{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:SRFBIFW74C47ZDKUNCJ3FDPJOC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"bdf16ae4d0c5e4c92ba0f65c293d1a7c5262ce947a90884b171722831a94bec0","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-26T13:58:27Z","title_canon_sha256":"5f733c52033cbb8e4eced747d9b4ed73e1a9bfdf5a24660f3401dab31e91ed5f"},"schema_version":"1.0","source":{"id":"2605.27042","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.27042","created_at":"2026-05-27T01:06:25Z"},{"alias_kind":"arxiv_version","alias_value":"2605.27042v1","created_at":"2026-05-27T01:06:25Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.27042","created_at":"2026-05-27T01:06:25Z"},{"alias_kind":"pith_short_12","alias_value":"SRFBIFW74C47","created_at":"2026-05-27T01:06:25Z"},{"alias_kind":"pith_short_16","alias_value":"SRFBIFW74C47ZDKU","created_at":"2026-05-27T01:06:25Z"},{"alias_kind":"pith_short_8","alias_value":"SRFBIFW7","created_at":"2026-05-27T01:06:25Z"}],"graph_snapshots":[{"event_id":"sha256:784fcbdd2af25836b7f09aee9d1bd020d1fff07c4e2a13c14abfbbdd1ebaf99b","target":"graph","created_at":"2026-05-27T01:06:25Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.27042/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"As AI systems gain increasing autonomy and execution capability, the number of discovered security vulnerabilities continues to rise. However, many of these vulnerabilities are not fundamentally novel, but instead reflect recurring classes of weaknesses long observed in prior computing systems. Execution-capable AI agents are effectively unbounded, self-modifying programs that interact extensively with multiple layers of the computing stack. This broad interaction surface imposes a significant security burden on developers, who must reason about and secure complex cross-layer behaviors. Prior ","authors_text":"Dhilung Kirat, Frederico Araujo, Ian Molloy, Jiyong Jang, Kevin Eykholt, Xiaokui Shu","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-26T13:58:27Z","title":"Lessons from Penetration Tests on Large-Scale Agent Systems"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.27042","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:cccbb7d4301461a4caffadf3a68f8104f089ba59f9cb18752d3c4b603b704fc6","target":"record","created_at":"2026-05-27T01:06:25Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"bdf16ae4d0c5e4c92ba0f65c293d1a7c5262ce947a90884b171722831a94bec0","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-26T13:58:27Z","title_canon_sha256":"5f733c52033cbb8e4eced747d9b4ed73e1a9bfdf5a24660f3401dab31e91ed5f"},"schema_version":"1.0","source":{"id":"2605.27042","kind":"arxiv","version":1}},"canonical_sha256":"944a1416dfe0b9fc8d546893b28de970a4d3d9cbaf5fbe14dd51b9319157a765","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"944a1416dfe0b9fc8d546893b28de970a4d3d9cbaf5fbe14dd51b9319157a765","first_computed_at":"2026-05-27T01:06:25.474309Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-27T01:06:25.474309Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"0HdpzatLbouwMG6ce4fArgt+qu/52GUysmRL8NB6S2jqFryPA+D0sDkGtf9l3hTTjqrrzi/QLz8khAxl52jhDw==","signature_status":"signed_v1","signed_at":"2026-05-27T01:06:25.474958Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.27042","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:cccbb7d4301461a4caffadf3a68f8104f089ba59f9cb18752d3c4b603b704fc6","sha256:784fcbdd2af25836b7f09aee9d1bd020d1fff07c4e2a13c14abfbbdd1ebaf99b"],"state_sha256":"3d870a4d0c4ccdcf4ffc0015bf56f21ce04d151727de990903310a4f737c2ecf"}