{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:PABCO7SY56LXAELUEBJGB37JV3","short_pith_number":"pith:PABCO7SY","canonical_record":{"source":{"id":"2605.25073","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-24T13:34:47Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"5c89794ae6e7368abbd9069ccd2864f3ec811186b7bf35853cc8c300a9fce260","abstract_canon_sha256":"09f52bd2be9734c7acc9595b653758727fe6884d99b269d3766cf9930a2b1bc7"},"schema_version":"1.0"},"canonical_sha256":"7802277e58ef97701174205260efe9aeefe6b818e38046517b3d8d6fc17e06e9","source":{"kind":"arxiv","id":"2605.25073","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.25073","created_at":"2026-05-26T02:03:38Z"},{"alias_kind":"arxiv_version","alias_value":"2605.25073v1","created_at":"2026-05-26T02:03:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.25073","created_at":"2026-05-26T02:03:38Z"},{"alias_kind":"pith_short_12","alias_value":"PABCO7SY56LX","created_at":"2026-05-26T02:03:38Z"},{"alias_kind":"pith_short_16","alias_value":"PABCO7SY56LXAELU","created_at":"2026-05-26T02:03:38Z"},{"alias_kind":"pith_short_8","alias_value":"PABCO7SY","created_at":"2026-05-26T02:03:38Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:PABCO7SY56LXAELUEBJGB37JV3","target":"record","payload":{"canonical_record":{"source":{"id":"2605.25073","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-24T13:34:47Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"5c89794ae6e7368abbd9069ccd2864f3ec811186b7bf35853cc8c300a9fce260","abstract_canon_sha256":"09f52bd2be9734c7acc9595b653758727fe6884d99b269d3766cf9930a2b1bc7"},"schema_version":"1.0"},"canonical_sha256":"7802277e58ef97701174205260efe9aeefe6b818e38046517b3d8d6fc17e06e9","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-26T02:03:38.602181Z","signature_b64":"UKZ1xiE6+0WaQX/geGiaVu+0D+M9s6ZEEPnYxinF71lbNhzV4KqPVKKFVdYsbc2g/ob2ppbaSGtKF/8/A7ECCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7802277e58ef97701174205260efe9aeefe6b818e38046517b3d8d6fc17e06e9","last_reissued_at":"2026-05-26T02:03:38.601489Z","signature_status":"signed_v1","first_computed_at":"2026-05-26T02:03:38.601489Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.25073","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T02:03:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7irrHcJ73Mts76lu77TaWvOstRnLulmZMrU5okG6XGj+xKTH+EXn5/v0QI3tzLbqYXPPR3YeJbgKiZZ8HlMBBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T10:20:54.455616Z"},"content_sha256":"7a422d3b33281257751f31d100e7cdec1aa5ed6cd39b295492a2c86e16f3af27","schema_version":"1.0","event_id":"sha256:7a422d3b33281257751f31d100e7cdec1aa5ed6cd39b295492a2c86e16f3af27"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:PABCO7SY56LXAELUEBJGB37JV3","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Security in the Fine-Tuning Lifecycle of Large Language Models: Threats, Defenses,Evaluation, and Future Directions","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Rajkumar Buyya, Runze Chen, Wenjuan Li, Yitao Liu","submitted_at":"2026-05-24T13:34:47Z","abstract_excerpt":"Background: Fine-tuning is central to adapting pre-trained Large Language Models (LLMs) to downstream tasks, but its reliance on training data, parameter updates, and reusable components opens entry points for attackers. Threats have evolved from data poisoning and weight tampering to agent manipulation and interface exploitation, yet existing reviews lack a unified framework spanning the full fine-tuning lifecycle. Objective: This paper presents a systematic survey of LLM fine-tuning security and establishes a lifecycle-based framework for comparing attacks and defenses, complemented by unifi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.25073","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.25073/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-26T02:03:38Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"5CtNi9z/zdkwr6J8EO9KzuBcjyhTsO8ZYqODAEpozIUfKUEH1myVP+Oo8FPwn78kIEcs9EbQ0Qkqug7p5+k9Bw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T10:20:54.455986Z"},"content_sha256":"b43a28a499fcc5936b898335a6e2ba00a6fed09744c38f873292d5e8acc1ce3a","schema_version":"1.0","event_id":"sha256:b43a28a499fcc5936b898335a6e2ba00a6fed09744c38f873292d5e8acc1ce3a"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/PABCO7SY56LXAELUEBJGB37JV3/bundle.json","state_url":"https://pith.science/pith/PABCO7SY56LXAELUEBJGB37JV3/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/PABCO7SY56LXAELUEBJGB37JV3/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-09T10:20:54Z","links":{"resolver":"https://pith.science/pith/PABCO7SY56LXAELUEBJGB37JV3","bundle":"https://pith.science/pith/PABCO7SY56LXAELUEBJGB37JV3/bundle.json","state":"https://pith.science/pith/PABCO7SY56LXAELUEBJGB37JV3/state.json","well_known_bundle":"https://pith.science/.well-known/pith/PABCO7SY56LXAELUEBJGB37JV3/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:PABCO7SY56LXAELUEBJGB37JV3","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"09f52bd2be9734c7acc9595b653758727fe6884d99b269d3766cf9930a2b1bc7","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-24T13:34:47Z","title_canon_sha256":"5c89794ae6e7368abbd9069ccd2864f3ec811186b7bf35853cc8c300a9fce260"},"schema_version":"1.0","source":{"id":"2605.25073","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.25073","created_at":"2026-05-26T02:03:38Z"},{"alias_kind":"arxiv_version","alias_value":"2605.25073v1","created_at":"2026-05-26T02:03:38Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.25073","created_at":"2026-05-26T02:03:38Z"},{"alias_kind":"pith_short_12","alias_value":"PABCO7SY56LX","created_at":"2026-05-26T02:03:38Z"},{"alias_kind":"pith_short_16","alias_value":"PABCO7SY56LXAELU","created_at":"2026-05-26T02:03:38Z"},{"alias_kind":"pith_short_8","alias_value":"PABCO7SY","created_at":"2026-05-26T02:03:38Z"}],"graph_snapshots":[{"event_id":"sha256:b43a28a499fcc5936b898335a6e2ba00a6fed09744c38f873292d5e8acc1ce3a","target":"graph","created_at":"2026-05-26T02:03:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.25073/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Background: Fine-tuning is central to adapting pre-trained Large Language Models (LLMs) to downstream tasks, but its reliance on training data, parameter updates, and reusable components opens entry points for attackers. Threats have evolved from data poisoning and weight tampering to agent manipulation and interface exploitation, yet existing reviews lack a unified framework spanning the full fine-tuning lifecycle. Objective: This paper presents a systematic survey of LLM fine-tuning security and establishes a lifecycle-based framework for comparing attacks and defenses, complemented by unifi","authors_text":"Rajkumar Buyya, Runze Chen, Wenjuan Li, Yitao Liu","cross_cats":["cs.AI","cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-24T13:34:47Z","title":"Security in the Fine-Tuning Lifecycle of Large Language Models: Threats, Defenses,Evaluation, and Future Directions"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.25073","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7a422d3b33281257751f31d100e7cdec1aa5ed6cd39b295492a2c86e16f3af27","target":"record","created_at":"2026-05-26T02:03:38Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"09f52bd2be9734c7acc9595b653758727fe6884d99b269d3766cf9930a2b1bc7","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-24T13:34:47Z","title_canon_sha256":"5c89794ae6e7368abbd9069ccd2864f3ec811186b7bf35853cc8c300a9fce260"},"schema_version":"1.0","source":{"id":"2605.25073","kind":"arxiv","version":1}},"canonical_sha256":"7802277e58ef97701174205260efe9aeefe6b818e38046517b3d8d6fc17e06e9","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"7802277e58ef97701174205260efe9aeefe6b818e38046517b3d8d6fc17e06e9","first_computed_at":"2026-05-26T02:03:38.601489Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-26T02:03:38.601489Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"UKZ1xiE6+0WaQX/geGiaVu+0D+M9s6ZEEPnYxinF71lbNhzV4KqPVKKFVdYsbc2g/ob2ppbaSGtKF/8/A7ECCA==","signature_status":"signed_v1","signed_at":"2026-05-26T02:03:38.602181Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.25073","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7a422d3b33281257751f31d100e7cdec1aa5ed6cd39b295492a2c86e16f3af27","sha256:b43a28a499fcc5936b898335a6e2ba00a6fed09744c38f873292d5e8acc1ce3a"],"state_sha256":"fc372a21b44cc039446d5dcde11c39b0fb2af050088dc60ed4531c603a811efd"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"EmhBJVZ68konkJhPrWrRb9gB1tqWwIhDM5/ZvuMbDW2nmY05rzc1M58F+8tbJS7pojBOHLoI9JydpMd/iL+qBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-09T10:20:54.457891Z","bundle_sha256":"143a987a02b5786d569a73147f9cffe0d76be1aebd005690329a0a217ae31cc9"}}