{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:TM7SOSHDEAHCYUAGTI2ZDR7GHA","short_pith_number":"pith:TM7SOSHD","canonical_record":{"source":{"id":"2605.18672","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-18T17:13:41Z","cross_cats_sorted":[],"title_canon_sha256":"faaa9859d0b8baa9893eb43c1dd14b01c50f2c53037f22f8adc8c9c39a2141db","abstract_canon_sha256":"57057bb1539cdc8e0fa0237c4621000655a8a95e03258c790f59cbf239bb8a91"},"schema_version":"1.0"},"canonical_sha256":"9b3f2748e3200e2c50069a3591c7e63813e1abaf75a5d9893848f36442f9c5fe","source":{"kind":"arxiv","id":"2605.18672","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.18672","created_at":"2026-05-20T00:06:14Z"},{"alias_kind":"arxiv_version","alias_value":"2605.18672v1","created_at":"2026-05-20T00:06:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.18672","created_at":"2026-05-20T00:06:14Z"},{"alias_kind":"pith_short_12","alias_value":"TM7SOSHDEAHC","created_at":"2026-05-20T00:06:14Z"},{"alias_kind":"pith_short_16","alias_value":"TM7SOSHDEAHCYUAG","created_at":"2026-05-20T00:06:14Z"},{"alias_kind":"pith_short_8","alias_value":"TM7SOSHD","created_at":"2026-05-20T00:06:14Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:TM7SOSHDEAHCYUAGTI2ZDR7GHA","target":"record","payload":{"canonical_record":{"source":{"id":"2605.18672","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-18T17:13:41Z","cross_cats_sorted":[],"title_canon_sha256":"faaa9859d0b8baa9893eb43c1dd14b01c50f2c53037f22f8adc8c9c39a2141db","abstract_canon_sha256":"57057bb1539cdc8e0fa0237c4621000655a8a95e03258c790f59cbf239bb8a91"},"schema_version":"1.0"},"canonical_sha256":"9b3f2748e3200e2c50069a3591c7e63813e1abaf75a5d9893848f36442f9c5fe","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-20T00:06:14.070459Z","signature_b64":"bQ/0ZQNtjg4GHGPRmbm2tfhPQYSjJZve63sWm6WD6EEZvTK+emNO8ef/UK80CpKGiJ20F5YR4aIyVb6yFUSSAQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9b3f2748e3200e2c50069a3591c7e63813e1abaf75a5d9893848f36442f9c5fe","last_reissued_at":"2026-05-20T00:06:14.069613Z","signature_status":"signed_v1","first_computed_at":"2026-05-20T00:06:14.069613Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.18672","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:06:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"89/ou/YHCNHLzyglS7oA8iHnI8LvJLrsqId/WhCIS397aliCPecInhsuiDz1urCVIRIpNT78OLJP6maY/VbUBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-24T14:49:28.960946Z"},"content_sha256":"cf4389e51d1b0c35a941f9b9a02c9ee50f90366aaa8b7ca8647d8087d26a611b","schema_version":"1.0","event_id":"sha256:cf4389e51d1b0c35a941f9b9a02c9ee50f90366aaa8b7ca8647d8087d26a611b"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:TM7SOSHDEAHCYUAGTI2ZDR7GHA","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Position: A Three-Layer Probabilistic Assume-Guarantee Architecture Is Structurally Required for Safe LLM Agent Deployment","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.AI","authors_text":"A. Nouri, C. Wu, D. Nickovic, J. Kroger, M. Franzle, R. Roy, S.Bensalem, X. Huang, Y. Dong","submitted_at":"2026-05-18T17:13:41Z","abstract_excerpt":"This position paper argues that enforcing LLM agent safety within a single abstraction layer is not merely suboptimal but categorically insufficient for deployed LLM agents -- a structural consequence of how agent execution works, not a contingent limitation of current systems. The three dimensions that jointly constitute safe operation -- semantic intent and policy compliance, environmental validity, and dynamical feasibility -- each depend on a strictly distinct set of information that becomes available at different stages of execution. No single guardrail can certify all three. We argue tha"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.18672","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.18672/integrity.json","findings":[],"available":true,"detectors_run":[{"name":"claim_evidence","ran_at":"2026-05-20T00:01:59.132607Z","status":"completed","version":"1.0.0","findings_count":0}],"snapshot_sha256":"a4ef03f9e54cd77ccc5802340090a614e9d81ee883bd4111d7535206d18fc5a7"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:06:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"l4enjivjvO5AigO9Zh8s6l8d7Mf34iPhZMGKj0u1Y8OZ8oMPhmOThCC/ZN4EI185CuBvm9tRwzt7m7DgZaIRCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-24T14:49:28.961727Z"},"content_sha256":"8f5977d47c2e7da1a8e64389a67ae0418d291e0b2d94a507c434ad20dce8b646","schema_version":"1.0","event_id":"sha256:8f5977d47c2e7da1a8e64389a67ae0418d291e0b2d94a507c434ad20dce8b646"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/TM7SOSHDEAHCYUAGTI2ZDR7GHA/bundle.json","state_url":"https://pith.science/pith/TM7SOSHDEAHCYUAGTI2ZDR7GHA/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/TM7SOSHDEAHCYUAGTI2ZDR7GHA/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-24T14:49:28Z","links":{"resolver":"https://pith.science/pith/TM7SOSHDEAHCYUAGTI2ZDR7GHA","bundle":"https://pith.science/pith/TM7SOSHDEAHCYUAGTI2ZDR7GHA/bundle.json","state":"https://pith.science/pith/TM7SOSHDEAHCYUAGTI2ZDR7GHA/state.json","well_known_bundle":"https://pith.science/.well-known/pith/TM7SOSHDEAHCYUAGTI2ZDR7GHA/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:TM7SOSHDEAHCYUAGTI2ZDR7GHA","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"57057bb1539cdc8e0fa0237c4621000655a8a95e03258c790f59cbf239bb8a91","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-18T17:13:41Z","title_canon_sha256":"faaa9859d0b8baa9893eb43c1dd14b01c50f2c53037f22f8adc8c9c39a2141db"},"schema_version":"1.0","source":{"id":"2605.18672","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.18672","created_at":"2026-05-20T00:06:14Z"},{"alias_kind":"arxiv_version","alias_value":"2605.18672v1","created_at":"2026-05-20T00:06:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.18672","created_at":"2026-05-20T00:06:14Z"},{"alias_kind":"pith_short_12","alias_value":"TM7SOSHDEAHC","created_at":"2026-05-20T00:06:14Z"},{"alias_kind":"pith_short_16","alias_value":"TM7SOSHDEAHCYUAG","created_at":"2026-05-20T00:06:14Z"},{"alias_kind":"pith_short_8","alias_value":"TM7SOSHD","created_at":"2026-05-20T00:06:14Z"}],"graph_snapshots":[{"event_id":"sha256:8f5977d47c2e7da1a8e64389a67ae0418d291e0b2d94a507c434ad20dce8b646","target":"graph","created_at":"2026-05-20T00:06:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"claim_evidence","ran_at":"2026-05-20T00:01:59.132607Z","status":"completed","version":"1.0.0"}],"endpoint":"/pith/2605.18672/integrity.json","findings":[],"snapshot_sha256":"a4ef03f9e54cd77ccc5802340090a614e9d81ee883bd4111d7535206d18fc5a7","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"This position paper argues that enforcing LLM agent safety within a single abstraction layer is not merely suboptimal but categorically insufficient for deployed LLM agents -- a structural consequence of how agent execution works, not a contingent limitation of current systems. The three dimensions that jointly constitute safe operation -- semantic intent and policy compliance, environmental validity, and dynamical feasibility -- each depend on a strictly distinct set of information that becomes available at different stages of execution. No single guardrail can certify all three. We argue tha","authors_text":"A. Nouri, C. Wu, D. Nickovic, J. Kroger, M. Franzle, R. Roy, S.Bensalem, X. Huang, Y. Dong","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-18T17:13:41Z","title":"Position: A Three-Layer Probabilistic Assume-Guarantee Architecture Is Structurally Required for Safe LLM Agent Deployment"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.18672","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:cf4389e51d1b0c35a941f9b9a02c9ee50f90366aaa8b7ca8647d8087d26a611b","target":"record","created_at":"2026-05-20T00:06:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"57057bb1539cdc8e0fa0237c4621000655a8a95e03258c790f59cbf239bb8a91","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-18T17:13:41Z","title_canon_sha256":"faaa9859d0b8baa9893eb43c1dd14b01c50f2c53037f22f8adc8c9c39a2141db"},"schema_version":"1.0","source":{"id":"2605.18672","kind":"arxiv","version":1}},"canonical_sha256":"9b3f2748e3200e2c50069a3591c7e63813e1abaf75a5d9893848f36442f9c5fe","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"9b3f2748e3200e2c50069a3591c7e63813e1abaf75a5d9893848f36442f9c5fe","first_computed_at":"2026-05-20T00:06:14.069613Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:06:14.069613Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"bQ/0ZQNtjg4GHGPRmbm2tfhPQYSjJZve63sWm6WD6EEZvTK+emNO8ef/UK80CpKGiJ20F5YR4aIyVb6yFUSSAQ==","signature_status":"signed_v1","signed_at":"2026-05-20T00:06:14.070459Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.18672","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:cf4389e51d1b0c35a941f9b9a02c9ee50f90366aaa8b7ca8647d8087d26a611b","sha256:8f5977d47c2e7da1a8e64389a67ae0418d291e0b2d94a507c434ad20dce8b646"],"state_sha256":"a7e9f62fb9ff3e497d42a4f679712fda2f0cfc9155d109b750902ab7d8d08e13"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"YXBnvjGneRNMG5u/ozSrOcTiecztLwOl2xwTSABtR7vBlozQ3T2WB0rC+hpD2KPpGR+8/KrLPH8DKs/wr4jUCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-24T14:49:28.965268Z","bundle_sha256":"dc82b3fa8a92917a5ee37a1aebfcdfa37cd2857a932208cd2a90a8319481f022"}}