{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:SB4OJHZNRCFRGUHO45KXE5RLSE","short_pith_number":"pith:SB4OJHZN","canonical_record":{"source":{"id":"2605.29524","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-28T07:40:24Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"ce4a8f86bcf070fc82bcef38e9c6a32cff90f46e8731e84b394d79f24b178326","abstract_canon_sha256":"4e13d411d312e91641b98f36c63523dfa66ac95107b58e9a809a3ef5d714c1e2"},"schema_version":"1.0"},"canonical_sha256":"9078e49f2d888b1350eee75572762b912957af17765733a0f63d75ee19fd3393","source":{"kind":"arxiv","id":"2605.29524","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.29524","created_at":"2026-05-29T01:05:44Z"},{"alias_kind":"arxiv_version","alias_value":"2605.29524v1","created_at":"2026-05-29T01:05:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.29524","created_at":"2026-05-29T01:05:44Z"},{"alias_kind":"pith_short_12","alias_value":"SB4OJHZNRCFR","created_at":"2026-05-29T01:05:44Z"},{"alias_kind":"pith_short_16","alias_value":"SB4OJHZNRCFRGUHO","created_at":"2026-05-29T01:05:44Z"},{"alias_kind":"pith_short_8","alias_value":"SB4OJHZN","created_at":"2026-05-29T01:05:44Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:SB4OJHZNRCFRGUHO45KXE5RLSE","target":"record","payload":{"canonical_record":{"source":{"id":"2605.29524","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-28T07:40:24Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"ce4a8f86bcf070fc82bcef38e9c6a32cff90f46e8731e84b394d79f24b178326","abstract_canon_sha256":"4e13d411d312e91641b98f36c63523dfa66ac95107b58e9a809a3ef5d714c1e2"},"schema_version":"1.0"},"canonical_sha256":"9078e49f2d888b1350eee75572762b912957af17765733a0f63d75ee19fd3393","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-29T01:05:44.998508Z","signature_b64":"+dTP7O54OM7ima/u6GIZIQw3wub8wUtpwH2xHJIuwALsGVduRZOg3KRZyWI5nJqN1Gbejp9sx56N5MP6oCnwAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9078e49f2d888b1350eee75572762b912957af17765733a0f63d75ee19fd3393","last_reissued_at":"2026-05-29T01:05:44.997604Z","signature_status":"signed_v1","first_computed_at":"2026-05-29T01:05:44.997604Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.29524","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T01:05:44Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"P7k0b3IA7Y2u6pkzAUbTaGftMtjRuGAcmouPNilddv1XfcI+wTi39Q2U91DUJrl8Mdok93n+719PAJpJPfjSBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T08:47:28.826619Z"},"content_sha256":"4ca24c37ee037d6cf9bf910fbac802a15d60dd1a1a816dc4088799b956dd4703","schema_version":"1.0","event_id":"sha256:4ca24c37ee037d6cf9bf910fbac802a15d60dd1a1a816dc4088799b956dd4703"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:SB4OJHZNRCFRGUHO45KXE5RLSE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"KBF: Knowledge Boundary as Fingerprint for Language Model and Black-Box API Auditing","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Bingyu Li, Mingxun Zhou, Yijia Fang, Yiqing Feng","submitted_at":"2026-05-28T07:40:24Z","abstract_excerpt":"Relay and reseller APIs increasingly intermediate access to large language models (LLMs), but users have no direct way to verify that a claimed endpoint is actually serving the advertised model. We introduce KBF, a low-cost black-box auditing protocol that fingerprints model APIs using stable numerical recall near the knowledge boundary. Across 16 production LLM endpoints, KBF flags all 155 economically relevant substitutions without rejecting any same-model controls, remains stable under deployment variation, detects high-separation mixed-routing attacks when only 5-10% of traffic is substitu"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.29524","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.29524/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T01:05:44Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"a3zLFVmaHvIFFpWvmRNNfB/gOEPehIq9ZxunMweltCIp70SpqKaIfaP83r1CttICA1QomcMYZuMehQp2DsNzCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-30T08:47:28.827525Z"},"content_sha256":"b6ddd205e290478d06c5f09ad2cca2c200a1f47f3383828b07f51c863aa200ac","schema_version":"1.0","event_id":"sha256:b6ddd205e290478d06c5f09ad2cca2c200a1f47f3383828b07f51c863aa200ac"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/SB4OJHZNRCFRGUHO45KXE5RLSE/bundle.json","state_url":"https://pith.science/pith/SB4OJHZNRCFRGUHO45KXE5RLSE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/SB4OJHZNRCFRGUHO45KXE5RLSE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-30T08:47:28Z","links":{"resolver":"https://pith.science/pith/SB4OJHZNRCFRGUHO45KXE5RLSE","bundle":"https://pith.science/pith/SB4OJHZNRCFRGUHO45KXE5RLSE/bundle.json","state":"https://pith.science/pith/SB4OJHZNRCFRGUHO45KXE5RLSE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/SB4OJHZNRCFRGUHO45KXE5RLSE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:SB4OJHZNRCFRGUHO45KXE5RLSE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"4e13d411d312e91641b98f36c63523dfa66ac95107b58e9a809a3ef5d714c1e2","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-28T07:40:24Z","title_canon_sha256":"ce4a8f86bcf070fc82bcef38e9c6a32cff90f46e8731e84b394d79f24b178326"},"schema_version":"1.0","source":{"id":"2605.29524","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.29524","created_at":"2026-05-29T01:05:44Z"},{"alias_kind":"arxiv_version","alias_value":"2605.29524v1","created_at":"2026-05-29T01:05:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.29524","created_at":"2026-05-29T01:05:44Z"},{"alias_kind":"pith_short_12","alias_value":"SB4OJHZNRCFR","created_at":"2026-05-29T01:05:44Z"},{"alias_kind":"pith_short_16","alias_value":"SB4OJHZNRCFRGUHO","created_at":"2026-05-29T01:05:44Z"},{"alias_kind":"pith_short_8","alias_value":"SB4OJHZN","created_at":"2026-05-29T01:05:44Z"}],"graph_snapshots":[{"event_id":"sha256:b6ddd205e290478d06c5f09ad2cca2c200a1f47f3383828b07f51c863aa200ac","target":"graph","created_at":"2026-05-29T01:05:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.29524/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Relay and reseller APIs increasingly intermediate access to large language models (LLMs), but users have no direct way to verify that a claimed endpoint is actually serving the advertised model. We introduce KBF, a low-cost black-box auditing protocol that fingerprints model APIs using stable numerical recall near the knowledge boundary. Across 16 production LLM endpoints, KBF flags all 155 economically relevant substitutions without rejecting any same-model controls, remains stable under deployment variation, detects high-separation mixed-routing attacks when only 5-10% of traffic is substitu","authors_text":"Bingyu Li, Mingxun Zhou, Yijia Fang, Yiqing Feng","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-28T07:40:24Z","title":"KBF: Knowledge Boundary as Fingerprint for Language Model and Black-Box API Auditing"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.29524","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4ca24c37ee037d6cf9bf910fbac802a15d60dd1a1a816dc4088799b956dd4703","target":"record","created_at":"2026-05-29T01:05:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"4e13d411d312e91641b98f36c63523dfa66ac95107b58e9a809a3ef5d714c1e2","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-28T07:40:24Z","title_canon_sha256":"ce4a8f86bcf070fc82bcef38e9c6a32cff90f46e8731e84b394d79f24b178326"},"schema_version":"1.0","source":{"id":"2605.29524","kind":"arxiv","version":1}},"canonical_sha256":"9078e49f2d888b1350eee75572762b912957af17765733a0f63d75ee19fd3393","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"9078e49f2d888b1350eee75572762b912957af17765733a0f63d75ee19fd3393","first_computed_at":"2026-05-29T01:05:44.997604Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-29T01:05:44.997604Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"+dTP7O54OM7ima/u6GIZIQw3wub8wUtpwH2xHJIuwALsGVduRZOg3KRZyWI5nJqN1Gbejp9sx56N5MP6oCnwAw==","signature_status":"signed_v1","signed_at":"2026-05-29T01:05:44.998508Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.29524","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4ca24c37ee037d6cf9bf910fbac802a15d60dd1a1a816dc4088799b956dd4703","sha256:b6ddd205e290478d06c5f09ad2cca2c200a1f47f3383828b07f51c863aa200ac"],"state_sha256":"daeeec6e7fd483134a092f11cc229e243f785320aa2d5d30c3d842d9d2cdea81"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hkPiPaed+tKoLJxTpn7qXkgH2rExur64Qh+SB5Jnq8RkXi/LdEeUJPIWy069jArxX+vxCmrek3cAVWis0MvHAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-30T08:47:28.831876Z","bundle_sha256":"dda6e1209b24afc4591301ed174c2b3b8f33fa2d3b91a9f2bcb10d3e94e8c763"}}