{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:PC7ICUDZ6ZP5COFLFA2JZOTIXR","short_pith_number":"pith:PC7ICUDZ","schema_version":"1.0","canonical_sha256":"78be815079f65fd138ab28349cba68bc4dffdbae615d40b2011bc3b1c61c5528","source":{"kind":"arxiv","id":"2605.30883","version":1},"attestation_state":"computed","paper":{"title":"TRACE: Task-Aware Adaptive Self-Evolving Agentic Jailbreaking","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chaochao Lu, Churui Zeng, KeDong Xiu, Kui Ren, Liang He, Tianhang Zheng, Weiwei Qi, Zhan Qin","submitted_at":"2026-05-29T06:13:58Z","abstract_excerpt":"The rise of LLM agents introduces a new threat by enabling planning, coding, and even end-to-end execution of expert-level attack workflows. However, this threat remains underexplored and underestimated since (i) safety alignment prevents LLMs from directly generating harmful instructions, and (ii) most existing jailbreak methods cannot consistently induce agents to execute malicious operations. In this paper, we propose TRACE, a practical agentic jailbreaking framework to further reveal the risks of this threat surface. To conceal the malicious intent, TRACE decomposes a malicious task into m"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2605.30883","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-29T06:13:58Z","cross_cats_sorted":[],"title_canon_sha256":"7e567fcbe86fa1c465522e9be78cded83a62b3f6b26eed41c993be5b5e1dbed5","abstract_canon_sha256":"552369c603a8eed362d4c575b4ec2722fa83f0942a52d3bf7af279b5fc39fd8b"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-01T01:03:23.120846Z","signature_b64":"Nziqy2piBqdGj2tyiE+aw53qb3+3lEgE1wjQofNDy45hw3MjceSW7qekYofo6UtsnNprJuaI9HzcC6geq3CIAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"78be815079f65fd138ab28349cba68bc4dffdbae615d40b2011bc3b1c61c5528","last_reissued_at":"2026-06-01T01:03:23.119993Z","signature_status":"signed_v1","first_computed_at":"2026-06-01T01:03:23.119993Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"TRACE: Task-Aware Adaptive Self-Evolving Agentic Jailbreaking","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chaochao Lu, Churui Zeng, KeDong Xiu, Kui Ren, Liang He, Tianhang Zheng, Weiwei Qi, Zhan Qin","submitted_at":"2026-05-29T06:13:58Z","abstract_excerpt":"The rise of LLM agents introduces a new threat by enabling planning, coding, and even end-to-end execution of expert-level attack workflows. However, this threat remains underexplored and underestimated since (i) safety alignment prevents LLMs from directly generating harmful instructions, and (ii) most existing jailbreak methods cannot consistently induce agents to execute malicious operations. In this paper, we propose TRACE, a practical agentic jailbreaking framework to further reveal the risks of this threat surface. To conceal the malicious intent, TRACE decomposes a malicious task into m"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.30883","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.30883/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2605.30883","created_at":"2026-06-01T01:03:23.120115+00:00"},{"alias_kind":"arxiv_version","alias_value":"2605.30883v1","created_at":"2026-06-01T01:03:23.120115+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.30883","created_at":"2026-06-01T01:03:23.120115+00:00"},{"alias_kind":"pith_short_12","alias_value":"PC7ICUDZ6ZP5","created_at":"2026-06-01T01:03:23.120115+00:00"},{"alias_kind":"pith_short_16","alias_value":"PC7ICUDZ6ZP5COFL","created_at":"2026-06-01T01:03:23.120115+00:00"},{"alias_kind":"pith_short_8","alias_value":"PC7ICUDZ","created_at":"2026-06-01T01:03:23.120115+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/PC7ICUDZ6ZP5COFLFA2JZOTIXR","json":"https://pith.science/pith/PC7ICUDZ6ZP5COFLFA2JZOTIXR.json","graph_json":"https://pith.science/api/pith-number/PC7ICUDZ6ZP5COFLFA2JZOTIXR/graph.json","events_json":"https://pith.science/api/pith-number/PC7ICUDZ6ZP5COFLFA2JZOTIXR/events.json","paper":"https://pith.science/paper/PC7ICUDZ"},"agent_actions":{"view_html":"https://pith.science/pith/PC7ICUDZ6ZP5COFLFA2JZOTIXR","download_json":"https://pith.science/pith/PC7ICUDZ6ZP5COFLFA2JZOTIXR.json","view_paper":"https://pith.science/paper/PC7ICUDZ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2605.30883&json=true","fetch_graph":"https://pith.science/api/pith-number/PC7ICUDZ6ZP5COFLFA2JZOTIXR/graph.json","fetch_events":"https://pith.science/api/pith-number/PC7ICUDZ6ZP5COFLFA2JZOTIXR/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/PC7ICUDZ6ZP5COFLFA2JZOTIXR/action/timestamp_anchor","attest_storage":"https://pith.science/pith/PC7ICUDZ6ZP5COFLFA2JZOTIXR/action/storage_attestation","attest_author":"https://pith.science/pith/PC7ICUDZ6ZP5COFLFA2JZOTIXR/action/author_attestation","sign_citation":"https://pith.science/pith/PC7ICUDZ6ZP5COFLFA2JZOTIXR/action/citation_signature","submit_replication":"https://pith.science/pith/PC7ICUDZ6ZP5COFLFA2JZOTIXR/action/replication_record"}},"created_at":"2026-06-01T01:03:23.120115+00:00","updated_at":"2026-06-01T01:03:23.120115+00:00"}