{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2024:T43GPEVXZNJ4G7NM75TGDBXNCB","short_pith_number":"pith:T43GPEVX","canonical_record":{"source":{"id":"2407.20242","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CY","submitted_at":"2024-07-16T13:13:16Z","cross_cats_sorted":["cs.AI","cs.RO"],"title_canon_sha256":"d83cc39178c88552c205074c2406b2c2c3ea4e5d41e5bc6a930a87916ad59116","abstract_canon_sha256":"43a7fcbc721bea40277258cf388a75cf538ec2550ca9e61874cc104568e32e44"},"schema_version":"1.0"},"canonical_sha256":"9f366792b7cb53c37dacff666186ed106158a851f380b6cd60afa38eb86971aa","source":{"kind":"arxiv","id":"2407.20242","version":5},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2407.20242","created_at":"2026-06-10T01:09:12Z"},{"alias_kind":"arxiv_version","alias_value":"2407.20242v5","created_at":"2026-06-10T01:09:12Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2407.20242","created_at":"2026-06-10T01:09:12Z"},{"alias_kind":"pith_short_12","alias_value":"T43GPEVXZNJ4","created_at":"2026-06-10T01:09:12Z"},{"alias_kind":"pith_short_16","alias_value":"T43GPEVXZNJ4G7NM","created_at":"2026-06-10T01:09:12Z"},{"alias_kind":"pith_short_8","alias_value":"T43GPEVX","created_at":"2026-06-10T01:09:12Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2024:T43GPEVXZNJ4G7NM75TGDBXNCB","target":"record","payload":{"canonical_record":{"source":{"id":"2407.20242","kind":"arxiv","version":5},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CY","submitted_at":"2024-07-16T13:13:16Z","cross_cats_sorted":["cs.AI","cs.RO"],"title_canon_sha256":"d83cc39178c88552c205074c2406b2c2c3ea4e5d41e5bc6a930a87916ad59116","abstract_canon_sha256":"43a7fcbc721bea40277258cf388a75cf538ec2550ca9e61874cc104568e32e44"},"schema_version":"1.0"},"canonical_sha256":"9f366792b7cb53c37dacff666186ed106158a851f380b6cd60afa38eb86971aa","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-10T01:09:12.445370Z","signature_b64":"Yumoqq6JzLuIxbwH6IUtpY7DVa/3rwlm824FuBKwvvXBDf4wvERWVGZ66FK+jSKtsCh/jzTjcyU5Fgb9X5BpAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9f366792b7cb53c37dacff666186ed106158a851f380b6cd60afa38eb86971aa","last_reissued_at":"2026-06-10T01:09:12.444205Z","signature_status":"signed_v1","first_computed_at":"2026-06-10T01:09:12.444205Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2407.20242","source_version":5,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-10T01:09:12Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"0KnB9vNaLMCTRR8XpEI48aiJcKSh0ttQJ/zX+dUCToh2ljgQR9i57mwAJS9NMDH1lkdeuVmoOE0P4B1C2tRxBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T10:58:53.976849Z"},"content_sha256":"8eda5c1eb4f795ef1c8599ddb56cef50853d489bc81dfad092d8bde88c864371","schema_version":"1.0","event_id":"sha256:8eda5c1eb4f795ef1c8599ddb56cef50853d489bc81dfad092d8bde88c864371"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2024:T43GPEVXZNJ4G7NM75TGDBXNCB","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"BadRobot: Jailbreaking Embodied LLM Agents in the Physical World","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.RO"],"primary_cat":"cs.CY","authors_text":"Aishan Liu, Changgan Yin, Chenyu Zhu, Hangtao Zhang, Leo Yu Zhang, Lulu Xue, Minghui Li, Peijin Guo, Shengshan Hu, Xianlong Wang, Yichen Wang, Ziqi Zhou","submitted_at":"2024-07-16T13:13:16Z","abstract_excerpt":"Embodied AI represents systems where AI is integrated into physical entities. Large Language Model (LLM), which exhibits powerful language understanding abilities, has been extensively employed in embodied AI by facilitating sophisticated task planning. However, a critical safety issue remains overlooked: could these embodied LLMs perpetrate harmful behaviors? In response, we introduce BadRobot, a novel attack paradigm aiming to make embodied LLMs violate safety and ethical constraints through typical voice-based user-system interactions. Specifically, three vulnerabilities are exploited to ac"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2407.20242","kind":"arxiv","version":5},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2407.20242/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-10T01:09:12Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"vesvGjgAOJZS+K38IS7pLgRQcdPhXNMhRJ/Fzk+Qqt9LfPTLonJyUaowQR3PrY5JJLgQfXwp3Ix13NuYjdKKDA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T10:58:53.977590Z"},"content_sha256":"dfc60db3c602876f0013589881f010b80b27978111052567b69b20b458cbfa71","schema_version":"1.0","event_id":"sha256:dfc60db3c602876f0013589881f010b80b27978111052567b69b20b458cbfa71"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/T43GPEVXZNJ4G7NM75TGDBXNCB/bundle.json","state_url":"https://pith.science/pith/T43GPEVXZNJ4G7NM75TGDBXNCB/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/T43GPEVXZNJ4G7NM75TGDBXNCB/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-10T10:58:53Z","links":{"resolver":"https://pith.science/pith/T43GPEVXZNJ4G7NM75TGDBXNCB","bundle":"https://pith.science/pith/T43GPEVXZNJ4G7NM75TGDBXNCB/bundle.json","state":"https://pith.science/pith/T43GPEVXZNJ4G7NM75TGDBXNCB/state.json","well_known_bundle":"https://pith.science/.well-known/pith/T43GPEVXZNJ4G7NM75TGDBXNCB/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2024:T43GPEVXZNJ4G7NM75TGDBXNCB","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"43a7fcbc721bea40277258cf388a75cf538ec2550ca9e61874cc104568e32e44","cross_cats_sorted":["cs.AI","cs.RO"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CY","submitted_at":"2024-07-16T13:13:16Z","title_canon_sha256":"d83cc39178c88552c205074c2406b2c2c3ea4e5d41e5bc6a930a87916ad59116"},"schema_version":"1.0","source":{"id":"2407.20242","kind":"arxiv","version":5}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2407.20242","created_at":"2026-06-10T01:09:12Z"},{"alias_kind":"arxiv_version","alias_value":"2407.20242v5","created_at":"2026-06-10T01:09:12Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2407.20242","created_at":"2026-06-10T01:09:12Z"},{"alias_kind":"pith_short_12","alias_value":"T43GPEVXZNJ4","created_at":"2026-06-10T01:09:12Z"},{"alias_kind":"pith_short_16","alias_value":"T43GPEVXZNJ4G7NM","created_at":"2026-06-10T01:09:12Z"},{"alias_kind":"pith_short_8","alias_value":"T43GPEVX","created_at":"2026-06-10T01:09:12Z"}],"graph_snapshots":[{"event_id":"sha256:dfc60db3c602876f0013589881f010b80b27978111052567b69b20b458cbfa71","target":"graph","created_at":"2026-06-10T01:09:12Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2407.20242/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Embodied AI represents systems where AI is integrated into physical entities. Large Language Model (LLM), which exhibits powerful language understanding abilities, has been extensively employed in embodied AI by facilitating sophisticated task planning. However, a critical safety issue remains overlooked: could these embodied LLMs perpetrate harmful behaviors? In response, we introduce BadRobot, a novel attack paradigm aiming to make embodied LLMs violate safety and ethical constraints through typical voice-based user-system interactions. Specifically, three vulnerabilities are exploited to ac","authors_text":"Aishan Liu, Changgan Yin, Chenyu Zhu, Hangtao Zhang, Leo Yu Zhang, Lulu Xue, Minghui Li, Peijin Guo, Shengshan Hu, Xianlong Wang, Yichen Wang, Ziqi Zhou","cross_cats":["cs.AI","cs.RO"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CY","submitted_at":"2024-07-16T13:13:16Z","title":"BadRobot: Jailbreaking Embodied LLM Agents in the Physical World"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2407.20242","kind":"arxiv","version":5},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8eda5c1eb4f795ef1c8599ddb56cef50853d489bc81dfad092d8bde88c864371","target":"record","created_at":"2026-06-10T01:09:12Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"43a7fcbc721bea40277258cf388a75cf538ec2550ca9e61874cc104568e32e44","cross_cats_sorted":["cs.AI","cs.RO"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CY","submitted_at":"2024-07-16T13:13:16Z","title_canon_sha256":"d83cc39178c88552c205074c2406b2c2c3ea4e5d41e5bc6a930a87916ad59116"},"schema_version":"1.0","source":{"id":"2407.20242","kind":"arxiv","version":5}},"canonical_sha256":"9f366792b7cb53c37dacff666186ed106158a851f380b6cd60afa38eb86971aa","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"9f366792b7cb53c37dacff666186ed106158a851f380b6cd60afa38eb86971aa","first_computed_at":"2026-06-10T01:09:12.444205Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-10T01:09:12.444205Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"Yumoqq6JzLuIxbwH6IUtpY7DVa/3rwlm824FuBKwvvXBDf4wvERWVGZ66FK+jSKtsCh/jzTjcyU5Fgb9X5BpAQ==","signature_status":"signed_v1","signed_at":"2026-06-10T01:09:12.445370Z","signed_message":"canonical_sha256_bytes"},"source_id":"2407.20242","source_kind":"arxiv","source_version":5}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8eda5c1eb4f795ef1c8599ddb56cef50853d489bc81dfad092d8bde88c864371","sha256:dfc60db3c602876f0013589881f010b80b27978111052567b69b20b458cbfa71"],"state_sha256":"b9a41cd32af6893603fddf9cfdc4792b725b318e09b6f55de061fafc836c7324"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"aHqNP9uNj5fS37hIO7zAk5psZb8IrTRQLDTywSOpTjfn6qZrUIyYk/FULKHHh3M4t+aMyj5p/JrzwJeuccF5Aw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-10T10:58:53.981992Z","bundle_sha256":"848c1186c775da0bb243b8e9320ee80b22633ec8c12244b3157f5e70bd4fce6f"}}