{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:SIIS4EXSYAL3ZIFIZL7XEHLB4S","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"11b007bbc89fa663085045dc393e30617b7e1507b5efc5c60d2c3b5de74c06d0","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-29T13:11:49Z","title_canon_sha256":"c713901e05320d69176760d8ec7da8d14f23a60536ce57118939c50d8c654bce"},"schema_version":"1.0","source":{"id":"2606.30263","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.30263","created_at":"2026-06-30T02:17:56Z"},{"alias_kind":"arxiv_version","alias_value":"2606.30263v1","created_at":"2026-06-30T02:17:56Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.30263","created_at":"2026-06-30T02:17:56Z"},{"alias_kind":"pith_short_12","alias_value":"SIIS4EXSYAL3","created_at":"2026-06-30T02:17:56Z"},{"alias_kind":"pith_short_16","alias_value":"SIIS4EXSYAL3ZIFI","created_at":"2026-06-30T02:17:56Z"},{"alias_kind":"pith_short_8","alias_value":"SIIS4EXS","created_at":"2026-06-30T02:17:56Z"}],"graph_snapshots":[{"event_id":"sha256:a8f523cfdce11fb9d9432bcc7b321a990e53d734cb98abb3278886f98248f1ce","target":"graph","created_at":"2026-06-30T02:17:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.30263/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Existing defenses are effective when harmful content is explicitly mixed into downstream fine-tuning data, but crafted samples can instead hide harmful supervision inside benign tasks. We propose Embedded Attack, where harmful QA pairs are embedded within benign training samples, and show that representative guardrails often fail to detect them at the example level. To address this, we propose Dual-Reference SFT (DR-SFT), which adapts DPO-style contrastive objective design to SFT through token-level regularization, mitigating harmful fine-tuning beyond coarse data filtering.","authors_text":"Bang An, Bernard Ghanem, Carlos Hinojosa, Dandan Guo, Ebtisam Alshehri, Yibo Yang","cross_cats":["cs.AI"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-29T13:11:49Z","title":"Defending Against Harmful Supervision Hidden in Benign Samples"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.30263","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:b7a36f6b1fc7ac01b2303e685fc1aebff36703dddbbf5e550d6d10f792a3687c","target":"record","created_at":"2026-06-30T02:17:56Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"11b007bbc89fa663085045dc393e30617b7e1507b5efc5c60d2c3b5de74c06d0","cross_cats_sorted":["cs.AI"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-29T13:11:49Z","title_canon_sha256":"c713901e05320d69176760d8ec7da8d14f23a60536ce57118939c50d8c654bce"},"schema_version":"1.0","source":{"id":"2606.30263","kind":"arxiv","version":1}},"canonical_sha256":"92112e12f2c017bca0a8caff721d61e48b574e07b438b80fe31bcc36cea93184","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"92112e12f2c017bca0a8caff721d61e48b574e07b438b80fe31bcc36cea93184","first_computed_at":"2026-06-30T02:17:56.649141Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-30T02:17:56.649141Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"mHtp5d+CoQCPFBI5zxv6pwktLu7xgTTkF1o4G/jctzr7CtUAA6uzVM2dOXfL5DEJFFdptIGqcVCL3dgT3h8KDg==","signature_status":"signed_v1","signed_at":"2026-06-30T02:17:56.649649Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.30263","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:b7a36f6b1fc7ac01b2303e685fc1aebff36703dddbbf5e550d6d10f792a3687c","sha256:a8f523cfdce11fb9d9432bcc7b321a990e53d734cb98abb3278886f98248f1ce"],"state_sha256":"4d4020c8826b4f317d63d601e3bdcaa5504fa245c1562325f121fc4747247a9a"}