{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:SA5OGNDFKCDIRE6COKHBWASLKR","short_pith_number":"pith:SA5OGNDF","schema_version":"1.0","canonical_sha256":"903ae3346550868893c2728e1b024b54773e65ecfd7b37bc5123d38cc2cfb7ab","source":{"kind":"arxiv","id":"2509.07764","version":1},"attestation_state":"computed","paper":{"title":"AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Haitao Hu, Peng Chen, Yanpeng Zhao, Yuqi Chen","submitted_at":"2025-09-09T13:59:00Z","abstract_excerpt":"Large Language Models (LLMs) have been increasingly integrated into computer-use agents, which can autonomously operate tools on a user's computer to accomplish complex tasks. However, due to the inherently unstable and unpredictable nature of LLM outputs, they may issue unintended tool commands or incorrect inputs, leading to potentially harmful operations. Unlike traditional security risks stemming from insecure user prompts, tool execution results from LLM-driven decisions introduce new and unique security challenges. These vulnerabilities span across all components of a computer-use agent."},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2509.07764","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2025-09-09T13:59:00Z","cross_cats_sorted":[],"title_canon_sha256":"8abe5ff731ed4c1a256dee9d02e27fa30fa0a72cb8da657e242a09abeac39075","abstract_canon_sha256":"d532cd83965c26d0077b4e00d2d70c86272967eae17cc6bd949212beff736cf3"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T12:07:27.788691Z","signature_b64":"HxDwF1mYyzxrAZPEQGuASDx2vAiaZ+w2wDuRq9egSEu1PzCPceDtwpwMVQ//VrDOWyNtaKtv1phU99UA5CNLCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"903ae3346550868893c2728e1b024b54773e65ecfd7b37bc5123d38cc2cfb7ab","last_reissued_at":"2026-07-05T12:07:27.788188Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T12:07:27.788188Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"AgentSentinel: An End-to-End and Real-Time Security Defense Framework for Computer-Use Agents","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Haitao Hu, Peng Chen, Yanpeng Zhao, Yuqi Chen","submitted_at":"2025-09-09T13:59:00Z","abstract_excerpt":"Large Language Models (LLMs) have been increasingly integrated into computer-use agents, which can autonomously operate tools on a user's computer to accomplish complex tasks. However, due to the inherently unstable and unpredictable nature of LLM outputs, they may issue unintended tool commands or incorrect inputs, leading to potentially harmful operations. Unlike traditional security risks stemming from insecure user prompts, tool execution results from LLM-driven decisions introduce new and unique security challenges. These vulnerabilities span across all components of a computer-use agent."},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2509.07764","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2509.07764/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2509.07764","created_at":"2026-07-05T12:07:27.788244+00:00"},{"alias_kind":"arxiv_version","alias_value":"2509.07764v1","created_at":"2026-07-05T12:07:27.788244+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2509.07764","created_at":"2026-07-05T12:07:27.788244+00:00"},{"alias_kind":"pith_short_12","alias_value":"SA5OGNDFKCDI","created_at":"2026-07-05T12:07:27.788244+00:00"},{"alias_kind":"pith_short_16","alias_value":"SA5OGNDFKCDIRE6C","created_at":"2026-07-05T12:07:27.788244+00:00"},{"alias_kind":"pith_short_8","alias_value":"SA5OGNDF","created_at":"2026-07-05T12:07:27.788244+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.08147","citing_title":"Prismata: Confining Cross-Site Prompt Injection in Web Agents","ref_index":34,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/SA5OGNDFKCDIRE6COKHBWASLKR","json":"https://pith.science/pith/SA5OGNDFKCDIRE6COKHBWASLKR.json","graph_json":"https://pith.science/api/pith-number/SA5OGNDFKCDIRE6COKHBWASLKR/graph.json","events_json":"https://pith.science/api/pith-number/SA5OGNDFKCDIRE6COKHBWASLKR/events.json","paper":"https://pith.science/paper/SA5OGNDF"},"agent_actions":{"view_html":"https://pith.science/pith/SA5OGNDFKCDIRE6COKHBWASLKR","download_json":"https://pith.science/pith/SA5OGNDFKCDIRE6COKHBWASLKR.json","view_paper":"https://pith.science/paper/SA5OGNDF","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2509.07764&json=true","fetch_graph":"https://pith.science/api/pith-number/SA5OGNDFKCDIRE6COKHBWASLKR/graph.json","fetch_events":"https://pith.science/api/pith-number/SA5OGNDFKCDIRE6COKHBWASLKR/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/SA5OGNDFKCDIRE6COKHBWASLKR/action/timestamp_anchor","attest_storage":"https://pith.science/pith/SA5OGNDFKCDIRE6COKHBWASLKR/action/storage_attestation","attest_author":"https://pith.science/pith/SA5OGNDFKCDIRE6COKHBWASLKR/action/author_attestation","sign_citation":"https://pith.science/pith/SA5OGNDFKCDIRE6COKHBWASLKR/action/citation_signature","submit_replication":"https://pith.science/pith/SA5OGNDFKCDIRE6COKHBWASLKR/action/replication_record"}},"created_at":"2026-07-05T12:07:27.788244+00:00","updated_at":"2026-07-05T12:07:27.788244+00:00"}