{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:NRG7PQ34TFLSQVH4GFIYQDOHUD","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"7146fda1be4010a60c8768f68422412fed439678cdc2f5a31d465730b72bf91c","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-09T11:53:25Z","title_canon_sha256":"9d7a6dd9ae6bfb7a9c8811c1db0dbdfbfa2e0e0c49a65bc444122144788cf486"},"schema_version":"1.0","source":{"id":"2606.10742","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.10742","created_at":"2026-06-10T01:10:37Z"},{"alias_kind":"arxiv_version","alias_value":"2606.10742v1","created_at":"2026-06-10T01:10:37Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.10742","created_at":"2026-06-10T01:10:37Z"},{"alias_kind":"pith_short_12","alias_value":"NRG7PQ34TFLS","created_at":"2026-06-10T01:10:37Z"},{"alias_kind":"pith_short_16","alias_value":"NRG7PQ34TFLSQVH4","created_at":"2026-06-10T01:10:37Z"},{"alias_kind":"pith_short_8","alias_value":"NRG7PQ34","created_at":"2026-06-10T01:10:37Z"}],"graph_snapshots":[{"event_id":"sha256:08967c5c3afd827a451e04548b6f28de6476956378531129648ab210e56144f4","target":"graph","created_at":"2026-06-10T01:10:37Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.10742/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"External memory has become a core component of modern web agents, enabling long-horizon reasoning through the retrieval of past experiences. However, this paradigm introduces a critical vulnerability: malicious content injected into memory can be persistently recalled and repeatedly influence agent behavior. In this work, we identify and systematically study multimodal memory poisoning, an overlooked yet practical attack surface in web-agent systems. We propose MemVenom, a unified black-box attack framework that poisons graph-structured external memory with coordinated text-image evidence. Our","authors_text":"Bin Chen, Fan Mo, Hao Fang, Hao Sun, Kuofeng Gao, Shu-Tao Xia, Yaowei Wang, Yv Zhang","cross_cats":["cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-09T11:53:25Z","title":"MemVenom: Triggered Poisoning of Multimodal Memories in Web Agents"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.10742","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:d69956df90d4d681f83a4804c666ba191b8f3bed09c36699c6477ace4ff68c1e","target":"record","created_at":"2026-06-10T01:10:37Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"7146fda1be4010a60c8768f68422412fed439678cdc2f5a31d465730b72bf91c","cross_cats_sorted":["cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-09T11:53:25Z","title_canon_sha256":"9d7a6dd9ae6bfb7a9c8811c1db0dbdfbfa2e0e0c49a65bc444122144788cf486"},"schema_version":"1.0","source":{"id":"2606.10742","kind":"arxiv","version":1}},"canonical_sha256":"6c4df7c37c99572854fc3151880dc7a0e68de7c3742558fad1a0c6285774c51b","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"6c4df7c37c99572854fc3151880dc7a0e68de7c3742558fad1a0c6285774c51b","first_computed_at":"2026-06-10T01:10:37.887871Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-10T01:10:37.887871Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"WdKxilKjzttgPRwlWUpEZ8sY9uL+Q6I7wLltJWW/IOz9uYw6keorb8qRKZTFD4fG0fDbLooAb720VT+kd+4OBA==","signature_status":"signed_v1","signed_at":"2026-06-10T01:10:37.888725Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.10742","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:d69956df90d4d681f83a4804c666ba191b8f3bed09c36699c6477ace4ff68c1e","sha256:08967c5c3afd827a451e04548b6f28de6476956378531129648ab210e56144f4"],"state_sha256":"c59fda75311522e1cbb5b386244cac91e7c2f5624fec14d746119c595845ae4c"}