{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:RNYL6M3OQRPWVUS2VM2DGD5CXM","short_pith_number":"pith:RNYL6M3O","canonical_record":{"source":{"id":"2604.01039","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-04-01T15:45:56Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"f401da0bf2f5b6d3c60815c926c031e2c5cef62506dc59d46eb2343842ec8dba","abstract_canon_sha256":"2e4004a6cd984baa88e68699e5e97432af8ad3b92ad844c56d9e4cb30400bcf3"},"schema_version":"1.0"},"canonical_sha256":"8b70bf336e845f6ad25aab34330fa2bb25c39090f1a4b3f2fca14a1fdf6ed38b","source":{"kind":"arxiv","id":"2604.01039","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2604.01039","created_at":"2026-06-09T01:04:42Z"},{"alias_kind":"arxiv_version","alias_value":"2604.01039v2","created_at":"2026-06-09T01:04:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2604.01039","created_at":"2026-06-09T01:04:42Z"},{"alias_kind":"pith_short_12","alias_value":"RNYL6M3OQRPW","created_at":"2026-06-09T01:04:42Z"},{"alias_kind":"pith_short_16","alias_value":"RNYL6M3OQRPWVUS2","created_at":"2026-06-09T01:04:42Z"},{"alias_kind":"pith_short_8","alias_value":"RNYL6M3O","created_at":"2026-06-09T01:04:42Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:RNYL6M3OQRPWVUS2VM2DGD5CXM","target":"record","payload":{"canonical_record":{"source":{"id":"2604.01039","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-04-01T15:45:56Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"f401da0bf2f5b6d3c60815c926c031e2c5cef62506dc59d46eb2343842ec8dba","abstract_canon_sha256":"2e4004a6cd984baa88e68699e5e97432af8ad3b92ad844c56d9e4cb30400bcf3"},"schema_version":"1.0"},"canonical_sha256":"8b70bf336e845f6ad25aab34330fa2bb25c39090f1a4b3f2fca14a1fdf6ed38b","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-09T01:04:42.415706Z","signature_b64":"NLJ8l/RSflqEM7t3Tdi/roL9zKDsHJM2C/pOrAkR6IS4N1owy0zJUtDP4uT1jE2Yybw7h8Y6G3BGLvMorknJAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8b70bf336e845f6ad25aab34330fa2bb25c39090f1a4b3f2fca14a1fdf6ed38b","last_reissued_at":"2026-06-09T01:04:42.415157Z","signature_status":"signed_v1","first_computed_at":"2026-06-09T01:04:42.415157Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2604.01039","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T01:04:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/NP6IKfVmYC1B0P6PMzUkR4qXuKMSkyD5Mrz3Oljco5VFvjNKATLuAJmMyJv7fB9yb7oRebk7XduOfQBE6lLAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T18:00:36.874761Z"},"content_sha256":"46421105eced67b2c36ff173a365df9205eb0c3ead2cd645283fc8bec3bdae2d","schema_version":"1.0","event_id":"sha256:46421105eced67b2c36ff173a365df9205eb0c3ead2cd645283fc8bec3bdae2d"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:RNYL6M3OQRPWVUS2VM2DGD5CXM","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Automated Framework to Evaluate and Harden LLM System Instructions against Encoding Attacks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Anubhab Sahu, Diptisha Samanta, Reza Soosahabi","submitted_at":"2026-04-01T15:45:56Z","abstract_excerpt":"System Instructions in Large Language Models (LLMs) are commonly used to enforce safety policies, define agent behavior, and protect sensitive operational context in agentic AI applications. These instructions may contain sensitive information such as API credentials, internal policies, and privileged workflow definitions, making system instruction leakage a critical security risk highlighted in the OWASP Top 10 for LLM Applications. Without incurring the overhead costs of reasoning models, many LLM applications rely on refusal-based instructions that block direct requests for system instructi"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2604.01039","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2604.01039/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T01:04:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Ic8jpImCqWmOQHpZZ6Df/5kTcyJ/5fKcdtDFvQgJXyQ1SceZN6oHpQZVllLlpO13qJgDwywRbkVihlIrORsPBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T18:00:36.875139Z"},"content_sha256":"81c4c5a92d19f86e6ef7406ee9904b3bfcc3a98796a8f0c6704deef6a9921657","schema_version":"1.0","event_id":"sha256:81c4c5a92d19f86e6ef7406ee9904b3bfcc3a98796a8f0c6704deef6a9921657"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/RNYL6M3OQRPWVUS2VM2DGD5CXM/bundle.json","state_url":"https://pith.science/pith/RNYL6M3OQRPWVUS2VM2DGD5CXM/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/RNYL6M3OQRPWVUS2VM2DGD5CXM/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-02T18:00:36Z","links":{"resolver":"https://pith.science/pith/RNYL6M3OQRPWVUS2VM2DGD5CXM","bundle":"https://pith.science/pith/RNYL6M3OQRPWVUS2VM2DGD5CXM/bundle.json","state":"https://pith.science/pith/RNYL6M3OQRPWVUS2VM2DGD5CXM/state.json","well_known_bundle":"https://pith.science/.well-known/pith/RNYL6M3OQRPWVUS2VM2DGD5CXM/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:RNYL6M3OQRPWVUS2VM2DGD5CXM","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"2e4004a6cd984baa88e68699e5e97432af8ad3b92ad844c56d9e4cb30400bcf3","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-04-01T15:45:56Z","title_canon_sha256":"f401da0bf2f5b6d3c60815c926c031e2c5cef62506dc59d46eb2343842ec8dba"},"schema_version":"1.0","source":{"id":"2604.01039","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2604.01039","created_at":"2026-06-09T01:04:42Z"},{"alias_kind":"arxiv_version","alias_value":"2604.01039v2","created_at":"2026-06-09T01:04:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2604.01039","created_at":"2026-06-09T01:04:42Z"},{"alias_kind":"pith_short_12","alias_value":"RNYL6M3OQRPW","created_at":"2026-06-09T01:04:42Z"},{"alias_kind":"pith_short_16","alias_value":"RNYL6M3OQRPWVUS2","created_at":"2026-06-09T01:04:42Z"},{"alias_kind":"pith_short_8","alias_value":"RNYL6M3O","created_at":"2026-06-09T01:04:42Z"}],"graph_snapshots":[{"event_id":"sha256:81c4c5a92d19f86e6ef7406ee9904b3bfcc3a98796a8f0c6704deef6a9921657","target":"graph","created_at":"2026-06-09T01:04:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2604.01039/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"System Instructions in Large Language Models (LLMs) are commonly used to enforce safety policies, define agent behavior, and protect sensitive operational context in agentic AI applications. These instructions may contain sensitive information such as API credentials, internal policies, and privileged workflow definitions, making system instruction leakage a critical security risk highlighted in the OWASP Top 10 for LLM Applications. Without incurring the overhead costs of reasoning models, many LLM applications rely on refusal-based instructions that block direct requests for system instructi","authors_text":"Anubhab Sahu, Diptisha Samanta, Reza Soosahabi","cross_cats":["cs.AI"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-04-01T15:45:56Z","title":"Automated Framework to Evaluate and Harden LLM System Instructions against Encoding Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2604.01039","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:46421105eced67b2c36ff173a365df9205eb0c3ead2cd645283fc8bec3bdae2d","target":"record","created_at":"2026-06-09T01:04:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"2e4004a6cd984baa88e68699e5e97432af8ad3b92ad844c56d9e4cb30400bcf3","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-04-01T15:45:56Z","title_canon_sha256":"f401da0bf2f5b6d3c60815c926c031e2c5cef62506dc59d46eb2343842ec8dba"},"schema_version":"1.0","source":{"id":"2604.01039","kind":"arxiv","version":2}},"canonical_sha256":"8b70bf336e845f6ad25aab34330fa2bb25c39090f1a4b3f2fca14a1fdf6ed38b","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"8b70bf336e845f6ad25aab34330fa2bb25c39090f1a4b3f2fca14a1fdf6ed38b","first_computed_at":"2026-06-09T01:04:42.415157Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-09T01:04:42.415157Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"NLJ8l/RSflqEM7t3Tdi/roL9zKDsHJM2C/pOrAkR6IS4N1owy0zJUtDP4uT1jE2Yybw7h8Y6G3BGLvMorknJAg==","signature_status":"signed_v1","signed_at":"2026-06-09T01:04:42.415706Z","signed_message":"canonical_sha256_bytes"},"source_id":"2604.01039","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:46421105eced67b2c36ff173a365df9205eb0c3ead2cd645283fc8bec3bdae2d","sha256:81c4c5a92d19f86e6ef7406ee9904b3bfcc3a98796a8f0c6704deef6a9921657"],"state_sha256":"de9521f0426492b67d795174d3d3ae30bedf4e51170bf97030ed1a16be85d651"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"xdPwv4JlRmHbVHJeP5gW7D3iJsgp4AZ+Ho+g/ihrDAYcMc9WprWehdABiffVuwfCV4yKKd9Fam9jvriqFqwHBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-02T18:00:36.877108Z","bundle_sha256":"f0d08a8d78ecabe977a26c6ba4fba7539aa86f55a5a6f5f8d68883b2d0e0f21f"}}