{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:PNACBSKQK6PWNDISW4IVMIXHLN","merge_version":"pith-open-graph-merge-v1","event_count":23,"valid_event_count":23,"invalid_event_count":0,"equivocation_count":1,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ae2d03cff26dee307219f3994bfd95811261ab16f0cc6e74de21e003c6d3fa73","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-04-26T08:03:32Z","title_canon_sha256":"04c22a538b6099863d5142de6a9fdb1fd874196d0c3d6b9c84c4b7faf635a0d8"},"schema_version":"1.0","source":{"id":"2604.23593","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2604.23593","created_at":"2026-06-02T01:04:16Z"},{"alias_kind":"arxiv_version","alias_value":"2604.23593v1","created_at":"2026-06-02T01:04:16Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2604.23593","created_at":"2026-06-02T01:04:16Z"},{"alias_kind":"pith_short_12","alias_value":"PNACBSKQK6PW","created_at":"2026-06-02T01:04:16Z"},{"alias_kind":"pith_short_16","alias_value":"PNACBSKQK6PWNDIS","created_at":"2026-06-02T01:04:16Z"},{"alias_kind":"pith_short_8","alias_value":"PNACBSKQ","created_at":"2026-06-02T01:04:16Z"}],"graph_snapshots":[{"event_id":"sha256:d3451de75627418e6abfd1ff9dd40fafe4bd278722445498c13c8e02d32e912a","target":"graph","created_at":"2026-06-02T01:04:16Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"Together, this taxonomy and experimental audit provide an evidence-based baseline for assessing and tracking the reliability of AI peer review and highlight concrete failure points to guide targeted, testable mitigations."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That the causal effects observed in the four treatment-control probes on a stratified set of ICLR 2025 submissions using two specific advanced LLMs generalize to other models, conferences, and review contexts."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"AI peer review systems are vulnerable to prompt injections, prestige biases, assertion strength effects, and contextual poisoning, as demonstrated by a new attack taxonomy and causal experiments on real conference submissions."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"AI peer review is vulnerable to manipulation by hidden prompts, prestige framing, and rebuttal sycophancy."}],"snapshot_sha256":"97b1b857893a9bf68ab09f0818066dab954c2f225345a7a12f8cdb6d0e02071f"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":false,"detectors_run":[{"findings_count":0,"name":"ai_meta_artifact","ran_at":"2026-05-21T08:38:10.695203Z","status":"completed","version":"1.0.0"},{"findings_count":21,"name":"doi_compliance","ran_at":"2026-05-19T22:57:54.994142Z","status":"completed","version":"1.0.0"}],"endpoint":"/pith/2604.23593/integrity.json","findings":[{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.48550/arxiv:2501.04306","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.48550/arxiv:2501.04306' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":6,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.1007/978-3031-92611-2_5","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.1007/978-3031-92611-2_5' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":22,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.1016/j.artint.2024","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.1016/j.artint.2024' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":27,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.48550/arxiv.2306","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.48550/arxiv.2306' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":28,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.5555/3241094","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.5555/3241094' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":71,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.48550/arxiv.2402","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.48550/arxiv.2402' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":29,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.1109/sp","detector":"doi_compliance","finding_type":"broken_identifier","note":"DOI '10.1109/sp' as printed in the bibliography is syntactically invalid and cannot resolve.","ref_index":70,"severity":"critical","verdict_class":"incontrovertible"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.5555/3042573.3042761","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.5555/3042573.3042761' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":74,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.48550/arxiv.1708","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.48550/arxiv.1708' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":76,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.5555/3327345.3327509","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.5555/3327345.3327509' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":78,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.5555/3495724","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.5555/3495724' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":84,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.3346/jkms.2025.40.e92https://www.ncbi.nlm.nih.gov/pubmed/39995259","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.3346/jkms.2025.40.e92https://www.ncbi.nlm.nih.gov/pubmed/39995259' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":90,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.48550/arxiv.2510","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.48550/arxiv.2510' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":101,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.48550/arxiv.2508","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.48550/arxiv.2508' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":105,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.5555/3766078.3766274","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.5555/3766078.3766274' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":109,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.18653/v1/2025.findingsacl.1059","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.18653/v1/2025.findingsacl.1059' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":126,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.48550/arxiv.2506","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.48550/arxiv.2506' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":120,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.5555/3618408.3619699","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.5555/3618408.3619699' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":125,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.1038/s41562025-02194-6","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.1038/s41562025-02194-6' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":134,"severity":"critical","verdict_class":"cross_source"},{"audited_at":"2026-05-19T22:57:54.994142Z","detected_arxiv_id":null,"detected_doi":"10.5555/3692070.3693262","detector":"doi_compliance","finding_type":"unresolvable_identifier","note":"Identifier '10.5555/3692070.3693262' is syntactically valid but the DOI registry (doi.org) returned 404, and Crossref / OpenAlex / internal corpus also have no record. The cited work could not be located through any authoritative source.","ref_index":7,"severity":"critical","verdict_class":"cross_source"}],"snapshot_sha256":"def9dbb91058a55532eeff553bc99b54a6894c6d459d29bb459f8ac22c84a503","summary":{"advisory":0,"by_detector":{"doi_compliance":{"advisory":0,"critical":21,"informational":0,"total":21}},"critical":21,"informational":0}},"paper":{"abstract_excerpt":"The volume of scientific submissions continues to climb, outpacing the capacity of qualified human referees and stretching editorial timelines. At the same time, modern large language models (LLMs) offer impressive capabilities in summarization, fact checking, and literature triage, making the integration of AI into peer review increasingly attractive -- and, in practice, unavoidable. Yet early deployments and informal adoption have exposed acute failure modes. Recent incidents have revealed that hidden prompt injections embedded in manuscripts can steer LLM-generated reviews toward unjustifia","authors_text":"Hang Xu, Jialiang Wang, Kaichun Hu, Kui Ren, Lei Chen, Linan Yue, Min-Ling Zhang, Shimin Di, Wangze Ni, Yuchen Liu","cross_cats":[],"headline":"AI peer review is vulnerable to manipulation by hidden prompts, prestige framing, and rebuttal sycophancy.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-04-26T08:03:32Z","title":"When AI reviews science: Can we trust the referee?"},"references":{"count":138,"internal_anchors":15,"resolved_work":138,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"Sample I. (2025). Quality of scientific papers ques- tioned as academics “overwhelmed” by the millions published. The Guardian. https://www.theguardian. com/science/2025/jul/13/quality-of-scientific-p","work_id":"e94e4ee4-0279-48a7-9010-cc537f9fda0e","year":2025},{"cited_arxiv_id":"","doi":"10.1038/d41586-","is_internal_anchor":false,"ref_index":2,"title":"Nature 567(7748), 305 (Mar 2019)","work_id":"ac93adcb-b6c9-4576-b59f-9121a5f0b643","year":2025},{"cited_arxiv_id":"","doi":"10.1038/d41586-025-01839-w","is_internal_anchor":false,"ref_index":3,"title":"and Bak-Coleman J","work_id":"837f16ee-c2d9-4c0a-86ba-931ab3edc570","year":2025},{"cited_arxiv_id":"","doi":"10.1016/j.cmpbup.2024.100145","is_internal_anchor":false,"ref_index":4,"title":"and Albadawy M","work_id":"84f8cae7-d97e-4e70-8f46-8221691da3d5","year":2024},{"cited_arxiv_id":"","doi":"10.48550/arxiv.2507.01903","is_internal_anchor":false,"ref_index":5,"title":"Ai4research: A survey of artificial intelligence for scientific research","work_id":"8434d9d4-cce5-4158-b4f0-acc351e5bb4c","year":2025}],"snapshot_sha256":"859c18cb8f765456f405dbc3abaad3b3c12313d77c6d0a9d9989318badc1d208"},"source":{"id":"2604.23593","kind":"arxiv","version":1},"verdict":{"created_at":"2026-05-08T06:15:04.151841Z","id":"bbf3c992-40f5-4fc2-b07d-6c9dc40d151a","model_set":{"reader":"grok-4.3"},"one_line_summary":"AI peer review systems are vulnerable to prompt injections, prestige biases, assertion strength effects, and contextual poisoning, as demonstrated by a new attack taxonomy and causal experiments on real conference submissions.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"AI peer review is vulnerable to manipulation by hidden prompts, prestige framing, and rebuttal sycophancy.","strongest_claim":"Together, this taxonomy and experimental audit provide an evidence-based baseline for assessing and tracking the reliability of AI peer review and highlight concrete failure points to guide targeted, testable mitigations.","weakest_assumption":"That the causal effects observed in the four treatment-control probes on a stratified set of ICLR 2025 submissions using two specific advanced LLMs generalize to other models, conferences, and review contexts."}},"verdict_id":"bbf3c992-40f5-4fc2-b07d-6c9dc40d151a"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5dae2cacee019b7ea95d0b277a19061f9c8d0380ebd511b7823b8cdab01c72d6","target":"record","created_at":"2026-06-02T01:04:16Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ae2d03cff26dee307219f3994bfd95811261ab16f0cc6e74de21e003c6d3fa73","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-04-26T08:03:32Z","title_canon_sha256":"04c22a538b6099863d5142de6a9fdb1fd874196d0c3d6b9c84c4b7faf635a0d8"},"schema_version":"1.0","source":{"id":"2604.23593","kind":"arxiv","version":1}},"canonical_sha256":"7b4020c950579f668d12b7115622e75b58cf4c156f32c8336c71d5a67346771e","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"7b4020c950579f668d12b7115622e75b58cf4c156f32c8336c71d5a67346771e","first_computed_at":"2026-06-02T01:04:16.429379Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-02T01:04:16.429379Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"YJonJBlM+/OOUwCnLVGWUYqk9jNT8FqgGo/aYNfddyNk+TLwkVQQtmrJ5osTxzvE3PjJoQvQYE418ZJjMCpJBg==","signature_status":"signed_v1","signed_at":"2026-06-02T01:04:16.429925Z","signed_message":"canonical_sha256_bytes"},"source_id":"2604.23593","source_kind":"arxiv","source_version":1}}},"equivocations":[{"signer_id":"pith.science","event_type":"integrity_finding","target":"integrity","event_ids":["sha256:0be978fdbbaee4fa6beb9c2e51aeffb8928a1272b25fcbcbb3b0499da42d2194","sha256:165dfb517fe32a35d04bfa83ee4ac9ff0bf41263c5d59889ddf730875d67c526","sha256:197a9b0e928fe8aff46197a1d68ab00d2b4e639e109dd4dd06afa4a082e2af28","sha256:2156a15013a6eb9faa5ef7f773ccc1f0f082ecc54f626c0a07938f93ab04bdd4","sha256:2d61e04986d6f0501aaefefdfcfa307ff4db264afcd351e857c0325ad4259a26","sha256:33561d584c4870400a7a070038fb11c60efac704d101a1bf10544c0535852578","sha256:52a8b688abb1284ef8a2157b0c749cdeefe85fe54896ed17daca6fa7515be236","sha256:5536405913c036188f82111b13a28de7728c723e305d9d19738c7464125f6d3f","sha256:58fba2e0448f877a3f85501b3ceb9e294c1d201620a5779fba3eec364bf095d7","sha256:60c5284820d9c88f6c15e3f0f9a4a86f303c8917f20069e65ca81e06eb71af21","sha256:62dfdfec049c671c72eb61c2b2dfb592f75184d3d5ae7ef2fcb65cf6b77d2050","sha256:8aae96e649bfa98bbe39730a76bf5910b0fde3e995ff5cd68727d908f5b25b53","sha256:952b389825b1180a566ac4d8cb30cb92da6e7cc1badb9c2ed31a31f4bdcbd970","sha256:a5ac3805184eb7aabdb316db99a62d947eddee0ebe5d9298db8897a9894c98b6","sha256:b58900a8aa525345c140b45e818f138329f036e5855c59bf7378a410be2f78c9","sha256:b9f8f3b0758bd195c9d685d2acd5828c2ca3fa4445cf62c33301760fc67ada1c","sha256:c78d9529b8853a957054551abc1db062dc6ba9d23611b1c6dfa479fef3ca074d","sha256:dbd820d872b6a2ad27a7b2def6d32d770c1f163df163a7b78d2e91c8b212a55c","sha256:f46b6576e9b28905b0aa631591da2d6028f5e381b92f7fe467cf1ab69658aa30","sha256:f75fb074ff0d1cf4fe5669ae54535982eaf62ac6b84dc3a8e6e050f682ebd848","sha256:fdc4d1ce755d32907719583b27fdcdc1d20be59e486eecab2fc7bda5589b53df"]}],"invalid_events":[],"applied_event_ids":["sha256:5dae2cacee019b7ea95d0b277a19061f9c8d0380ebd511b7823b8cdab01c72d6","sha256:d3451de75627418e6abfd1ff9dd40fafe4bd278722445498c13c8e02d32e912a"],"state_sha256":"8e2c2cc0b25ce4b45ce1fb849eb9655002252675c2fda97a1ab0317129454535"}