{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:PKH4YDKLOBSITJSOJ35XXUUMHN","short_pith_number":"pith:PKH4YDKL","canonical_record":{"source":{"id":"2606.01166","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-31T11:16:18Z","cross_cats_sorted":["cs.CL"],"title_canon_sha256":"225597914a29788e031e18be5f217dcac6ec3d6097c91da377c1752426b0f708","abstract_canon_sha256":"922fd746ce971e115be0444ac0bbdf4f3de21572d7edeac62a19597a34d65aa1"},"schema_version":"1.0"},"canonical_sha256":"7a8fcc0d4b706489a64e4efb7bd28c3b5b2798076d061494e31899399dcb8b43","source":{"kind":"arxiv","id":"2606.01166","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.01166","created_at":"2026-06-02T02:04:25Z"},{"alias_kind":"arxiv_version","alias_value":"2606.01166v1","created_at":"2026-06-02T02:04:25Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.01166","created_at":"2026-06-02T02:04:25Z"},{"alias_kind":"pith_short_12","alias_value":"PKH4YDKLOBSI","created_at":"2026-06-02T02:04:25Z"},{"alias_kind":"pith_short_16","alias_value":"PKH4YDKLOBSITJSO","created_at":"2026-06-02T02:04:25Z"},{"alias_kind":"pith_short_8","alias_value":"PKH4YDKL","created_at":"2026-06-02T02:04:25Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:PKH4YDKLOBSITJSOJ35XXUUMHN","target":"record","payload":{"canonical_record":{"source":{"id":"2606.01166","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-31T11:16:18Z","cross_cats_sorted":["cs.CL"],"title_canon_sha256":"225597914a29788e031e18be5f217dcac6ec3d6097c91da377c1752426b0f708","abstract_canon_sha256":"922fd746ce971e115be0444ac0bbdf4f3de21572d7edeac62a19597a34d65aa1"},"schema_version":"1.0"},"canonical_sha256":"7a8fcc0d4b706489a64e4efb7bd28c3b5b2798076d061494e31899399dcb8b43","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-02T02:04:25.586364Z","signature_b64":"SrtBhXZ6nLo3/OxKXGUjoJns8sm4VxeS6G0WFXBnsw8np+ZPRiy2OmQM1o0jG3vqZgE06NtvEfT1DlWeagq+AA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7a8fcc0d4b706489a64e4efb7bd28c3b5b2798076d061494e31899399dcb8b43","last_reissued_at":"2026-06-02T02:04:25.585974Z","signature_status":"signed_v1","first_computed_at":"2026-06-02T02:04:25.585974Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.01166","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T02:04:25Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"3VLEaaieVwN2ESuL/1vvw6XDfC5dkuGYgDKdEjPFiHu6zc3dTb9rSWKVaL7adX1FY7p19xpx/8zPmICtTAvyCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T19:30:47.626720Z"},"content_sha256":"3c1386eae815ef5cf7a49c869a5b392b16db749af620a1706bac43aad08a5695","schema_version":"1.0","event_id":"sha256:3c1386eae815ef5cf7a49c869a5b392b16db749af620a1706bac43aad08a5695"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:PKH4YDKLOBSITJSOJ35XXUUMHN","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"BraveGuard: From Open-World Threats to Safer Computer-Use Agents","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.CR","authors_text":"Baihui Zheng, Kerui Cao, Ming Wen, Wenke Huang, Xiaohu Du, Xingjun Ma, Xinhao Deng, Yanming Guo, Yifan Ding, Yige Li, Yingshui Tan, Yixu Wang, Yu-Gang Jiang, Yunhao Feng, Yutao Wu, Yuxiang Xie","submitted_at":"2026-05-31T11:16:18Z","abstract_excerpt":"Computer-use agents extend language models from text generation to sustained interaction with files, terminals, browsers, and external tools. This shift creates safety risks that are difficult to detect from isolated prompts or final responses, because harm often emerges only through multi-step execution traces whose individual actions appear locally benign. We introduce BraveGuard, a self-evolving defense framework for training guard models from open-world threat signals and realistic agent trajectories. BraveGuard mines recent research sources to identify emerging risks and attack patterns, "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.01166","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.01166/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T02:04:25Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"XugO9X+7IyRzF82HykgNxxK3PXwUjCiTfVRoZIRzyW8C9gD+UhvYdC6W1hdArPSd0y50jesVN0N5TaJHTRJnBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-03T19:30:47.627103Z"},"content_sha256":"9cee31adc756b37fc862909f267b20ad887915b1ccc3b9c8c0ee444c2fc16b2b","schema_version":"1.0","event_id":"sha256:9cee31adc756b37fc862909f267b20ad887915b1ccc3b9c8c0ee444c2fc16b2b"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/PKH4YDKLOBSITJSOJ35XXUUMHN/bundle.json","state_url":"https://pith.science/pith/PKH4YDKLOBSITJSOJ35XXUUMHN/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/PKH4YDKLOBSITJSOJ35XXUUMHN/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-03T19:30:47Z","links":{"resolver":"https://pith.science/pith/PKH4YDKLOBSITJSOJ35XXUUMHN","bundle":"https://pith.science/pith/PKH4YDKLOBSITJSOJ35XXUUMHN/bundle.json","state":"https://pith.science/pith/PKH4YDKLOBSITJSOJ35XXUUMHN/state.json","well_known_bundle":"https://pith.science/.well-known/pith/PKH4YDKLOBSITJSOJ35XXUUMHN/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:PKH4YDKLOBSITJSOJ35XXUUMHN","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"922fd746ce971e115be0444ac0bbdf4f3de21572d7edeac62a19597a34d65aa1","cross_cats_sorted":["cs.CL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-31T11:16:18Z","title_canon_sha256":"225597914a29788e031e18be5f217dcac6ec3d6097c91da377c1752426b0f708"},"schema_version":"1.0","source":{"id":"2606.01166","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.01166","created_at":"2026-06-02T02:04:25Z"},{"alias_kind":"arxiv_version","alias_value":"2606.01166v1","created_at":"2026-06-02T02:04:25Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.01166","created_at":"2026-06-02T02:04:25Z"},{"alias_kind":"pith_short_12","alias_value":"PKH4YDKLOBSI","created_at":"2026-06-02T02:04:25Z"},{"alias_kind":"pith_short_16","alias_value":"PKH4YDKLOBSITJSO","created_at":"2026-06-02T02:04:25Z"},{"alias_kind":"pith_short_8","alias_value":"PKH4YDKL","created_at":"2026-06-02T02:04:25Z"}],"graph_snapshots":[{"event_id":"sha256:9cee31adc756b37fc862909f267b20ad887915b1ccc3b9c8c0ee444c2fc16b2b","target":"graph","created_at":"2026-06-02T02:04:25Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.01166/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Computer-use agents extend language models from text generation to sustained interaction with files, terminals, browsers, and external tools. This shift creates safety risks that are difficult to detect from isolated prompts or final responses, because harm often emerges only through multi-step execution traces whose individual actions appear locally benign. We introduce BraveGuard, a self-evolving defense framework for training guard models from open-world threat signals and realistic agent trajectories. BraveGuard mines recent research sources to identify emerging risks and attack patterns, ","authors_text":"Baihui Zheng, Kerui Cao, Ming Wen, Wenke Huang, Xiaohu Du, Xingjun Ma, Xinhao Deng, Yanming Guo, Yifan Ding, Yige Li, Yingshui Tan, Yixu Wang, Yu-Gang Jiang, Yunhao Feng, Yutao Wu, Yuxiang Xie","cross_cats":["cs.CL"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-31T11:16:18Z","title":"BraveGuard: From Open-World Threats to Safer Computer-Use Agents"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.01166","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:3c1386eae815ef5cf7a49c869a5b392b16db749af620a1706bac43aad08a5695","target":"record","created_at":"2026-06-02T02:04:25Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"922fd746ce971e115be0444ac0bbdf4f3de21572d7edeac62a19597a34d65aa1","cross_cats_sorted":["cs.CL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-31T11:16:18Z","title_canon_sha256":"225597914a29788e031e18be5f217dcac6ec3d6097c91da377c1752426b0f708"},"schema_version":"1.0","source":{"id":"2606.01166","kind":"arxiv","version":1}},"canonical_sha256":"7a8fcc0d4b706489a64e4efb7bd28c3b5b2798076d061494e31899399dcb8b43","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"7a8fcc0d4b706489a64e4efb7bd28c3b5b2798076d061494e31899399dcb8b43","first_computed_at":"2026-06-02T02:04:25.585974Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-02T02:04:25.585974Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"SrtBhXZ6nLo3/OxKXGUjoJns8sm4VxeS6G0WFXBnsw8np+ZPRiy2OmQM1o0jG3vqZgE06NtvEfT1DlWeagq+AA==","signature_status":"signed_v1","signed_at":"2026-06-02T02:04:25.586364Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.01166","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:3c1386eae815ef5cf7a49c869a5b392b16db749af620a1706bac43aad08a5695","sha256:9cee31adc756b37fc862909f267b20ad887915b1ccc3b9c8c0ee444c2fc16b2b"],"state_sha256":"9290caf6404a4864fc0d7271db63db44e12d72b6cb7395a3bb15384311ad87ce"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"qhumNI5c1XcyOgn91un/i5SKjzoW7f18XlzvULd83EPNhU/sNcJewR5jF3lq6wiykBCSdgVG0BHwBMT30mokAA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-03T19:30:47.629422Z","bundle_sha256":"5281130b05f9058a988a522dcbc13494d1fb789460f6ce7cc53a9831c7b568df"}}