sian-Yao Huang, Yen-Shan Chen, Yun-Nung Chen","cross_cats":["cs.CL","cs.CR"],"headline":"","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2025-10-01T07:07:22Z","title":"Eyes-on-Me: Scalable RAG Poisoning through Transferable Attention-Steering Attractors"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2510.00586","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4dc75ee50150ab071e35f755c316efda6d6e7b2cb835451cccc1cfc199281739","target":"record","created_at":"2026-06-26T01:15:46Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"3d53ddb79132ed92a0111fbf61a22ee44b7368910da265dc30cce9c9cd0c20b4","cross_cats_sorted":["cs.CL","cs.CR"],"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.LG","submitted_at":"2025-10-01T07:07:22Z","title_canon_sha256":"b580ce71cbbc896764092d70fa61f919de751eaa5b1f2cac8b16322b95cc2564"},"schema_version":"1.0","source":{"id":"2510.00586","kind":"arxiv","version":3}},"canonical_sha256":"65aeba5805e304558f1bbb49e738422286bdc39ac33f7a2f04ff4a822eeb91f3","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"65aeba5805e304558f1bbb49e738422286bdc39ac33f7a2f04ff4a822eeb91f3","first_computed_at":"2026-06-26T01:15:46.180771Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-26T01:15:46.180771Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"CNU0c3coVKZol2Pp0i899SRNIIMbOmNhnmISJMr2qMBIhf8J5pnAwuUsDeEvNJA2bGaOPFnxpIRgIKy195wZCA==","signature_status":"signed_v1","signed_at":"2026-06-26T01:15:46.181249Z","signed_message":"canonical_sha256_bytes"},"source_id":"2510.00586","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4dc75ee50150ab071e35f755c316efda6d6e7b2cb835451cccc1cfc199281739","sha256:11f7a22f4f19d63f631152a3fae1bf4717da204a00cb8953769d417146678fa4"],"state_sha256":"cb3a7dea3290e128f13fa157130bcb5d0607e30bdc140f152309c0e18464c546"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"U4bEACki0Ra+jcZ/mqG+MwXwCF2qg1iCcVSVuyhJOJhvQe75x2R2yHNZDWqYH0+4M0QgRztxMijyPosTAYRZBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-30T09:47:41.988305Z","bundle_sha256":"001249ad2bd008aa6ac1a066928222a9a2ed6ff0fb6c7c620a4f219f209b0cd0"}}