{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:RJ6TBSBTVIDGOLFZGC6EPHQQTR","short_pith_number":"pith:RJ6TBSBT","schema_version":"1.0","canonical_sha256":"8a7d30c833aa06672cb930bc479e109c658dd233f4612d3f85f02566f8423cb9","source":{"kind":"arxiv","id":"2507.16773","version":1},"attestation_state":"computed","paper":{"title":"When LLMs Copy to Think: Uncovering Copy-Guided Attacks in Reasoning LLMs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Fengyuan Xu, Hao Wu, Sheng Zhong, Xiao Li, Xiuzhen Cheng, Yue Li, Yue Zhang","submitted_at":"2025-07-22T17:21:36Z","abstract_excerpt":"Large Language Models (LLMs) have become integral to automated code analysis, enabling tasks such as vulnerability detection and code comprehension. However, their integration introduces novel attack surfaces. In this paper, we identify and investigate a new class of prompt-based attacks, termed Copy-Guided Attacks (CGA), which exploit the inherent copying tendencies of reasoning-capable LLMs. By injecting carefully crafted triggers into external code snippets, adversaries can induce the model to replicate malicious content during inference. This behavior enables two classes of vulnerabilities"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2507.16773","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-07-22T17:21:36Z","cross_cats_sorted":[],"title_canon_sha256":"55c6c09df0785badd262e2a69b40fe5a0a34e957a982ccc48c644480f209d003","abstract_canon_sha256":"0bcac93607b12e8725ab0a6f08d7c49e6e1bd8c17f10cf4afc58304bef6b5616"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:41:30.861204Z","signature_b64":"Cbt9/t1W/LGpgi85khyrj8dFB1wSoQqV5xIpehJhaF20XOZvm4tw7JElYaLVWfbyhCbfCPOn8HtG2fD66N8ACg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8a7d30c833aa06672cb930bc479e109c658dd233f4612d3f85f02566f8423cb9","last_reissued_at":"2026-07-05T11:41:30.860701Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:41:30.860701Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"When LLMs Copy to Think: Uncovering Copy-Guided Attacks in Reasoning LLMs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Fengyuan Xu, Hao Wu, Sheng Zhong, Xiao Li, Xiuzhen Cheng, Yue Li, Yue Zhang","submitted_at":"2025-07-22T17:21:36Z","abstract_excerpt":"Large Language Models (LLMs) have become integral to automated code analysis, enabling tasks such as vulnerability detection and code comprehension. However, their integration introduces novel attack surfaces. In this paper, we identify and investigate a new class of prompt-based attacks, termed Copy-Guided Attacks (CGA), which exploit the inherent copying tendencies of reasoning-capable LLMs. By injecting carefully crafted triggers into external code snippets, adversaries can induce the model to replicate malicious content during inference. This behavior enables two classes of vulnerabilities"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2507.16773","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2507.16773/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2507.16773","created_at":"2026-07-05T11:41:30.860765+00:00"},{"alias_kind":"arxiv_version","alias_value":"2507.16773v1","created_at":"2026-07-05T11:41:30.860765+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2507.16773","created_at":"2026-07-05T11:41:30.860765+00:00"},{"alias_kind":"pith_short_12","alias_value":"RJ6TBSBTVIDG","created_at":"2026-07-05T11:41:30.860765+00:00"},{"alias_kind":"pith_short_16","alias_value":"RJ6TBSBTVIDGOLFZ","created_at":"2026-07-05T11:41:30.860765+00:00"},{"alias_kind":"pith_short_8","alias_value":"RJ6TBSBT","created_at":"2026-07-05T11:41:30.860765+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2508.19277","citing_title":"POT: Inducing Overthinking in LLMs via Black-Box Iterative Optimization","ref_index":15,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/RJ6TBSBTVIDGOLFZGC6EPHQQTR","json":"https://pith.science/pith/RJ6TBSBTVIDGOLFZGC6EPHQQTR.json","graph_json":"https://pith.science/api/pith-number/RJ6TBSBTVIDGOLFZGC6EPHQQTR/graph.json","events_json":"https://pith.science/api/pith-number/RJ6TBSBTVIDGOLFZGC6EPHQQTR/events.json","paper":"https://pith.science/paper/RJ6TBSBT"},"agent_actions":{"view_html":"https://pith.science/pith/RJ6TBSBTVIDGOLFZGC6EPHQQTR","download_json":"https://pith.science/pith/RJ6TBSBTVIDGOLFZGC6EPHQQTR.json","view_paper":"https://pith.science/paper/RJ6TBSBT","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2507.16773&json=true","fetch_graph":"https://pith.science/api/pith-number/RJ6TBSBTVIDGOLFZGC6EPHQQTR/graph.json","fetch_events":"https://pith.science/api/pith-number/RJ6TBSBTVIDGOLFZGC6EPHQQTR/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/RJ6TBSBTVIDGOLFZGC6EPHQQTR/action/timestamp_anchor","attest_storage":"https://pith.science/pith/RJ6TBSBTVIDGOLFZGC6EPHQQTR/action/storage_attestation","attest_author":"https://pith.science/pith/RJ6TBSBTVIDGOLFZGC6EPHQQTR/action/author_attestation","sign_citation":"https://pith.science/pith/RJ6TBSBTVIDGOLFZGC6EPHQQTR/action/citation_signature","submit_replication":"https://pith.science/pith/RJ6TBSBTVIDGOLFZGC6EPHQQTR/action/replication_record"}},"created_at":"2026-07-05T11:41:30.860765+00:00","updated_at":"2026-07-05T11:41:30.860765+00:00"}