{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:R6WERKAF3Y4TN5DGJ2UK77YHMC","short_pith_number":"pith:R6WERKAF","canonical_record":{"source":{"id":"2606.01212","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-31T13:03:47Z","cross_cats_sorted":["cs.AI","cs.CR","cs.IR"],"title_canon_sha256":"5cc7517607d5c074678525972992175b95951ce80e7aadf086cd2014e12b8cc6","abstract_canon_sha256":"d8317ad22a782aec48b14fd0864935e871dfdfa72de0857bd3e0de17186bd6f9"},"schema_version":"1.0"},"canonical_sha256":"8fac48a805de3936f4664ea8afff0760aa61e5de2ce36e154f53626ea0d1e4ff","source":{"kind":"arxiv","id":"2606.01212","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.01212","created_at":"2026-06-02T02:04:26Z"},{"alias_kind":"arxiv_version","alias_value":"2606.01212v1","created_at":"2026-06-02T02:04:26Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.01212","created_at":"2026-06-02T02:04:26Z"},{"alias_kind":"pith_short_12","alias_value":"R6WERKAF3Y4T","created_at":"2026-06-02T02:04:26Z"},{"alias_kind":"pith_short_16","alias_value":"R6WERKAF3Y4TN5DG","created_at":"2026-06-02T02:04:26Z"},{"alias_kind":"pith_short_8","alias_value":"R6WERKAF","created_at":"2026-06-02T02:04:26Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:R6WERKAF3Y4TN5DGJ2UK77YHMC","target":"record","payload":{"canonical_record":{"source":{"id":"2606.01212","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-31T13:03:47Z","cross_cats_sorted":["cs.AI","cs.CR","cs.IR"],"title_canon_sha256":"5cc7517607d5c074678525972992175b95951ce80e7aadf086cd2014e12b8cc6","abstract_canon_sha256":"d8317ad22a782aec48b14fd0864935e871dfdfa72de0857bd3e0de17186bd6f9"},"schema_version":"1.0"},"canonical_sha256":"8fac48a805de3936f4664ea8afff0760aa61e5de2ce36e154f53626ea0d1e4ff","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-02T02:04:26.970721Z","signature_b64":"T/eVcXDdWafYh9mrDozXozgLixsgdFP9Xg92a4hAdlfApvqxECeKQL14tW83S+CjT6woX8UH5m4Gmu7hXUtyCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8fac48a805de3936f4664ea8afff0760aa61e5de2ce36e154f53626ea0d1e4ff","last_reissued_at":"2026-06-02T02:04:26.970350Z","signature_status":"signed_v1","first_computed_at":"2026-06-02T02:04:26.970350Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.01212","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T02:04:26Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"5IILAyWuw7kk/Fa8LO+mAKggmtCAr7VHm0Wae8JxZJQ/xagMxEFVlnkEL/wICqyn+mo2Qdo/I5xhdnKL/aClBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T21:06:11.400052Z"},"content_sha256":"7a09d236cc07d78c399a285507d77fe8962c2cb425613d38453109c30b32c844","schema_version":"1.0","event_id":"sha256:7a09d236cc07d78c399a285507d77fe8962c2cb425613d38453109c30b32c844"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:R6WERKAF3Y4TN5DGJ2UK77YHMC","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"DiscourseFlip: An Oblique Discourse-Level Opinion Manipulation Attack against Black-box Retrieval-Augmented Generation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.CR","cs.IR"],"primary_cat":"cs.CL","authors_text":"Guoxiu He, Jiawei Liu, Miaokun Chen, Wei Lu, Xiaofeng Wang, Xiaozhong Liu, Yuyang Gong, Zhuo Chen","submitted_at":"2026-05-31T13:03:47Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) systems are widely deployed and increasingly influential, but their reliance on external corpora exposes new security risks from poisoned retrieval content. Existing RAG attacks are largely focusing on individual queries or narrow topic-local query sets, which limits their practical reach and offers limited camouflage in real-world settings. In this paper, we introduce discourse-level opinion manipulation, a new threat model in which coordinated influence across a semantic query network induces opinion shifts over a holistic, multi-topic query space. We for"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.01212","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.01212/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-02T02:04:26Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"HrbcXwK9CmuEWu3NhDuw4Nq8VMkO4OQsW1/2HHX0ufBMy33Tavj+qkZzN47r4tfQuxNOHi9ZWu5mWEWLncBKBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T21:06:11.400762Z"},"content_sha256":"300928e1b1cbd361479faea6efc7e4cbe6ef9b10699c73444c42bf335bb2a915","schema_version":"1.0","event_id":"sha256:300928e1b1cbd361479faea6efc7e4cbe6ef9b10699c73444c42bf335bb2a915"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/R6WERKAF3Y4TN5DGJ2UK77YHMC/bundle.json","state_url":"https://pith.science/pith/R6WERKAF3Y4TN5DGJ2UK77YHMC/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/R6WERKAF3Y4TN5DGJ2UK77YHMC/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-02T21:06:11Z","links":{"resolver":"https://pith.science/pith/R6WERKAF3Y4TN5DGJ2UK77YHMC","bundle":"https://pith.science/pith/R6WERKAF3Y4TN5DGJ2UK77YHMC/bundle.json","state":"https://pith.science/pith/R6WERKAF3Y4TN5DGJ2UK77YHMC/state.json","well_known_bundle":"https://pith.science/.well-known/pith/R6WERKAF3Y4TN5DGJ2UK77YHMC/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:R6WERKAF3Y4TN5DGJ2UK77YHMC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"d8317ad22a782aec48b14fd0864935e871dfdfa72de0857bd3e0de17186bd6f9","cross_cats_sorted":["cs.AI","cs.CR","cs.IR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-31T13:03:47Z","title_canon_sha256":"5cc7517607d5c074678525972992175b95951ce80e7aadf086cd2014e12b8cc6"},"schema_version":"1.0","source":{"id":"2606.01212","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.01212","created_at":"2026-06-02T02:04:26Z"},{"alias_kind":"arxiv_version","alias_value":"2606.01212v1","created_at":"2026-06-02T02:04:26Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.01212","created_at":"2026-06-02T02:04:26Z"},{"alias_kind":"pith_short_12","alias_value":"R6WERKAF3Y4T","created_at":"2026-06-02T02:04:26Z"},{"alias_kind":"pith_short_16","alias_value":"R6WERKAF3Y4TN5DG","created_at":"2026-06-02T02:04:26Z"},{"alias_kind":"pith_short_8","alias_value":"R6WERKAF","created_at":"2026-06-02T02:04:26Z"}],"graph_snapshots":[{"event_id":"sha256:300928e1b1cbd361479faea6efc7e4cbe6ef9b10699c73444c42bf335bb2a915","target":"graph","created_at":"2026-06-02T02:04:26Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.01212/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Retrieval-Augmented Generation (RAG) systems are widely deployed and increasingly influential, but their reliance on external corpora exposes new security risks from poisoned retrieval content. Existing RAG attacks are largely focusing on individual queries or narrow topic-local query sets, which limits their practical reach and offers limited camouflage in real-world settings. In this paper, we introduce discourse-level opinion manipulation, a new threat model in which coordinated influence across a semantic query network induces opinion shifts over a holistic, multi-topic query space. We for","authors_text":"Guoxiu He, Jiawei Liu, Miaokun Chen, Wei Lu, Xiaofeng Wang, Xiaozhong Liu, Yuyang Gong, Zhuo Chen","cross_cats":["cs.AI","cs.CR","cs.IR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-31T13:03:47Z","title":"DiscourseFlip: An Oblique Discourse-Level Opinion Manipulation Attack against Black-box Retrieval-Augmented Generation"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.01212","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7a09d236cc07d78c399a285507d77fe8962c2cb425613d38453109c30b32c844","target":"record","created_at":"2026-06-02T02:04:26Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"d8317ad22a782aec48b14fd0864935e871dfdfa72de0857bd3e0de17186bd6f9","cross_cats_sorted":["cs.AI","cs.CR","cs.IR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2026-05-31T13:03:47Z","title_canon_sha256":"5cc7517607d5c074678525972992175b95951ce80e7aadf086cd2014e12b8cc6"},"schema_version":"1.0","source":{"id":"2606.01212","kind":"arxiv","version":1}},"canonical_sha256":"8fac48a805de3936f4664ea8afff0760aa61e5de2ce36e154f53626ea0d1e4ff","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"8fac48a805de3936f4664ea8afff0760aa61e5de2ce36e154f53626ea0d1e4ff","first_computed_at":"2026-06-02T02:04:26.970350Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-02T02:04:26.970350Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"T/eVcXDdWafYh9mrDozXozgLixsgdFP9Xg92a4hAdlfApvqxECeKQL14tW83S+CjT6woX8UH5m4Gmu7hXUtyCg==","signature_status":"signed_v1","signed_at":"2026-06-02T02:04:26.970721Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.01212","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7a09d236cc07d78c399a285507d77fe8962c2cb425613d38453109c30b32c844","sha256:300928e1b1cbd361479faea6efc7e4cbe6ef9b10699c73444c42bf335bb2a915"],"state_sha256":"58b532b7a959d22e1ff0be22d55d089072cb2c1ecd067744a8703490c13a9c64"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+Tqu0BIAyBhze1cbQ7vb19/1RP+/T2tvno0q24ZobnhPtAoB6/NYu63OsoZD+iHF04sFo2Jkk0XLcuix5mWPBw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-02T21:06:11.404225Z","bundle_sha256":"b80c24303da1a7dfc30276e0505d0df2d9f1042e482a7d48ad8c740ddd91513b"}}