{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:QLVPASIKZ2FYNCNOIDEPX6QLOM","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"197892eb98b81c315b2c46449fa11459ea5075e5af47ab8358692330fc3fec43","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T22:57:02Z","title_canon_sha256":"f3c3076b44ae3711ca89f15fa29b645aa498614e0e4a7ea6e8cdc711447791f3"},"schema_version":"1.0","source":{"id":"2606.12737","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.12737","created_at":"2026-06-12T01:08:48Z"},{"alias_kind":"arxiv_version","alias_value":"2606.12737v1","created_at":"2026-06-12T01:08:48Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.12737","created_at":"2026-06-12T01:08:48Z"},{"alias_kind":"pith_short_12","alias_value":"QLVPASIKZ2FY","created_at":"2026-06-12T01:08:48Z"},{"alias_kind":"pith_short_16","alias_value":"QLVPASIKZ2FYNCNO","created_at":"2026-06-12T01:08:48Z"},{"alias_kind":"pith_short_8","alias_value":"QLVPASIK","created_at":"2026-06-12T01:08:48Z"}],"graph_snapshots":[{"event_id":"sha256:8b20a8845da13839ab17252449da8649cf500a5a6044114de4d4afa642b30a1c","target":"graph","created_at":"2026-06-12T01:08:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.12737/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large Language Models (LLMs) are rapidly evolving into agentic systems that interact with external tools and environments, introducing new security risks such as indirect prompt injection attacks through untrusted external sources. Existing defenses mainly focus on blocking malicious content at inference time, and current red-teaming methods primarily optimize attack success. As a result, developers have limited visibility into how latent prompt injections emerge and propagate through agents. We propose PI-Hunter, an automated agentic auditing framework for proactive vulnerability exposure in ","authors_text":"Ash Fox, George Lee, Jiliang Tang, Lesly Miculicich, Long T. Le, Pengfei He, Tomas Pfister, Vishesh Sharma","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T22:57:02Z","title":"PI-Hunter: Automated Red-Teaming for Exposing and Localizing Prompt Injections"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.12737","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f84b94a30ce4cd3131a6495ae4bc6aeec13414d8775926cd72c3a0bc3c4b546d","target":"record","created_at":"2026-06-12T01:08:48Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"197892eb98b81c315b2c46449fa11459ea5075e5af47ab8358692330fc3fec43","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T22:57:02Z","title_canon_sha256":"f3c3076b44ae3711ca89f15fa29b645aa498614e0e4a7ea6e8cdc711447791f3"},"schema_version":"1.0","source":{"id":"2606.12737","kind":"arxiv","version":1}},"canonical_sha256":"82eaf0490ace8b8689ae40c8fbfa0b7319b7c1adf6920e34984335e9fa593536","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"82eaf0490ace8b8689ae40c8fbfa0b7319b7c1adf6920e34984335e9fa593536","first_computed_at":"2026-06-12T01:08:48.517435Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-12T01:08:48.517435Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"9NPmOzkSob7Vrjun3IG7IELbwROhZ3qNKRQGhXI+iquxn2trKl0YjeIlkFd5HnUd1I5SCXhsOQs3knjYJpWXDQ==","signature_status":"signed_v1","signed_at":"2026-06-12T01:08:48.518344Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.12737","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f84b94a30ce4cd3131a6495ae4bc6aeec13414d8775926cd72c3a0bc3c4b546d","sha256:8b20a8845da13839ab17252449da8649cf500a5a6044114de4d4afa642b30a1c"],"state_sha256":"a0d51b74065fe848b5d3709a1bb321c4460ef3bbebc47c09c036e0efc7f651c8"}