{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:U3JWRSMXBWV3G5WYLODCHN435T","short_pith_number":"pith:U3JWRSMX","canonical_record":{"source":{"id":"2606.02995","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T01:11:58Z","cross_cats_sorted":["cs.AI","cs.IR","cs.LG"],"title_canon_sha256":"9fc119bcbaf73b2f71f779cb576bbe0e9bdecf3401b7c511d70c756dd69f29dd","abstract_canon_sha256":"ec8abecc406d59848dc81732648853b8064871019588ed7ba69ddbd2290dad96"},"schema_version":"1.0"},"canonical_sha256":"a6d368c9970dabb376d85b8623b79becff7551b7772a5fb8c2757e5d626dbb5f","source":{"kind":"arxiv","id":"2606.02995","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.02995","created_at":"2026-06-03T01:05:28Z"},{"alias_kind":"arxiv_version","alias_value":"2606.02995v1","created_at":"2026-06-03T01:05:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.02995","created_at":"2026-06-03T01:05:28Z"},{"alias_kind":"pith_short_12","alias_value":"U3JWRSMXBWV3","created_at":"2026-06-03T01:05:28Z"},{"alias_kind":"pith_short_16","alias_value":"U3JWRSMXBWV3G5WY","created_at":"2026-06-03T01:05:28Z"},{"alias_kind":"pith_short_8","alias_value":"U3JWRSMX","created_at":"2026-06-03T01:05:28Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:U3JWRSMXBWV3G5WYLODCHN435T","target":"record","payload":{"canonical_record":{"source":{"id":"2606.02995","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T01:11:58Z","cross_cats_sorted":["cs.AI","cs.IR","cs.LG"],"title_canon_sha256":"9fc119bcbaf73b2f71f779cb576bbe0e9bdecf3401b7c511d70c756dd69f29dd","abstract_canon_sha256":"ec8abecc406d59848dc81732648853b8064871019588ed7ba69ddbd2290dad96"},"schema_version":"1.0"},"canonical_sha256":"a6d368c9970dabb376d85b8623b79becff7551b7772a5fb8c2757e5d626dbb5f","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-03T01:05:28.812796Z","signature_b64":"0b9j4+Dt8hLn5FSdk0+xyilBijthmwKYFhSdSPOfYHZU7QNOkAomhbN5LItxuWFYRMhv02i1vCSUGiKNtERwAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a6d368c9970dabb376d85b8623b79becff7551b7772a5fb8c2757e5d626dbb5f","last_reissued_at":"2026-06-03T01:05:28.812352Z","signature_status":"signed_v1","first_computed_at":"2026-06-03T01:05:28.812352Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.02995","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"1m0dXfClEknQXC2Bj92YWrGX/oQWjUU4Br0t4mi4Vc3gJ/2qmPAf2nb9YVGUp+vsKCQs1yOdjrq8Zc5SdH5tCg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T19:21:28.759303Z"},"content_sha256":"e94cd094f32490bd2b45cf8cde93de654f92550ba8d3e5900de9ecfc896557bb","schema_version":"1.0","event_id":"sha256:e94cd094f32490bd2b45cf8cde93de654f92550ba8d3e5900de9ecfc896557bb"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:U3JWRSMXBWV3G5WYLODCHN435T","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Patcher: Post-Hoc Patching of Backdoored Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.IR","cs.LG"],"primary_cat":"cs.CR","authors_text":"Anjun Gao, Minghong Fang, Yueyang Quan, Yufei Xia, Zhuqing Liu","submitted_at":"2026-06-02T01:11:58Z","abstract_excerpt":"Large language models remain vulnerable to jailbreak backdoor attacks, where adversaries poison safety alignment data to embed hidden triggers that bypass safety mechanisms. Existing defenses often require comprehensive attack information or multiple triggered examples, making them impractical when defenders only observe a single reported failure case without knowing whether it stems from a backdoor attack or a natural alignment bug. This paper presents Patcher, a post-hoc defense framework that repairs backdoored language models using only a single reported failure case and the model paramete"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.02995","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.02995/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-03T01:05:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"piImVNaCnpIl2N0cJBuwqiDJnzTHEadOzXkrDUKtNU/O9WB4XtYSskxDo+g5s3DrxTSJZjTyRYRoxRTVj5R3DQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T19:21:28.759695Z"},"content_sha256":"89638e041f6b981eba25e4cb548e9ed1084192407268c7a6cd530036a7e0d2eb","schema_version":"1.0","event_id":"sha256:89638e041f6b981eba25e4cb548e9ed1084192407268c7a6cd530036a7e0d2eb"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T/bundle.json","state_url":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/U3JWRSMXBWV3G5WYLODCHN435T/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-10T19:21:28Z","links":{"resolver":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T","bundle":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T/bundle.json","state":"https://pith.science/pith/U3JWRSMXBWV3G5WYLODCHN435T/state.json","well_known_bundle":"https://pith.science/.well-known/pith/U3JWRSMXBWV3G5WYLODCHN435T/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:U3JWRSMXBWV3G5WYLODCHN435T","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ec8abecc406d59848dc81732648853b8064871019588ed7ba69ddbd2290dad96","cross_cats_sorted":["cs.AI","cs.IR","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T01:11:58Z","title_canon_sha256":"9fc119bcbaf73b2f71f779cb576bbe0e9bdecf3401b7c511d70c756dd69f29dd"},"schema_version":"1.0","source":{"id":"2606.02995","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.02995","created_at":"2026-06-03T01:05:28Z"},{"alias_kind":"arxiv_version","alias_value":"2606.02995v1","created_at":"2026-06-03T01:05:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.02995","created_at":"2026-06-03T01:05:28Z"},{"alias_kind":"pith_short_12","alias_value":"U3JWRSMXBWV3","created_at":"2026-06-03T01:05:28Z"},{"alias_kind":"pith_short_16","alias_value":"U3JWRSMXBWV3G5WY","created_at":"2026-06-03T01:05:28Z"},{"alias_kind":"pith_short_8","alias_value":"U3JWRSMX","created_at":"2026-06-03T01:05:28Z"}],"graph_snapshots":[{"event_id":"sha256:89638e041f6b981eba25e4cb548e9ed1084192407268c7a6cd530036a7e0d2eb","target":"graph","created_at":"2026-06-03T01:05:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.02995/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language models remain vulnerable to jailbreak backdoor attacks, where adversaries poison safety alignment data to embed hidden triggers that bypass safety mechanisms. Existing defenses often require comprehensive attack information or multiple triggered examples, making them impractical when defenders only observe a single reported failure case without knowing whether it stems from a backdoor attack or a natural alignment bug. This paper presents Patcher, a post-hoc defense framework that repairs backdoored language models using only a single reported failure case and the model paramete","authors_text":"Anjun Gao, Minghong Fang, Yueyang Quan, Yufei Xia, Zhuqing Liu","cross_cats":["cs.AI","cs.IR","cs.LG"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T01:11:58Z","title":"Patcher: Post-Hoc Patching of Backdoored Large Language Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.02995","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:e94cd094f32490bd2b45cf8cde93de654f92550ba8d3e5900de9ecfc896557bb","target":"record","created_at":"2026-06-03T01:05:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ec8abecc406d59848dc81732648853b8064871019588ed7ba69ddbd2290dad96","cross_cats_sorted":["cs.AI","cs.IR","cs.LG"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-02T01:11:58Z","title_canon_sha256":"9fc119bcbaf73b2f71f779cb576bbe0e9bdecf3401b7c511d70c756dd69f29dd"},"schema_version":"1.0","source":{"id":"2606.02995","kind":"arxiv","version":1}},"canonical_sha256":"a6d368c9970dabb376d85b8623b79becff7551b7772a5fb8c2757e5d626dbb5f","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a6d368c9970dabb376d85b8623b79becff7551b7772a5fb8c2757e5d626dbb5f","first_computed_at":"2026-06-03T01:05:28.812352Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-03T01:05:28.812352Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"0b9j4+Dt8hLn5FSdk0+xyilBijthmwKYFhSdSPOfYHZU7QNOkAomhbN5LItxuWFYRMhv02i1vCSUGiKNtERwAg==","signature_status":"signed_v1","signed_at":"2026-06-03T01:05:28.812796Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.02995","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:e94cd094f32490bd2b45cf8cde93de654f92550ba8d3e5900de9ecfc896557bb","sha256:89638e041f6b981eba25e4cb548e9ed1084192407268c7a6cd530036a7e0d2eb"],"state_sha256":"76765245d8b5f8f73c84cca137ae53968f58de954c92bee9c1abcb8f3bc56745"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"S6BGk+VVnrA0gbutBirPIeshRIoa2T97Dkk5wYbpDotRohN4QeaILBYZC0DJyw+f6UWDNinkS/HXF0qklhSHDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-10T19:21:28.761682Z","bundle_sha256":"eeb20ede2d510bfe0f8b67dc40ba7ef6ce2b17b278ad5d51c2b4c8952f6e5e29"}}