{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:SHCN667RE4TW5KECA2PMYL7FNR","short_pith_number":"pith:SHCN667R","canonical_record":{"source":{"id":"2604.17860","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-04-20T06:12:51Z","cross_cats_sorted":[],"title_canon_sha256":"318a2e430d0e48c10e9fd7170975a1d091df76e240fce759f5f6fd17a7694a3f","abstract_canon_sha256":"7cf74a98c967aa3f1dc3d066f9c6385fbab062b6de8a109dc5e8b6f96e136294"},"schema_version":"1.0"},"canonical_sha256":"91c4df7bf127276ea882069ecc2fe56c7fc842f38e2996e57fbfebc3d36e7121","source":{"kind":"arxiv","id":"2604.17860","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2604.17860","created_at":"2026-06-03T01:05:13Z"},{"alias_kind":"arxiv_version","alias_value":"2604.17860v2","created_at":"2026-06-03T01:05:13Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2604.17860","created_at":"2026-06-03T01:05:13Z"},{"alias_kind":"pith_short_12","alias_value":"SHCN667RE4TW","created_at":"2026-06-03T01:05:13Z"},{"alias_kind":"pith_short_16","alias_value":"SHCN667RE4TW5KEC","created_at":"2026-06-03T01:05:13Z"},{"alias_kind":"pith_short_8","alias_value":"SHCN667R","created_at":"2026-06-03T01:05:13Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:SHCN667RE4TW5KECA2PMYL7FNR","target":"record","payload":{"canonical_record":{"source":{"id":"2604.17860","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-04-20T06:12:51Z","cross_cats_sorted":[],"title_canon_sha256":"318a2e430d0e48c10e9fd7170975a1d091df76e240fce759f5f6fd17a7694a3f","abstract_canon_sha256":"7cf74a98c967aa3f1dc3d066f9c6385fbab062b6de8a109dc5e8b6f96e136294"},"schema_version":"1.0"},"canonical_sha256":"91c4df7bf127276ea882069ecc2fe56c7fc842f38e2996e57fbfebc3d36e7121","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-03T01:05:13.879122Z","signature_b64":"WyJKrzCs1Pc8GOCA3Jee1OAa7Y9gSmh7edD7RtgADl3RVXb5jnU7fwVbV0qONr3jusUAt7awl5l1AIqKkyFfAw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"91c4df7bf127276ea882069ecc2fe56c7fc842f38e2996e57fbfebc3d36e7121","last_reissued_at":"2026-06-03T01:05:13.878722Z","signature_status":"signed_v1","first_computed_at":"2026-06-03T01:05:13.878722Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2604.17860","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:13Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"1flVGJ4/W0ZSzXBKE3nMMRCxidOmJmsfFX3jHxzfu8ASf4WVlTuF4gYvjcc97GnziCK8qRkzz5pXBUHWXl50CA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-04T09:42:05.664532Z"},"content_sha256":"5fcad033b2e25e99a4dc2e7c625fbb9c94e16f29f2ab60e1decb601b0ecd68a6","schema_version":"1.0","event_id":"sha256:5fcad033b2e25e99a4dc2e7c625fbb9c94e16f29f2ab60e1decb601b0ecd68a6"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:SHCN667RE4TW5KECA2PMYL7FNR","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"TitanCA: Lessons from Orchestrating LLM Agents to Discover 100+ CVEs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"An orchestrated team of LLM agents discovers 203 zero-day vulnerabilities and yields 118 CVEs in open-source code.","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Chengran Yang, David Lo, Eng Lieh Ouh, Hong Jin Kang, Huihui Huang, Huu Hung Nguyen, Ivana Clairine Irsan, Jinfeng Jiang, Lwin Khin Shar, Ngoc Tan Bui, Phuc Thanh Nguyen, Ratnadira Widyasari, Ting Zhang, Wen Bin Leow, Yan Naing Tun, Yide Yin, Yikun Li, Yue Liu","submitted_at":"2026-04-20T06:12:51Z","abstract_excerpt":"Software vulnerabilities remain one of the most persistent threats to modern digital infrastructure. While static application security testing (SAST) tools have long served as the first line of defense, they suffer from high false-positive rates. This article presents TitanCA, a collaborative project between Singapore Management University and GovTech Singapore that orchestrates multiple large language model (LLM)-powered agents into a unified vulnerability discovery pipeline. Applied in open-source software, TitanCA has discovered 203 confirmed zero-day vulnerabilities and yielded 118 CVEs. W"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"Applied in open-source software, TitanCA has discovered 203 confirmed zero-day vulnerabilities and yielded 118 CVEs.","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"That the vulnerabilities flagged by the LLM pipeline are independently verifiable as true zero-days with low false-positive rates and that the four-module orchestration generalizes beyond the specific projects tested.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"TitanCA's LLM agent pipeline discovered 203 confirmed zero-day vulnerabilities and produced 118 CVEs in open-source software.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"An orchestrated team of LLM agents discovers 203 zero-day vulnerabilities and yields 118 CVEs in open-source code.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"277abab8edef83fe57558638212622eced3e4e99c0a81357bbae39966d171309"},"source":{"id":"2604.17860","kind":"arxiv","version":2},"verdict":{"id":"61bdc6c6-948a-4e79-858c-2f88f4ced31a","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-10T04:44:02.880136Z","strongest_claim":"Applied in open-source software, TitanCA has discovered 203 confirmed zero-day vulnerabilities and yielded 118 CVEs.","one_line_summary":"TitanCA's LLM agent pipeline discovered 203 confirmed zero-day vulnerabilities and produced 118 CVEs in open-source software.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"That the vulnerabilities flagged by the LLM pipeline are independently verifiable as true zero-days with low false-positive rates and that the four-module orchestration generalizes beyond the specific projects tested.","pith_extraction_headline":"An orchestrated team of LLM agents discovers 203 zero-day vulnerabilities and yields 118 CVEs in open-source code."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2604.17860/integrity.json","findings":[],"available":true,"detectors_run":[{"name":"doi_compliance","ran_at":"2026-05-20T04:41:27.248874Z","status":"completed","version":"1.0.0","findings_count":0}],"snapshot_sha256":"ed33307a3d13a2c0273bbbfaffb60785968af88808fc93f77a2ace4a39af2edc"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"61bdc6c6-948a-4e79-858c-2f88f4ced31a"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:13Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"RQik0NVt27jg8WOkz2NKt8nf0Tp/6se0TNWoNjkXgZLm7xA+ubfEssUYCopsyR/cht0r4IPdpBJhTheJ/qABDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-04T09:42:05.665227Z"},"content_sha256":"ee0b87f41774cd46f3fbe42c7522ea6fcabd733883997588da248aa8c1e8f5a7","schema_version":"1.0","event_id":"sha256:ee0b87f41774cd46f3fbe42c7522ea6fcabd733883997588da248aa8c1e8f5a7"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/SHCN667RE4TW5KECA2PMYL7FNR/bundle.json","state_url":"https://pith.science/pith/SHCN667RE4TW5KECA2PMYL7FNR/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/SHCN667RE4TW5KECA2PMYL7FNR/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-04T09:42:05Z","links":{"resolver":"https://pith.science/pith/SHCN667RE4TW5KECA2PMYL7FNR","bundle":"https://pith.science/pith/SHCN667RE4TW5KECA2PMYL7FNR/bundle.json","state":"https://pith.science/pith/SHCN667RE4TW5KECA2PMYL7FNR/state.json","well_known_bundle":"https://pith.science/.well-known/pith/SHCN667RE4TW5KECA2PMYL7FNR/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:SHCN667RE4TW5KECA2PMYL7FNR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"7cf74a98c967aa3f1dc3d066f9c6385fbab062b6de8a109dc5e8b6f96e136294","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-04-20T06:12:51Z","title_canon_sha256":"318a2e430d0e48c10e9fd7170975a1d091df76e240fce759f5f6fd17a7694a3f"},"schema_version":"1.0","source":{"id":"2604.17860","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2604.17860","created_at":"2026-06-03T01:05:13Z"},{"alias_kind":"arxiv_version","alias_value":"2604.17860v2","created_at":"2026-06-03T01:05:13Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2604.17860","created_at":"2026-06-03T01:05:13Z"},{"alias_kind":"pith_short_12","alias_value":"SHCN667RE4TW","created_at":"2026-06-03T01:05:13Z"},{"alias_kind":"pith_short_16","alias_value":"SHCN667RE4TW5KEC","created_at":"2026-06-03T01:05:13Z"},{"alias_kind":"pith_short_8","alias_value":"SHCN667R","created_at":"2026-06-03T01:05:13Z"}],"graph_snapshots":[{"event_id":"sha256:ee0b87f41774cd46f3fbe42c7522ea6fcabd733883997588da248aa8c1e8f5a7","target":"graph","created_at":"2026-06-03T01:05:13Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"Applied in open-source software, TitanCA has discovered 203 confirmed zero-day vulnerabilities and yielded 118 CVEs."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"That the vulnerabilities flagged by the LLM pipeline are independently verifiable as true zero-days with low false-positive rates and that the four-module orchestration generalizes beyond the specific projects tested."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"TitanCA's LLM agent pipeline discovered 203 confirmed zero-day vulnerabilities and produced 118 CVEs in open-source software."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"An orchestrated team of LLM agents discovers 203 zero-day vulnerabilities and yields 118 CVEs in open-source code."}],"snapshot_sha256":"277abab8edef83fe57558638212622eced3e4e99c0a81357bbae39966d171309"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"doi_compliance","ran_at":"2026-05-20T04:41:27.248874Z","status":"completed","version":"1.0.0"}],"endpoint":"/pith/2604.17860/integrity.json","findings":[],"snapshot_sha256":"ed33307a3d13a2c0273bbbfaffb60785968af88808fc93f77a2ace4a39af2edc","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Software vulnerabilities remain one of the most persistent threats to modern digital infrastructure. While static application security testing (SAST) tools have long served as the first line of defense, they suffer from high false-positive rates. This article presents TitanCA, a collaborative project between Singapore Management University and GovTech Singapore that orchestrates multiple large language model (LLM)-powered agents into a unified vulnerability discovery pipeline. Applied in open-source software, TitanCA has discovered 203 confirmed zero-day vulnerabilities and yielded 118 CVEs. W","authors_text":"Chengran Yang, David Lo, Eng Lieh Ouh, Hong Jin Kang, Huihui Huang, Huu Hung Nguyen, Ivana Clairine Irsan, Jinfeng Jiang, Lwin Khin Shar, Ngoc Tan Bui, Phuc Thanh Nguyen, Ratnadira Widyasari, Ting Zhang, Wen Bin Leow, Yan Naing Tun, Yide Yin, Yikun Li, Yue Liu","cross_cats":[],"headline":"An orchestrated team of LLM agents discovers 203 zero-day vulnerabilities and yields 118 CVEs in open-source code.","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-04-20T06:12:51Z","title":"TitanCA: Lessons from Orchestrating LLM Agents to Discover 100+ CVEs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2604.17860","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-10T04:44:02.880136Z","id":"61bdc6c6-948a-4e79-858c-2f88f4ced31a","model_set":{"reader":"grok-4.3"},"one_line_summary":"TitanCA's LLM agent pipeline discovered 203 confirmed zero-day vulnerabilities and produced 118 CVEs in open-source software.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"An orchestrated team of LLM agents discovers 203 zero-day vulnerabilities and yields 118 CVEs in open-source code.","strongest_claim":"Applied in open-source software, TitanCA has discovered 203 confirmed zero-day vulnerabilities and yielded 118 CVEs.","weakest_assumption":"That the vulnerabilities flagged by the LLM pipeline are independently verifiable as true zero-days with low false-positive rates and that the four-module orchestration generalizes beyond the specific projects tested."}},"verdict_id":"61bdc6c6-948a-4e79-858c-2f88f4ced31a"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:5fcad033b2e25e99a4dc2e7c625fbb9c94e16f29f2ab60e1decb601b0ecd68a6","target":"record","created_at":"2026-06-03T01:05:13Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"7cf74a98c967aa3f1dc3d066f9c6385fbab062b6de8a109dc5e8b6f96e136294","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-04-20T06:12:51Z","title_canon_sha256":"318a2e430d0e48c10e9fd7170975a1d091df76e240fce759f5f6fd17a7694a3f"},"schema_version":"1.0","source":{"id":"2604.17860","kind":"arxiv","version":2}},"canonical_sha256":"91c4df7bf127276ea882069ecc2fe56c7fc842f38e2996e57fbfebc3d36e7121","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"91c4df7bf127276ea882069ecc2fe56c7fc842f38e2996e57fbfebc3d36e7121","first_computed_at":"2026-06-03T01:05:13.878722Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-03T01:05:13.878722Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"WyJKrzCs1Pc8GOCA3Jee1OAa7Y9gSmh7edD7RtgADl3RVXb5jnU7fwVbV0qONr3jusUAt7awl5l1AIqKkyFfAw==","signature_status":"signed_v1","signed_at":"2026-06-03T01:05:13.879122Z","signed_message":"canonical_sha256_bytes"},"source_id":"2604.17860","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:5fcad033b2e25e99a4dc2e7c625fbb9c94e16f29f2ab60e1decb601b0ecd68a6","sha256:ee0b87f41774cd46f3fbe42c7522ea6fcabd733883997588da248aa8c1e8f5a7"],"state_sha256":"8ea9d6eaaab7456ee46483555591aa3d49781ffaaf6e412cc667557b59bdaa30"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hRNsDUTI32tMmpnp/xQllcTJmvCfX7pwTVD2HMaiDG/NBQa2R5uMl+aYekLXPhwo20G5A+YOQl5GC6WGhCfiCQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-04T09:42:05.669169Z","bundle_sha256":"bd4171eb2141cc9bb8939332a1e6dc91f548710f8a32584e5eaa60eb04052e01"}}