{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2022:RELJI4P3LVKIKBRVZF7TFZNAWZ","short_pith_number":"pith:RELJI4P3","canonical_record":{"source":{"id":"2209.07858","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2022-08-23T23:37:14Z","cross_cats_sorted":["cs.AI","cs.CY"],"title_canon_sha256":"fd13613aaa303a30e09f7680abae66812319290fb3669a253962851d5422ba25","abstract_canon_sha256":"f718d264fed58bbde4d6a6b189216990bd3531c66d26424ca18a7e760eb42066"},"schema_version":"1.0"},"canonical_sha256":"89169471fb5d54850635c97f32e5a0b67b74d441d9b05509ed54bbdf98b75f9f","source":{"kind":"arxiv","id":"2209.07858","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2209.07858","created_at":"2026-07-05T05:18:49Z"},{"alias_kind":"arxiv_version","alias_value":"2209.07858v2","created_at":"2026-07-05T05:18:49Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2209.07858","created_at":"2026-07-05T05:18:49Z"},{"alias_kind":"pith_short_12","alias_value":"RELJI4P3LVKI","created_at":"2026-07-05T05:18:49Z"},{"alias_kind":"pith_short_16","alias_value":"RELJI4P3LVKIKBRV","created_at":"2026-07-05T05:18:49Z"},{"alias_kind":"pith_short_8","alias_value":"RELJI4P3","created_at":"2026-07-05T05:18:49Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2022:RELJI4P3LVKIKBRVZF7TFZNAWZ","target":"record","payload":{"canonical_record":{"source":{"id":"2209.07858","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2022-08-23T23:37:14Z","cross_cats_sorted":["cs.AI","cs.CY"],"title_canon_sha256":"fd13613aaa303a30e09f7680abae66812319290fb3669a253962851d5422ba25","abstract_canon_sha256":"f718d264fed58bbde4d6a6b189216990bd3531c66d26424ca18a7e760eb42066"},"schema_version":"1.0"},"canonical_sha256":"89169471fb5d54850635c97f32e5a0b67b74d441d9b05509ed54bbdf98b75f9f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T05:18:49.618938Z","signature_b64":"yHDJoGF0WAmLLGRLmSRvR9fwUSOU8lbW88iW15FaBAlzG2YxNK3Jc+ldb6V88eo3iND53+muX4on3WySrFruAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"89169471fb5d54850635c97f32e5a0b67b74d441d9b05509ed54bbdf98b75f9f","last_reissued_at":"2026-07-05T05:18:49.618352Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T05:18:49.618352Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2209.07858","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T05:18:49Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"UzmhwqclS6JyyQQxQln/138yPlG9otwdeusC7mkLf9OTeebbc892zyABH2oEkTPbmn/DIzZyU0Kkqx8F6+eBCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-17T19:57:41.581475Z"},"content_sha256":"694af005419ce6e28426d7931b579b0464c836983f48bce5df76e8271143aa7a","schema_version":"1.0","event_id":"sha256:694af005419ce6e28426d7931b579b0464c836983f48bce5df76e8271143aa7a"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2022:RELJI4P3LVKIKBRVZF7TFZNAWZ","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned","license":"http://creativecommons.org/licenses/by/4.0/","headline":"RLHF-trained language models become progressively harder to red-team into harmful outputs as they scale up in size, while other training approaches show no such improvement.","cross_cats":["cs.AI","cs.CY"],"primary_cat":"cs.CL","authors_text":"Amanda Askell, Andy Jones, Anna Chen, Ben Mann, Catherine Olsson, Chris Olah, Danny Hernandez, Dario Amodei, Dawn Drain, Deep Ganguli, Eli Tran-Johnson, Ethan Perez, Jack Clark, Jackson Kernion, Jared Kaplan, Josh Jacobson, Kamal Ndousse, Liane Lovitt, Nelson Elhage, Nicholas Joseph, Nicholas Schiefer, Nova DasSarma, Sam Bowman, Sam McCandlish, Sam Ringer, Saurav Kadavath, Scott Johnston, Shauna Kravec, Sheer El-Showk, Stanislav Fort, Tom Brown, Tom Conerly, Tom Henighan, Tristan Hume, Yuntao Bai, Zac Hatfield-Dodds","submitted_at":"2022-08-23T23:37:14Z","abstract_excerpt":"We describe our early efforts to red team language models in order to simultaneously discover, measure, and attempt to reduce their potentially harmful outputs. We make three main contributions. First, we investigate scaling behaviors for red teaming across 3 model sizes (2.7B, 13B, and 52B parameters) and 4 model types: a plain language model (LM); an LM prompted to be helpful, honest, and harmless; an LM with rejection sampling; and a model trained to be helpful and harmless using reinforcement learning from human feedback (RLHF). We find that the RLHF models are increasingly difficult to re"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"We find that the RLHF models are increasingly difficult to red team as they scale, and we find a flat trend with scale for the other model types.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"The assumption that the red team attacks used in the study are sufficient to uncover all or most potential harmful behaviors in the models, and that the model types tested are representative of current and future language models.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"RLHF-aligned language models show increasing resistance to red teaming with scale up to 52B parameters, unlike prompted or rejection-sampled models, supported by a released dataset of 38,961 attacks.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"RLHF-trained language models become progressively harder to red-team into harmful outputs as they scale up in size, while other training approaches show no such improvement.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"d958902ff033f235ca7c014dd0589025548fc9070da1d471ed1e884ed1df72f7"},"source":{"id":"2209.07858","kind":"arxiv","version":2},"verdict":{"id":"c33b612e-12a1-4462-a590-08d1e45d31c6","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-12T01:32:45.315412Z","strongest_claim":"We find that the RLHF models are increasingly difficult to red team as they scale, and we find a flat trend with scale for the other model types.","one_line_summary":"RLHF-aligned language models show increasing resistance to red teaming with scale up to 52B parameters, unlike prompted or rejection-sampled models, supported by a released dataset of 38,961 attacks.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"The assumption that the red team attacks used in the study are sufficient to uncover all or most potential harmful behaviors in the models, and that the model types tested are representative of current and future language models.","pith_extraction_headline":"RLHF-trained language models become progressively harder to red-team into harmful outputs as they scale up in size, while other training approaches show no such improvement."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2209.07858/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":64,"sample":[{"doi":"","year":2021,"title":"A. Abid, M. Farooqi, and J. Zou. Large language models associate Muslims with violence. Nature Machine Intelligence, 3(6):461–463, June 2021. Number: 6 Publisher: Nature Publishing Group","work_id":"5d776628-9723-4199-9be1-38dbaca4dfed","ref_index":1,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2021,"title":"A General Language Assistant as a Laboratory for Alignment","work_id":"a43f9ea0-01be-47d5-b8ee-a1a9f73381c5","ref_index":2,"cited_arxiv_id":"2112.00861","is_internal_anchor":true},{"doi":"","year":2021,"title":"S. Avin, H. Belﬁeld, M. Brundage, G. Krueger, J. Wang, A. Weller, M. Anderljung, I. Krawczuk, D. Krueger, J. Lebensold, T. Maharaj, and N. Zilberman. Filling gaps in trustworthy development of AI. Sci","work_id":"60cf31e9-9d53-4dbc-a09b-a8f411de74ab","ref_index":3,"cited_arxiv_id":"","is_internal_anchor":false},{"doi":"","year":2022,"title":"Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback","work_id":"a1f2574b-a899-4713-be60-c87ba332656c","ref_index":4,"cited_arxiv_id":"2204.05862","is_internal_anchor":true},{"doi":"","year":null,"title":"P. Barrett. Research Highlights | Who Moderates the Social Media Giants? A Call to End Outsourcing - NYU Stern","work_id":"14ac4614-1ec6-4208-9015-ac81b5a21407","ref_index":5,"cited_arxiv_id":"","is_internal_anchor":false}],"resolved_work":64,"snapshot_sha256":"ae59e2d892889ca297a75d3ac2155a3f5672604dceeb01725e9c5397cab68107","internal_anchors":12},"formal_canon":{"evidence_count":2,"snapshot_sha256":"7787fdae4ab5689b8c6f063095e15160bacd325c8b9e02cffe721ce2d629710f"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"c33b612e-12a1-4462-a590-08d1e45d31c6"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T05:18:49Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Psq6FmXlZgDVfHL6DtLUAinINS/3jXzrclVVxs9LRR3jptOWA6ctYvttAzU0OvbUPKC9J3BeOG21q382UlHODA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-17T19:57:41.582350Z"},"content_sha256":"a1281fba89446d48c9a61c46eaea4a323eacee61f6697db5bb4320862cf9c11f","schema_version":"1.0","event_id":"sha256:a1281fba89446d48c9a61c46eaea4a323eacee61f6697db5bb4320862cf9c11f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/RELJI4P3LVKIKBRVZF7TFZNAWZ/bundle.json","state_url":"https://pith.science/pith/RELJI4P3LVKIKBRVZF7TFZNAWZ/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/RELJI4P3LVKIKBRVZF7TFZNAWZ/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-17T19:57:41Z","links":{"resolver":"https://pith.science/pith/RELJI4P3LVKIKBRVZF7TFZNAWZ","bundle":"https://pith.science/pith/RELJI4P3LVKIKBRVZF7TFZNAWZ/bundle.json","state":"https://pith.science/pith/RELJI4P3LVKIKBRVZF7TFZNAWZ/state.json","well_known_bundle":"https://pith.science/.well-known/pith/RELJI4P3LVKIKBRVZF7TFZNAWZ/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2022:RELJI4P3LVKIKBRVZF7TFZNAWZ","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"f718d264fed58bbde4d6a6b189216990bd3531c66d26424ca18a7e760eb42066","cross_cats_sorted":["cs.AI","cs.CY"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2022-08-23T23:37:14Z","title_canon_sha256":"fd13613aaa303a30e09f7680abae66812319290fb3669a253962851d5422ba25"},"schema_version":"1.0","source":{"id":"2209.07858","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2209.07858","created_at":"2026-07-05T05:18:49Z"},{"alias_kind":"arxiv_version","alias_value":"2209.07858v2","created_at":"2026-07-05T05:18:49Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2209.07858","created_at":"2026-07-05T05:18:49Z"},{"alias_kind":"pith_short_12","alias_value":"RELJI4P3LVKI","created_at":"2026-07-05T05:18:49Z"},{"alias_kind":"pith_short_16","alias_value":"RELJI4P3LVKIKBRV","created_at":"2026-07-05T05:18:49Z"},{"alias_kind":"pith_short_8","alias_value":"RELJI4P3","created_at":"2026-07-05T05:18:49Z"}],"graph_snapshots":[{"event_id":"sha256:a1281fba89446d48c9a61c46eaea4a323eacee61f6697db5bb4320862cf9c11f","target":"graph","created_at":"2026-07-05T05:18:49Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"We find that the RLHF models are increasingly difficult to red team as they scale, and we find a flat trend with scale for the other model types."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The assumption that the red team attacks used in the study are sufficient to uncover all or most potential harmful behaviors in the models, and that the model types tested are representative of current and future language models."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"RLHF-aligned language models show increasing resistance to red teaming with scale up to 52B parameters, unlike prompted or rejection-sampled models, supported by a released dataset of 38,961 attacks."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"RLHF-trained language models become progressively harder to red-team into harmful outputs as they scale up in size, while other training approaches show no such improvement."}],"snapshot_sha256":"d958902ff033f235ca7c014dd0589025548fc9070da1d471ed1e884ed1df72f7"},"formal_canon":{"evidence_count":2,"snapshot_sha256":"7787fdae4ab5689b8c6f063095e15160bacd325c8b9e02cffe721ce2d629710f"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2209.07858/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"We describe our early efforts to red team language models in order to simultaneously discover, measure, and attempt to reduce their potentially harmful outputs. We make three main contributions. First, we investigate scaling behaviors for red teaming across 3 model sizes (2.7B, 13B, and 52B parameters) and 4 model types: a plain language model (LM); an LM prompted to be helpful, honest, and harmless; an LM with rejection sampling; and a model trained to be helpful and harmless using reinforcement learning from human feedback (RLHF). We find that the RLHF models are increasingly difficult to re","authors_text":"Amanda Askell, Andy Jones, Anna Chen, Ben Mann, Catherine Olsson, Chris Olah, Danny Hernandez, Dario Amodei, Dawn Drain, Deep Ganguli, Eli Tran-Johnson, Ethan Perez, Jack Clark, Jackson Kernion, Jared Kaplan, Josh Jacobson, Kamal Ndousse, Liane Lovitt, Nelson Elhage, Nicholas Joseph, Nicholas Schiefer, Nova DasSarma, Sam Bowman, Sam McCandlish, Sam Ringer, Saurav Kadavath, Scott Johnston, Shauna Kravec, Sheer El-Showk, Stanislav Fort, Tom Brown, Tom Conerly, Tom Henighan, Tristan Hume, Yuntao Bai, Zac Hatfield-Dodds","cross_cats":["cs.AI","cs.CY"],"headline":"RLHF-trained language models become progressively harder to red-team into harmful outputs as they scale up in size, while other training approaches show no such improvement.","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2022-08-23T23:37:14Z","title":"Red Teaming Language Models to Reduce Harms: Methods, Scaling Behaviors, and Lessons Learned"},"references":{"count":64,"internal_anchors":12,"resolved_work":64,"sample":[{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":1,"title":"A. Abid, M. Farooqi, and J. Zou. Large language models associate Muslims with violence. Nature Machine Intelligence, 3(6):461–463, June 2021. Number: 6 Publisher: Nature Publishing Group","work_id":"5d776628-9723-4199-9be1-38dbaca4dfed","year":2021},{"cited_arxiv_id":"2112.00861","doi":"","is_internal_anchor":true,"ref_index":2,"title":"A General Language Assistant as a Laboratory for Alignment","work_id":"a43f9ea0-01be-47d5-b8ee-a1a9f73381c5","year":2021},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":3,"title":"S. Avin, H. Belﬁeld, M. Brundage, G. Krueger, J. Wang, A. Weller, M. Anderljung, I. Krawczuk, D. Krueger, J. Lebensold, T. Maharaj, and N. Zilberman. Filling gaps in trustworthy development of AI. Sci","work_id":"60cf31e9-9d53-4dbc-a09b-a8f411de74ab","year":2021},{"cited_arxiv_id":"2204.05862","doi":"","is_internal_anchor":true,"ref_index":4,"title":"Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback","work_id":"a1f2574b-a899-4713-be60-c87ba332656c","year":2022},{"cited_arxiv_id":"","doi":"","is_internal_anchor":false,"ref_index":5,"title":"P. Barrett. Research Highlights | Who Moderates the Social Media Giants? A Call to End Outsourcing - NYU Stern","work_id":"14ac4614-1ec6-4208-9015-ac81b5a21407","year":null}],"snapshot_sha256":"ae59e2d892889ca297a75d3ac2155a3f5672604dceeb01725e9c5397cab68107"},"source":{"id":"2209.07858","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-12T01:32:45.315412Z","id":"c33b612e-12a1-4462-a590-08d1e45d31c6","model_set":{"reader":"grok-4.3"},"one_line_summary":"RLHF-aligned language models show increasing resistance to red teaming with scale up to 52B parameters, unlike prompted or rejection-sampled models, supported by a released dataset of 38,961 attacks.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"RLHF-trained language models become progressively harder to red-team into harmful outputs as they scale up in size, while other training approaches show no such improvement.","strongest_claim":"We find that the RLHF models are increasingly difficult to red team as they scale, and we find a flat trend with scale for the other model types.","weakest_assumption":"The assumption that the red team attacks used in the study are sufficient to uncover all or most potential harmful behaviors in the models, and that the model types tested are representative of current and future language models."}},"verdict_id":"c33b612e-12a1-4462-a590-08d1e45d31c6"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:694af005419ce6e28426d7931b579b0464c836983f48bce5df76e8271143aa7a","target":"record","created_at":"2026-07-05T05:18:49Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"f718d264fed58bbde4d6a6b189216990bd3531c66d26424ca18a7e760eb42066","cross_cats_sorted":["cs.AI","cs.CY"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2022-08-23T23:37:14Z","title_canon_sha256":"fd13613aaa303a30e09f7680abae66812319290fb3669a253962851d5422ba25"},"schema_version":"1.0","source":{"id":"2209.07858","kind":"arxiv","version":2}},"canonical_sha256":"89169471fb5d54850635c97f32e5a0b67b74d441d9b05509ed54bbdf98b75f9f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"89169471fb5d54850635c97f32e5a0b67b74d441d9b05509ed54bbdf98b75f9f","first_computed_at":"2026-07-05T05:18:49.618352Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T05:18:49.618352Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"yHDJoGF0WAmLLGRLmSRvR9fwUSOU8lbW88iW15FaBAlzG2YxNK3Jc+ldb6V88eo3iND53+muX4on3WySrFruAA==","signature_status":"signed_v1","signed_at":"2026-07-05T05:18:49.618938Z","signed_message":"canonical_sha256_bytes"},"source_id":"2209.07858","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:694af005419ce6e28426d7931b579b0464c836983f48bce5df76e8271143aa7a","sha256:a1281fba89446d48c9a61c46eaea4a323eacee61f6697db5bb4320862cf9c11f"],"state_sha256":"07cec22dadc3335ccfad253cfb66aaf3777384676553de885f7ef6cc92bd462d"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"REte+KofcHumbGSC/L76sCDUIZYjVnzxVAGa+Tmj/LsKO1JrgVAGRrTlKvskQu31iPBh8HW1dvlO0a7PEsdZBw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-17T19:57:41.591555Z","bundle_sha256":"8aac263bdd4abe2e0f1b02833617e19aa3fa827976a96855eb84ac5d490db086"}}