{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:QB47BYOLQQEYT5ZSKCYMLAHZAN","short_pith_number":"pith:QB47BYOL","canonical_record":{"source":{"id":"2606.30819","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-29T18:46:21Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"178f9bbb781e177c0f34d56385387e78216eab7b70d6167e3d3c9db6041cbd2a","abstract_canon_sha256":"e102c0cdd509348745cc50ea23f6f3464005484e1250e598ed8d31177548bc96"},"schema_version":"1.0"},"canonical_sha256":"8079f0e1cb840989f73250b0c580f9037be2c9b8cd10a05f0bdc9f29a3c9ac1e","source":{"kind":"arxiv","id":"2606.30819","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.30819","created_at":"2026-07-01T00:17:18Z"},{"alias_kind":"arxiv_version","alias_value":"2606.30819v1","created_at":"2026-07-01T00:17:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.30819","created_at":"2026-07-01T00:17:18Z"},{"alias_kind":"pith_short_12","alias_value":"QB47BYOLQQEY","created_at":"2026-07-01T00:17:18Z"},{"alias_kind":"pith_short_16","alias_value":"QB47BYOLQQEYT5ZS","created_at":"2026-07-01T00:17:18Z"},{"alias_kind":"pith_short_8","alias_value":"QB47BYOL","created_at":"2026-07-01T00:17:18Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:QB47BYOLQQEYT5ZSKCYMLAHZAN","target":"record","payload":{"canonical_record":{"source":{"id":"2606.30819","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-29T18:46:21Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"178f9bbb781e177c0f34d56385387e78216eab7b70d6167e3d3c9db6041cbd2a","abstract_canon_sha256":"e102c0cdd509348745cc50ea23f6f3464005484e1250e598ed8d31177548bc96"},"schema_version":"1.0"},"canonical_sha256":"8079f0e1cb840989f73250b0c580f9037be2c9b8cd10a05f0bdc9f29a3c9ac1e","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-01T00:17:18.423700Z","signature_b64":"45+MVh3qEcHV4Vhdhnng09tZRVDjRAkCOY26cmbW4LAa7b2KRGJ26MxW2sMUadrqLIhHB9UwSKoUZz/ox3q3CA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8079f0e1cb840989f73250b0c580f9037be2c9b8cd10a05f0bdc9f29a3c9ac1e","last_reissued_at":"2026-07-01T00:17:18.423280Z","signature_status":"signed_v1","first_computed_at":"2026-07-01T00:17:18.423280Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.30819","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-01T00:17:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"6GPFLwF0q97grXC4ZG41ZFObcIdQPfw/m7fivisqoL/WfF5bqquHBSA/bqs9aAssG4ivS9l0KjwqxVKCAAB6Aw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-03T19:24:44.552097Z"},"content_sha256":"fe219affb418119afac44e7bf3dd1d7be3265c646990c421aad072f5e1ea2aa1","schema_version":"1.0","event_id":"sha256:fe219affb418119afac44e7bf3dd1d7be3265c646990c421aad072f5e1ea2aa1"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:QB47BYOLQQEYT5ZSKCYMLAHZAN","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"AI-Generated PowerShell Malware: An Experimental Framework and Dataset","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Luciano Pianese, Pietro Liguori, Roberto Natella, Vittorio Orbinato","submitted_at":"2026-06-29T18:46:21Z","abstract_excerpt":"Generative AI has emerged as a significant cybersecurity threat, with several recent attack campaigns leveraging LLMs to generate code for malicious purposes via scripting languages such as PowerShell. Consequently, for cybersecurity analysts, it is imperative to investigate the offensive capabilities of AI code generators. In this paper, we propose an experimental framework to assess LLM-generated PowerShell malware, which comprises a novel sandbox approach for dynamic analysis of AI-generated malware. Furthermore, we present a novel, manually curated dataset of real-world PowerShell malware,"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.30819","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.30819/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-01T00:17:18Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"VvQ54qGsmhb3OkLuwVNJsYSn2m2C2T/8zakk3+nDoh7xlhQjoXgYFvndBVYoD3wyQbonBVq6BCGfnsPu4OzdBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-03T19:24:44.552516Z"},"content_sha256":"bebcb872af2aa575de49388b0b84d02a3a5f412df2a71395bbb0a14bda343583","schema_version":"1.0","event_id":"sha256:bebcb872af2aa575de49388b0b84d02a3a5f412df2a71395bbb0a14bda343583"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/QB47BYOLQQEYT5ZSKCYMLAHZAN/bundle.json","state_url":"https://pith.science/pith/QB47BYOLQQEYT5ZSKCYMLAHZAN/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/QB47BYOLQQEYT5ZSKCYMLAHZAN/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-03T19:24:44Z","links":{"resolver":"https://pith.science/pith/QB47BYOLQQEYT5ZSKCYMLAHZAN","bundle":"https://pith.science/pith/QB47BYOLQQEYT5ZSKCYMLAHZAN/bundle.json","state":"https://pith.science/pith/QB47BYOLQQEYT5ZSKCYMLAHZAN/state.json","well_known_bundle":"https://pith.science/.well-known/pith/QB47BYOLQQEYT5ZSKCYMLAHZAN/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:QB47BYOLQQEYT5ZSKCYMLAHZAN","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e102c0cdd509348745cc50ea23f6f3464005484e1250e598ed8d31177548bc96","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-29T18:46:21Z","title_canon_sha256":"178f9bbb781e177c0f34d56385387e78216eab7b70d6167e3d3c9db6041cbd2a"},"schema_version":"1.0","source":{"id":"2606.30819","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.30819","created_at":"2026-07-01T00:17:18Z"},{"alias_kind":"arxiv_version","alias_value":"2606.30819v1","created_at":"2026-07-01T00:17:18Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.30819","created_at":"2026-07-01T00:17:18Z"},{"alias_kind":"pith_short_12","alias_value":"QB47BYOLQQEY","created_at":"2026-07-01T00:17:18Z"},{"alias_kind":"pith_short_16","alias_value":"QB47BYOLQQEYT5ZS","created_at":"2026-07-01T00:17:18Z"},{"alias_kind":"pith_short_8","alias_value":"QB47BYOL","created_at":"2026-07-01T00:17:18Z"}],"graph_snapshots":[{"event_id":"sha256:bebcb872af2aa575de49388b0b84d02a3a5f412df2a71395bbb0a14bda343583","target":"graph","created_at":"2026-07-01T00:17:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.30819/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Generative AI has emerged as a significant cybersecurity threat, with several recent attack campaigns leveraging LLMs to generate code for malicious purposes via scripting languages such as PowerShell. Consequently, for cybersecurity analysts, it is imperative to investigate the offensive capabilities of AI code generators. In this paper, we propose an experimental framework to assess LLM-generated PowerShell malware, which comprises a novel sandbox approach for dynamic analysis of AI-generated malware. Furthermore, we present a novel, manually curated dataset of real-world PowerShell malware,","authors_text":"Luciano Pianese, Pietro Liguori, Roberto Natella, Vittorio Orbinato","cross_cats":["cs.AI"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-29T18:46:21Z","title":"AI-Generated PowerShell Malware: An Experimental Framework and Dataset"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.30819","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:fe219affb418119afac44e7bf3dd1d7be3265c646990c421aad072f5e1ea2aa1","target":"record","created_at":"2026-07-01T00:17:18Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e102c0cdd509348745cc50ea23f6f3464005484e1250e598ed8d31177548bc96","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-29T18:46:21Z","title_canon_sha256":"178f9bbb781e177c0f34d56385387e78216eab7b70d6167e3d3c9db6041cbd2a"},"schema_version":"1.0","source":{"id":"2606.30819","kind":"arxiv","version":1}},"canonical_sha256":"8079f0e1cb840989f73250b0c580f9037be2c9b8cd10a05f0bdc9f29a3c9ac1e","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"8079f0e1cb840989f73250b0c580f9037be2c9b8cd10a05f0bdc9f29a3c9ac1e","first_computed_at":"2026-07-01T00:17:18.423280Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-01T00:17:18.423280Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"45+MVh3qEcHV4Vhdhnng09tZRVDjRAkCOY26cmbW4LAa7b2KRGJ26MxW2sMUadrqLIhHB9UwSKoUZz/ox3q3CA==","signature_status":"signed_v1","signed_at":"2026-07-01T00:17:18.423700Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.30819","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:fe219affb418119afac44e7bf3dd1d7be3265c646990c421aad072f5e1ea2aa1","sha256:bebcb872af2aa575de49388b0b84d02a3a5f412df2a71395bbb0a14bda343583"],"state_sha256":"d717dc24debb720a423066cecbc9717e5fa710836fb0c9b59feedbba41b02cab"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"z957cwmqOL4RfWkr3I49ihYvMeOhHIilSe373M0OgpOd1wlSGZtKfFlGBc3nXw8U+Q5C+1sDfZKWaaaXZSVSCQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-03T19:24:44.554561Z","bundle_sha256":"e1d6fee8b7e955c7cbe9dc240c1a3b167ea8cd9c0c99ed94390a1d177d24bfd4"}}