{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:SBPL22IWHQ6JYAD23SYDTBB3GU","short_pith_number":"pith:SBPL22IW","canonical_record":{"source":{"id":"2509.03122","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2025-09-03T08:22:04Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"dccd12bd4a1b992f658ec5dfbbfda648df87992bab2247057582f38b7108b986","abstract_canon_sha256":"97506761da81c24d3ed096ad21430f325b8e0714aab20d4fd4c7ef88dbe189b2"},"schema_version":"1.0"},"canonical_sha256":"905ebd69163c3c9c007adcb039843b353579c56f2ade7670aec754f4b8697dd7","source":{"kind":"arxiv","id":"2509.03122","version":4},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2509.03122","created_at":"2026-06-19T16:12:47Z"},{"alias_kind":"arxiv_version","alias_value":"2509.03122v4","created_at":"2026-06-19T16:12:47Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2509.03122","created_at":"2026-06-19T16:12:47Z"},{"alias_kind":"pith_short_12","alias_value":"SBPL22IWHQ6J","created_at":"2026-06-19T16:12:47Z"},{"alias_kind":"pith_short_16","alias_value":"SBPL22IWHQ6JYAD2","created_at":"2026-06-19T16:12:47Z"},{"alias_kind":"pith_short_8","alias_value":"SBPL22IW","created_at":"2026-06-19T16:12:47Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:SBPL22IWHQ6JYAD23SYDTBB3GU","target":"record","payload":{"canonical_record":{"source":{"id":"2509.03122","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2025-09-03T08:22:04Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"dccd12bd4a1b992f658ec5dfbbfda648df87992bab2247057582f38b7108b986","abstract_canon_sha256":"97506761da81c24d3ed096ad21430f325b8e0714aab20d4fd4c7ef88dbe189b2"},"schema_version":"1.0"},"canonical_sha256":"905ebd69163c3c9c007adcb039843b353579c56f2ade7670aec754f4b8697dd7","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-19T16:12:47.497604Z","signature_b64":"cAdrC4jQWpDY5kK6D2+0XME65QCgFTB41tV5oKLj5M/xZ/DmO3cFtER1iiRq9Be3TemvPoGCMw36j8SG0E0gCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"905ebd69163c3c9c007adcb039843b353579c56f2ade7670aec754f4b8697dd7","last_reissued_at":"2026-06-19T16:12:47.497010Z","signature_status":"signed_v1","first_computed_at":"2026-06-19T16:12:47.497010Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2509.03122","source_version":4,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:12:47Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iqSGGbQN/sdIQSc8CnaSuhhvkY6KYXBp7JgHTGOHU4fy3whmGkZCAeOkBv/BBTaZFLOc8/0+CN4GR3lBH1oFBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-24T01:48:10.281287Z"},"content_sha256":"5cc887a9aa6faac38645a06609e8d9b77335ef1bbef8411bcec407568a69cc55","schema_version":"1.0","event_id":"sha256:5cc887a9aa6faac38645a06609e8d9b77335ef1bbef8411bcec407568a69cc55"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:SBPL22IWHQ6JYAD23SYDTBB3GU","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"From Construction to Injection: Edit-Based Fingerprints for Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CL","authors_text":"Dongsheng Shi, Gerard de Melo, Linlin Wang, Xin Yi, Yongyi Cui, Yue Li","submitted_at":"2025-09-03T08:22:04Z","abstract_excerpt":"Reliable model fingerprints are essential for protecting large language models (LLMs) against unauthorized redistribution and commercial misuse. In black-box deployment, verification is hindered by defensive filtering of suspected fingerprint queries, as well as by downstream model modifications that may weaken embedded ownership evidence. These risks require fingerprints to be robust in both construction and injection. For construction, prior paradigms face an imperceptibility trade-off: natural-language fingerprints may be accidentally activated, whereas garbled fingerprints are statisticall"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2509.03122","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2509.03122/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:12:47Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"OluD0VE4Bah1jnQbo6KLAoTgl49g7J+xOJxfDUgL7zJ0122stOVex59JyY5hmOXe4bCDhXscJkwERMi9KDThBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-24T01:48:10.281677Z"},"content_sha256":"fbc7678675499a6022d95a4956651d98e005651610710a0cdb3d207a953ef283","schema_version":"1.0","event_id":"sha256:fbc7678675499a6022d95a4956651d98e005651610710a0cdb3d207a953ef283"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/SBPL22IWHQ6JYAD23SYDTBB3GU/bundle.json","state_url":"https://pith.science/pith/SBPL22IWHQ6JYAD23SYDTBB3GU/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/SBPL22IWHQ6JYAD23SYDTBB3GU/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-24T01:48:10Z","links":{"resolver":"https://pith.science/pith/SBPL22IWHQ6JYAD23SYDTBB3GU","bundle":"https://pith.science/pith/SBPL22IWHQ6JYAD23SYDTBB3GU/bundle.json","state":"https://pith.science/pith/SBPL22IWHQ6JYAD23SYDTBB3GU/state.json","well_known_bundle":"https://pith.science/.well-known/pith/SBPL22IWHQ6JYAD23SYDTBB3GU/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:SBPL22IWHQ6JYAD23SYDTBB3GU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"97506761da81c24d3ed096ad21430f325b8e0714aab20d4fd4c7ef88dbe189b2","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2025-09-03T08:22:04Z","title_canon_sha256":"dccd12bd4a1b992f658ec5dfbbfda648df87992bab2247057582f38b7108b986"},"schema_version":"1.0","source":{"id":"2509.03122","kind":"arxiv","version":4}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2509.03122","created_at":"2026-06-19T16:12:47Z"},{"alias_kind":"arxiv_version","alias_value":"2509.03122v4","created_at":"2026-06-19T16:12:47Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2509.03122","created_at":"2026-06-19T16:12:47Z"},{"alias_kind":"pith_short_12","alias_value":"SBPL22IWHQ6J","created_at":"2026-06-19T16:12:47Z"},{"alias_kind":"pith_short_16","alias_value":"SBPL22IWHQ6JYAD2","created_at":"2026-06-19T16:12:47Z"},{"alias_kind":"pith_short_8","alias_value":"SBPL22IW","created_at":"2026-06-19T16:12:47Z"}],"graph_snapshots":[{"event_id":"sha256:fbc7678675499a6022d95a4956651d98e005651610710a0cdb3d207a953ef283","target":"graph","created_at":"2026-06-19T16:12:47Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2509.03122/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Reliable model fingerprints are essential for protecting large language models (LLMs) against unauthorized redistribution and commercial misuse. In black-box deployment, verification is hindered by defensive filtering of suspected fingerprint queries, as well as by downstream model modifications that may weaken embedded ownership evidence. These risks require fingerprints to be robust in both construction and injection. For construction, prior paradigms face an imperceptibility trade-off: natural-language fingerprints may be accidentally activated, whereas garbled fingerprints are statisticall","authors_text":"Dongsheng Shi, Gerard de Melo, Linlin Wang, Xin Yi, Yongyi Cui, Yue Li","cross_cats":["cs.AI","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2025-09-03T08:22:04Z","title":"From Construction to Injection: Edit-Based Fingerprints for Large Language Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2509.03122","kind":"arxiv","version":4},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5cc887a9aa6faac38645a06609e8d9b77335ef1bbef8411bcec407568a69cc55","target":"record","created_at":"2026-06-19T16:12:47Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"97506761da81c24d3ed096ad21430f325b8e0714aab20d4fd4c7ef88dbe189b2","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CL","submitted_at":"2025-09-03T08:22:04Z","title_canon_sha256":"dccd12bd4a1b992f658ec5dfbbfda648df87992bab2247057582f38b7108b986"},"schema_version":"1.0","source":{"id":"2509.03122","kind":"arxiv","version":4}},"canonical_sha256":"905ebd69163c3c9c007adcb039843b353579c56f2ade7670aec754f4b8697dd7","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"905ebd69163c3c9c007adcb039843b353579c56f2ade7670aec754f4b8697dd7","first_computed_at":"2026-06-19T16:12:47.497010Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-19T16:12:47.497010Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"cAdrC4jQWpDY5kK6D2+0XME65QCgFTB41tV5oKLj5M/xZ/DmO3cFtER1iiRq9Be3TemvPoGCMw36j8SG0E0gCQ==","signature_status":"signed_v1","signed_at":"2026-06-19T16:12:47.497604Z","signed_message":"canonical_sha256_bytes"},"source_id":"2509.03122","source_kind":"arxiv","source_version":4}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:5cc887a9aa6faac38645a06609e8d9b77335ef1bbef8411bcec407568a69cc55","sha256:fbc7678675499a6022d95a4956651d98e005651610710a0cdb3d207a953ef283"],"state_sha256":"e0d088e0773fd811945e69e1d4609ce3864dcc11cc402c9339e4ed44cb70c5e0"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"h6FmSXxLuW5Y5jLm3atqP8DIppwA8S/OI45nZpwGCkJbll6mc73s0bMmhXQMVCLWd7NTcDrvX5Rxot7/RglxDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-24T01:48:10.283678Z","bundle_sha256":"329b58c4b7b3a98cc0066d88bdf2881543b6e8087f8d44686b55cc5e98601046"}}