{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:PQ5MYA73WJQYR2RC6TBD4TOADQ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"c4d9d1fae6a8fccd442a5f730defa01393e104c645e2e757cc1888a5dc61a250","cross_cats_sorted":["cs.CL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-09T13:39:17Z","title_canon_sha256":"bdc3f87b4120a213164c92b2a4e50d3317c3e1dfc169a2c045fd980f61ffe3a3"},"schema_version":"1.0","source":{"id":"2606.10860","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.10860","created_at":"2026-06-10T01:10:44Z"},{"alias_kind":"arxiv_version","alias_value":"2606.10860v1","created_at":"2026-06-10T01:10:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.10860","created_at":"2026-06-10T01:10:44Z"},{"alias_kind":"pith_short_12","alias_value":"PQ5MYA73WJQY","created_at":"2026-06-10T01:10:44Z"},{"alias_kind":"pith_short_16","alias_value":"PQ5MYA73WJQYR2RC","created_at":"2026-06-10T01:10:44Z"},{"alias_kind":"pith_short_8","alias_value":"PQ5MYA73","created_at":"2026-06-10T01:10:44Z"}],"graph_snapshots":[{"event_id":"sha256:4be3bc6c185e75a90b73c0b1f1dfd3bfa09037cc8116c3ef842c839e61cca528","target":"graph","created_at":"2026-06-10T01:10:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.10860/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Production LLMs receive instructions from sources with very different levels of trust, yet attend to every token with uniform architectural privilege. This is the structural vulnerability that enables malicious prompt injections and, more broadly, leaves models without a principled way to resolve conflicts between legitimate but competing instructions. A common training-based response is to teach models an explicit instruction hierarchy; existing approaches, however, formalize hierarchies of only three or four levels, treat all violations as equally severe, and rarely evaluate the full set of ","authors_text":"Lena A. J\\\"ager, Lena S. Bolliger","cross_cats":["cs.CL"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-09T13:39:17Z","title":"Training LLMs to Enforce Multi-Level Instruction Hierarchies via Gravity-Weighted Direct Preference Optimization"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.10860","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:248175433a4ba7a099386cf0ba37cfff43d74444d451612df06c0cc5a14854dc","target":"record","created_at":"2026-06-10T01:10:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"c4d9d1fae6a8fccd442a5f730defa01393e104c645e2e757cc1888a5dc61a250","cross_cats_sorted":["cs.CL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-09T13:39:17Z","title_canon_sha256":"bdc3f87b4120a213164c92b2a4e50d3317c3e1dfc169a2c045fd980f61ffe3a3"},"schema_version":"1.0","source":{"id":"2606.10860","kind":"arxiv","version":1}},"canonical_sha256":"7c3acc03fbb26188ea22f4c23e4dc01c268b9119a79c1f6303d85d7a2c18f130","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"7c3acc03fbb26188ea22f4c23e4dc01c268b9119a79c1f6303d85d7a2c18f130","first_computed_at":"2026-06-10T01:10:44.332695Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-10T01:10:44.332695Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"S1kNOnhoxaxBamR0fHn/bSt35SeE1xSgiqy1XxeNbZcH/dXuiHcLZMiwf22GxHgM77dZXtxXK3iPw2eAVNEwBw==","signature_status":"signed_v1","signed_at":"2026-06-10T01:10:44.333603Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.10860","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:248175433a4ba7a099386cf0ba37cfff43d74444d451612df06c0cc5a14854dc","sha256:4be3bc6c185e75a90b73c0b1f1dfd3bfa09037cc8116c3ef842c839e61cca528"],"state_sha256":"be7b3c8bcd83a36fc5b1755f964f98af7e51d1e936e965f0a8b2b940bf3d0416"}