{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:PHBBMTKUWJG4LZDZ4RDQLF372L","short_pith_number":"pith:PHBBMTKU","canonical_record":{"source":{"id":"2605.31593","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-29T17:57:00Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"490c894236b47552d3161ccf669fcd76024e46333811432ebf685cb786d79b9d","abstract_canon_sha256":"8083e1b1a0d40cc05cf3921e9775b42d21157730839f1757552dd974d5b01e12"},"schema_version":"1.0"},"canonical_sha256":"79c2164d54b24dc5e479e44705977fd2cd05eda1daf1e34a9e17366551d00acf","source":{"kind":"arxiv","id":"2605.31593","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.31593","created_at":"2026-06-01T02:04:14Z"},{"alias_kind":"arxiv_version","alias_value":"2605.31593v1","created_at":"2026-06-01T02:04:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.31593","created_at":"2026-06-01T02:04:14Z"},{"alias_kind":"pith_short_12","alias_value":"PHBBMTKUWJG4","created_at":"2026-06-01T02:04:14Z"},{"alias_kind":"pith_short_16","alias_value":"PHBBMTKUWJG4LZDZ","created_at":"2026-06-01T02:04:14Z"},{"alias_kind":"pith_short_8","alias_value":"PHBBMTKU","created_at":"2026-06-01T02:04:14Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:PHBBMTKUWJG4LZDZ4RDQLF372L","target":"record","payload":{"canonical_record":{"source":{"id":"2605.31593","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-29T17:57:00Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"490c894236b47552d3161ccf669fcd76024e46333811432ebf685cb786d79b9d","abstract_canon_sha256":"8083e1b1a0d40cc05cf3921e9775b42d21157730839f1757552dd974d5b01e12"},"schema_version":"1.0"},"canonical_sha256":"79c2164d54b24dc5e479e44705977fd2cd05eda1daf1e34a9e17366551d00acf","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-01T02:04:14.874348Z","signature_b64":"MeT4cD2N1+4erzGbmvYqIGu8E+eULYqX0S1H+LRuc4kZAzacn4yKJbVZSLH7lcJQuhhQ4PvSoY96XfAB0nfhCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"79c2164d54b24dc5e479e44705977fd2cd05eda1daf1e34a9e17366551d00acf","last_reissued_at":"2026-06-01T02:04:14.873864Z","signature_status":"signed_v1","first_computed_at":"2026-06-01T02:04:14.873864Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.31593","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-01T02:04:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Sqxx66RkuDfwi7iGmQxrIY22DSJpsho0hhW9pslsX5taInboatcZe+kLADZ1Xa//e8j4OxKjr99DUtBfoIOsDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T03:13:07.900034Z"},"content_sha256":"fc73ccf310cd08bde8966fb24e863efef97dd59d5d77ca19384fd5a2eeaa072c","schema_version":"1.0","event_id":"sha256:fc73ccf310cd08bde8966fb24e863efef97dd59d5d77ca19384fd5a2eeaa072c"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:PHBBMTKUWJG4LZDZ4RDQLF372L","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Stateful Online Monitoring Catches Distributed Agent Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Alexander Robey, Arav Santhanam, Davis Brown, Eric Wong, Hamed Hassani, Ivan Zhang, Kasper Hong, Matan Shtepel, Samarth Bhargav, Steffi Chern","submitted_at":"2026-05-29T17:57:00Z","abstract_excerpt":"Language models can find thousands of severe software vulnerabilities, and agents are increasingly being misused for cyberattacks. To avoid detection, attackers frequently distribute their misuse, splitting a harmful task across many user accounts so each individual transcript looks benign. Because safety monitors score only one agent context at a time, they are structurally blind to misuse that is only visible in aggregate, across many accounts. We show this gap is real by building, to our knowledge, the first distributed agent attack, a multi-agent scaffold that completes hard cybersecurity "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.31593","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.31593/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-01T02:04:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8wUCZpkormrKa0cCQqZlH8tyYy8DfmZpkZGSoxXUOYX8BMh6+dPQxyELPLJVTmsE30RNWwBAvFwkwsFAgIz5Bw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T03:13:07.900434Z"},"content_sha256":"251d75d66e234b2fc2bd178dbe51e0ca1db26c17f0a6da62756a38d0919370d8","schema_version":"1.0","event_id":"sha256:251d75d66e234b2fc2bd178dbe51e0ca1db26c17f0a6da62756a38d0919370d8"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/PHBBMTKUWJG4LZDZ4RDQLF372L/bundle.json","state_url":"https://pith.science/pith/PHBBMTKUWJG4LZDZ4RDQLF372L/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/PHBBMTKUWJG4LZDZ4RDQLF372L/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-02T03:13:07Z","links":{"resolver":"https://pith.science/pith/PHBBMTKUWJG4LZDZ4RDQLF372L","bundle":"https://pith.science/pith/PHBBMTKUWJG4LZDZ4RDQLF372L/bundle.json","state":"https://pith.science/pith/PHBBMTKUWJG4LZDZ4RDQLF372L/state.json","well_known_bundle":"https://pith.science/.well-known/pith/PHBBMTKUWJG4LZDZ4RDQLF372L/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:PHBBMTKUWJG4LZDZ4RDQLF372L","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"8083e1b1a0d40cc05cf3921e9775b42d21157730839f1757552dd974d5b01e12","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-29T17:57:00Z","title_canon_sha256":"490c894236b47552d3161ccf669fcd76024e46333811432ebf685cb786d79b9d"},"schema_version":"1.0","source":{"id":"2605.31593","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.31593","created_at":"2026-06-01T02:04:14Z"},{"alias_kind":"arxiv_version","alias_value":"2605.31593v1","created_at":"2026-06-01T02:04:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.31593","created_at":"2026-06-01T02:04:14Z"},{"alias_kind":"pith_short_12","alias_value":"PHBBMTKUWJG4","created_at":"2026-06-01T02:04:14Z"},{"alias_kind":"pith_short_16","alias_value":"PHBBMTKUWJG4LZDZ","created_at":"2026-06-01T02:04:14Z"},{"alias_kind":"pith_short_8","alias_value":"PHBBMTKU","created_at":"2026-06-01T02:04:14Z"}],"graph_snapshots":[{"event_id":"sha256:251d75d66e234b2fc2bd178dbe51e0ca1db26c17f0a6da62756a38d0919370d8","target":"graph","created_at":"2026-06-01T02:04:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.31593/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Language models can find thousands of severe software vulnerabilities, and agents are increasingly being misused for cyberattacks. To avoid detection, attackers frequently distribute their misuse, splitting a harmful task across many user accounts so each individual transcript looks benign. Because safety monitors score only one agent context at a time, they are structurally blind to misuse that is only visible in aggregate, across many accounts. We show this gap is real by building, to our knowledge, the first distributed agent attack, a multi-agent scaffold that completes hard cybersecurity ","authors_text":"Alexander Robey, Arav Santhanam, Davis Brown, Eric Wong, Hamed Hassani, Ivan Zhang, Kasper Hong, Matan Shtepel, Samarth Bhargav, Steffi Chern","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-29T17:57:00Z","title":"Stateful Online Monitoring Catches Distributed Agent Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.31593","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:fc73ccf310cd08bde8966fb24e863efef97dd59d5d77ca19384fd5a2eeaa072c","target":"record","created_at":"2026-06-01T02:04:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"8083e1b1a0d40cc05cf3921e9775b42d21157730839f1757552dd974d5b01e12","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-29T17:57:00Z","title_canon_sha256":"490c894236b47552d3161ccf669fcd76024e46333811432ebf685cb786d79b9d"},"schema_version":"1.0","source":{"id":"2605.31593","kind":"arxiv","version":1}},"canonical_sha256":"79c2164d54b24dc5e479e44705977fd2cd05eda1daf1e34a9e17366551d00acf","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"79c2164d54b24dc5e479e44705977fd2cd05eda1daf1e34a9e17366551d00acf","first_computed_at":"2026-06-01T02:04:14.873864Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-01T02:04:14.873864Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"MeT4cD2N1+4erzGbmvYqIGu8E+eULYqX0S1H+LRuc4kZAzacn4yKJbVZSLH7lcJQuhhQ4PvSoY96XfAB0nfhCQ==","signature_status":"signed_v1","signed_at":"2026-06-01T02:04:14.874348Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.31593","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:fc73ccf310cd08bde8966fb24e863efef97dd59d5d77ca19384fd5a2eeaa072c","sha256:251d75d66e234b2fc2bd178dbe51e0ca1db26c17f0a6da62756a38d0919370d8"],"state_sha256":"cd6bda4edde0c3d6bb93596e696224f86242cebf97363f58b6583480e74e3729"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"LrYCyk9MOFm1hAme26xw3ypM9pM1+zaBl0DMvNl3u082xoIdesCQw4vHjrhQQ/MyfZ3Lcl5PGdaRn9B8x6jkAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-02T03:13:07.902486Z","bundle_sha256":"ed1598747ddfe8bc4bdb583570440070f68e17b121ea7533fb6586e87a2e1f34"}}