{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:PXWGPF5Z7OYW62O5FNDUZTDLKM","short_pith_number":"pith:PXWGPF5Z","canonical_record":{"source":{"id":"2605.18891","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-17T05:22:27Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"f59ccb1207108d425d887e3f30ce18b6afbfebc33990c052a0bfa11782560012","abstract_canon_sha256":"e946854035a9506b8a255c7386908b8ecb5c53012faf030bbd027cdeff387d85"},"schema_version":"1.0"},"canonical_sha256":"7dec6797b9fbb16f69dd2b474ccc6b5333b1692b33762b2833cd3f8c3a06f7f2","source":{"kind":"arxiv","id":"2605.18891","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.18891","created_at":"2026-05-20T00:06:30Z"},{"alias_kind":"arxiv_version","alias_value":"2605.18891v1","created_at":"2026-05-20T00:06:30Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.18891","created_at":"2026-05-20T00:06:30Z"},{"alias_kind":"pith_short_12","alias_value":"PXWGPF5Z7OYW","created_at":"2026-05-20T00:06:30Z"},{"alias_kind":"pith_short_16","alias_value":"PXWGPF5Z7OYW62O5","created_at":"2026-05-20T00:06:30Z"},{"alias_kind":"pith_short_8","alias_value":"PXWGPF5Z","created_at":"2026-05-20T00:06:30Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:PXWGPF5Z7OYW62O5FNDUZTDLKM","target":"record","payload":{"canonical_record":{"source":{"id":"2605.18891","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-17T05:22:27Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"f59ccb1207108d425d887e3f30ce18b6afbfebc33990c052a0bfa11782560012","abstract_canon_sha256":"e946854035a9506b8a255c7386908b8ecb5c53012faf030bbd027cdeff387d85"},"schema_version":"1.0"},"canonical_sha256":"7dec6797b9fbb16f69dd2b474ccc6b5333b1692b33762b2833cd3f8c3a06f7f2","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-20T00:06:30.770655Z","signature_b64":"+QILBnzeDJ0XbQKJynfZrqv8826dh7I1e92nfVLG7oFziHiZIY2tFThcHM3sXRGGLJ+F0ui/AjS0++BV2AX+Ag==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"7dec6797b9fbb16f69dd2b474ccc6b5333b1692b33762b2833cd3f8c3a06f7f2","last_reissued_at":"2026-05-20T00:06:30.769804Z","signature_status":"signed_v1","first_computed_at":"2026-05-20T00:06:30.769804Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.18891","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:06:30Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"FAg2HIe1JFNqp3lGwZO6QmzS2F4EdYfbU6ftVtrHm7Qfbthz3dyD/iqlOie6V7x6NDLoemkIcJ+By8IRhxz+Dw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-22T21:48:41.739275Z"},"content_sha256":"692447af90a4028d6d2f4bbe6812d677ae66153803bd1856ffe21534530af015","schema_version":"1.0","event_id":"sha256:692447af90a4028d6d2f4bbe6812d677ae66153803bd1856ffe21534530af015"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:PXWGPF5Z7OYW62O5FNDUZTDLKM","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Auditing Reasoning-Trace Memorization Claims after Unlearning with Head-Conditioned Canaries","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.LG","authors_text":"Yanhang Li, Zexin Zhuang, Zhichao Fan","submitted_at":"2026-05-17T05:22:27Z","abstract_excerpt":"Evaluations of unlearning on reasoning models sometimes show a bypass pattern. The answer side looks unlearned, but the model's own thinking trace keeps emitting the forgotten content, and the gap is taken as evidence that the weights still remember. We audit this reading on DeepSeek-R1-Distill-Qwen-7B with LoRA-memorized fictional authors and NPO unlearning, conditioned on a six-token canary head. On one seed, swapping the thinking trace for a short non-canary prefill on the same weights drops the answer rate by as much as the bypass gap itself, whether the prefill mimics the training templat"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.18891","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.18891/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:06:30Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"chdZ3J+oOBZXLaWhGGsCN/faX9Je1aLcBt3TlYBsakN7ddw9xeEDXZqnjaPTb20BolDezNejyQf59WPl9PhxBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-22T21:48:41.739991Z"},"content_sha256":"e82ce9cdfa3e2e97f158871bace58299a04f8c5e4e21b9cab519af3d2d52544d","schema_version":"1.0","event_id":"sha256:e82ce9cdfa3e2e97f158871bace58299a04f8c5e4e21b9cab519af3d2d52544d"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/PXWGPF5Z7OYW62O5FNDUZTDLKM/bundle.json","state_url":"https://pith.science/pith/PXWGPF5Z7OYW62O5FNDUZTDLKM/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/PXWGPF5Z7OYW62O5FNDUZTDLKM/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-22T21:48:41Z","links":{"resolver":"https://pith.science/pith/PXWGPF5Z7OYW62O5FNDUZTDLKM","bundle":"https://pith.science/pith/PXWGPF5Z7OYW62O5FNDUZTDLKM/bundle.json","state":"https://pith.science/pith/PXWGPF5Z7OYW62O5FNDUZTDLKM/state.json","well_known_bundle":"https://pith.science/.well-known/pith/PXWGPF5Z7OYW62O5FNDUZTDLKM/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:PXWGPF5Z7OYW62O5FNDUZTDLKM","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e946854035a9506b8a255c7386908b8ecb5c53012faf030bbd027cdeff387d85","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-17T05:22:27Z","title_canon_sha256":"f59ccb1207108d425d887e3f30ce18b6afbfebc33990c052a0bfa11782560012"},"schema_version":"1.0","source":{"id":"2605.18891","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.18891","created_at":"2026-05-20T00:06:30Z"},{"alias_kind":"arxiv_version","alias_value":"2605.18891v1","created_at":"2026-05-20T00:06:30Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.18891","created_at":"2026-05-20T00:06:30Z"},{"alias_kind":"pith_short_12","alias_value":"PXWGPF5Z7OYW","created_at":"2026-05-20T00:06:30Z"},{"alias_kind":"pith_short_16","alias_value":"PXWGPF5Z7OYW62O5","created_at":"2026-05-20T00:06:30Z"},{"alias_kind":"pith_short_8","alias_value":"PXWGPF5Z","created_at":"2026-05-20T00:06:30Z"}],"graph_snapshots":[{"event_id":"sha256:e82ce9cdfa3e2e97f158871bace58299a04f8c5e4e21b9cab519af3d2d52544d","target":"graph","created_at":"2026-05-20T00:06:30Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.18891/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Evaluations of unlearning on reasoning models sometimes show a bypass pattern. The answer side looks unlearned, but the model's own thinking trace keeps emitting the forgotten content, and the gap is taken as evidence that the weights still remember. We audit this reading on DeepSeek-R1-Distill-Qwen-7B with LoRA-memorized fictional authors and NPO unlearning, conditioned on a six-token canary head. On one seed, swapping the thinking trace for a short non-canary prefill on the same weights drops the answer rate by as much as the bypass gap itself, whether the prefill mimics the training templat","authors_text":"Yanhang Li, Zexin Zhuang, Zhichao Fan","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-17T05:22:27Z","title":"Auditing Reasoning-Trace Memorization Claims after Unlearning with Head-Conditioned Canaries"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.18891","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:692447af90a4028d6d2f4bbe6812d677ae66153803bd1856ffe21534530af015","target":"record","created_at":"2026-05-20T00:06:30Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e946854035a9506b8a255c7386908b8ecb5c53012faf030bbd027cdeff387d85","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-05-17T05:22:27Z","title_canon_sha256":"f59ccb1207108d425d887e3f30ce18b6afbfebc33990c052a0bfa11782560012"},"schema_version":"1.0","source":{"id":"2605.18891","kind":"arxiv","version":1}},"canonical_sha256":"7dec6797b9fbb16f69dd2b474ccc6b5333b1692b33762b2833cd3f8c3a06f7f2","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"7dec6797b9fbb16f69dd2b474ccc6b5333b1692b33762b2833cd3f8c3a06f7f2","first_computed_at":"2026-05-20T00:06:30.769804Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:06:30.769804Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"+QILBnzeDJ0XbQKJynfZrqv8826dh7I1e92nfVLG7oFziHiZIY2tFThcHM3sXRGGLJ+F0ui/AjS0++BV2AX+Ag==","signature_status":"signed_v1","signed_at":"2026-05-20T00:06:30.770655Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.18891","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:692447af90a4028d6d2f4bbe6812d677ae66153803bd1856ffe21534530af015","sha256:e82ce9cdfa3e2e97f158871bace58299a04f8c5e4e21b9cab519af3d2d52544d"],"state_sha256":"3500f14283b9730dc9372860430ef46505eb2799594f5fee89e9685a91aff1a6"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"r101eKQ9rrkRQaZ+WouTqKwuMZZs3RGKLZv9Exx4AsAs2XdfmfWNSEpzgpYDekT95/Obj9OOsQzoYURzIEKfCQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-22T21:48:41.744435Z","bundle_sha256":"2176924627b93932e5afa65863950154dc9a20135aaba7bf65ef1d271414f7ba"}}