{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:U6CJ544FDRQGRRNOVDBV5SKYNV","short_pith_number":"pith:U6CJ544F","canonical_record":{"source":{"id":"2605.17310","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2026-05-17T08:02:27Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"3a63f5cd24cb8a5ab6808648a0af7d6d5f7b795c8a7e7d57ec2907b70aa8c294","abstract_canon_sha256":"0b68c641650cbbe3bb3db2a37f7291a230ba6d2d3f0c48718217fd312691f94b"},"schema_version":"1.0"},"canonical_sha256":"a7849ef3851c6068c5aea8c35ec9586d4ca7c70694e4c94c05923568b5752573","source":{"kind":"arxiv","id":"2605.17310","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.17310","created_at":"2026-05-20T00:03:51Z"},{"alias_kind":"arxiv_version","alias_value":"2605.17310v1","created_at":"2026-05-20T00:03:51Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.17310","created_at":"2026-05-20T00:03:51Z"},{"alias_kind":"pith_short_12","alias_value":"U6CJ544FDRQG","created_at":"2026-05-20T00:03:51Z"},{"alias_kind":"pith_short_16","alias_value":"U6CJ544FDRQGRRNO","created_at":"2026-05-20T00:03:51Z"},{"alias_kind":"pith_short_8","alias_value":"U6CJ544F","created_at":"2026-05-20T00:03:51Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:U6CJ544FDRQGRRNOVDBV5SKYNV","target":"record","payload":{"canonical_record":{"source":{"id":"2605.17310","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2026-05-17T08:02:27Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"3a63f5cd24cb8a5ab6808648a0af7d6d5f7b795c8a7e7d57ec2907b70aa8c294","abstract_canon_sha256":"0b68c641650cbbe3bb3db2a37f7291a230ba6d2d3f0c48718217fd312691f94b"},"schema_version":"1.0"},"canonical_sha256":"a7849ef3851c6068c5aea8c35ec9586d4ca7c70694e4c94c05923568b5752573","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-20T00:03:51.519564Z","signature_b64":"fVKjISgj07TEusGXIXgQkB3M6ynDJeOWiDgNfKBQEzKmI8Ep0pWIfjECiaVEXMsErY67oRZqtc+rljFjAc+2CQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a7849ef3851c6068c5aea8c35ec9586d4ca7c70694e4c94c05923568b5752573","last_reissued_at":"2026-05-20T00:03:51.518772Z","signature_status":"signed_v1","first_computed_at":"2026-05-20T00:03:51.518772Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.17310","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:03:51Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"i4cfFyk/hMhzr0uigSiEeNOFfu8wgMToiK84jEFpjgAr+4PwCvvB8uOryjO6fzJZohdRVq7oUf2c5FQJ1LWFAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T01:39:04.529257Z"},"content_sha256":"356585970d5a7131a4d8bf1d0437d5dcb53f051bd69bb9d6e5cc044a9f3bddb6","schema_version":"1.0","event_id":"sha256:356585970d5a7131a4d8bf1d0437d5dcb53f051bd69bb9d6e5cc044a9f3bddb6"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:U6CJ544FDRQGRRNOVDBV5SKYNV","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Attention Hijacking: Response Manipulation Across Queries in Vision-Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CV","authors_text":"Dongrui Liu, Wei Xue, Wenhan Luo, Yan Li, Yike Guo, Zhiqiang Wang, Zonghao Ying","submitted_at":"2026-05-17T08:02:27Z","abstract_excerpt":"Existing adversarial attacks on vision-language models (VLMs) can steer model outputs toward attacker-specified target responses, but their effectiveness often degrades when the same perturbed input is paired with different textual queries. This paper studies cross-query response manipulation, where a single adversarial example is expected to remain effective across diverse user queries. We first analyze the limitations of existing attacks and find that successful transfer is closely associated with preserving an image-dominant attention pattern during response generation. Motivated by the obs"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.17310","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.17310/integrity.json","findings":[],"available":true,"detectors_run":[{"name":"claim_evidence","ran_at":"2026-05-19T22:01:57.790690Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"ai_meta_artifact","ran_at":"2026-05-19T21:33:23.754985Z","status":"skipped","version":"1.0.0","findings_count":0}],"snapshot_sha256":"d50edaac4e2fbfdb59f0097f81e725cceee0f579750a36c8d53df81b3d910975"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:03:51Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"xH9DbatGWoVagMgdCJddgZpygm1fWfHqHzWqESIXWS0R5qDrxDAQWfxs/AaPFitx4zEzozP0nNv0+uXYruh/AQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T01:39:04.530005Z"},"content_sha256":"c1d449d5409b05415a9214fb8b3ad0e4a98c9817699845db6ddac3246d2bfb5e","schema_version":"1.0","event_id":"sha256:c1d449d5409b05415a9214fb8b3ad0e4a98c9817699845db6ddac3246d2bfb5e"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/U6CJ544FDRQGRRNOVDBV5SKYNV/bundle.json","state_url":"https://pith.science/pith/U6CJ544FDRQGRRNOVDBV5SKYNV/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/U6CJ544FDRQGRRNOVDBV5SKYNV/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-27T01:39:04Z","links":{"resolver":"https://pith.science/pith/U6CJ544FDRQGRRNOVDBV5SKYNV","bundle":"https://pith.science/pith/U6CJ544FDRQGRRNOVDBV5SKYNV/bundle.json","state":"https://pith.science/pith/U6CJ544FDRQGRRNOVDBV5SKYNV/state.json","well_known_bundle":"https://pith.science/.well-known/pith/U6CJ544FDRQGRRNOVDBV5SKYNV/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:U6CJ544FDRQGRRNOVDBV5SKYNV","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0b68c641650cbbe3bb3db2a37f7291a230ba6d2d3f0c48718217fd312691f94b","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2026-05-17T08:02:27Z","title_canon_sha256":"3a63f5cd24cb8a5ab6808648a0af7d6d5f7b795c8a7e7d57ec2907b70aa8c294"},"schema_version":"1.0","source":{"id":"2605.17310","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.17310","created_at":"2026-05-20T00:03:51Z"},{"alias_kind":"arxiv_version","alias_value":"2605.17310v1","created_at":"2026-05-20T00:03:51Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.17310","created_at":"2026-05-20T00:03:51Z"},{"alias_kind":"pith_short_12","alias_value":"U6CJ544FDRQG","created_at":"2026-05-20T00:03:51Z"},{"alias_kind":"pith_short_16","alias_value":"U6CJ544FDRQGRRNO","created_at":"2026-05-20T00:03:51Z"},{"alias_kind":"pith_short_8","alias_value":"U6CJ544F","created_at":"2026-05-20T00:03:51Z"}],"graph_snapshots":[{"event_id":"sha256:c1d449d5409b05415a9214fb8b3ad0e4a98c9817699845db6ddac3246d2bfb5e","target":"graph","created_at":"2026-05-20T00:03:51Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"claim_evidence","ran_at":"2026-05-19T22:01:57.790690Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"ai_meta_artifact","ran_at":"2026-05-19T21:33:23.754985Z","status":"skipped","version":"1.0.0"}],"endpoint":"/pith/2605.17310/integrity.json","findings":[],"snapshot_sha256":"d50edaac4e2fbfdb59f0097f81e725cceee0f579750a36c8d53df81b3d910975","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Existing adversarial attacks on vision-language models (VLMs) can steer model outputs toward attacker-specified target responses, but their effectiveness often degrades when the same perturbed input is paired with different textual queries. This paper studies cross-query response manipulation, where a single adversarial example is expected to remain effective across diverse user queries. We first analyze the limitations of existing attacks and find that successful transfer is closely associated with preserving an image-dominant attention pattern during response generation. Motivated by the obs","authors_text":"Dongrui Liu, Wei Xue, Wenhan Luo, Yan Li, Yike Guo, Zhiqiang Wang, Zonghao Ying","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2026-05-17T08:02:27Z","title":"Attention Hijacking: Response Manipulation Across Queries in Vision-Language Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.17310","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:356585970d5a7131a4d8bf1d0437d5dcb53f051bd69bb9d6e5cc044a9f3bddb6","target":"record","created_at":"2026-05-20T00:03:51Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0b68c641650cbbe3bb3db2a37f7291a230ba6d2d3f0c48718217fd312691f94b","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2026-05-17T08:02:27Z","title_canon_sha256":"3a63f5cd24cb8a5ab6808648a0af7d6d5f7b795c8a7e7d57ec2907b70aa8c294"},"schema_version":"1.0","source":{"id":"2605.17310","kind":"arxiv","version":1}},"canonical_sha256":"a7849ef3851c6068c5aea8c35ec9586d4ca7c70694e4c94c05923568b5752573","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a7849ef3851c6068c5aea8c35ec9586d4ca7c70694e4c94c05923568b5752573","first_computed_at":"2026-05-20T00:03:51.518772Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:03:51.518772Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"fVKjISgj07TEusGXIXgQkB3M6ynDJeOWiDgNfKBQEzKmI8Ep0pWIfjECiaVEXMsErY67oRZqtc+rljFjAc+2CQ==","signature_status":"signed_v1","signed_at":"2026-05-20T00:03:51.519564Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.17310","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:356585970d5a7131a4d8bf1d0437d5dcb53f051bd69bb9d6e5cc044a9f3bddb6","sha256:c1d449d5409b05415a9214fb8b3ad0e4a98c9817699845db6ddac3246d2bfb5e"],"state_sha256":"809d1220a143571b88fd7026081bba3ca7f00d5f414222ad80407ff443fc5738"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"P6O6Lp6NKD5i4p+SZw69GVV+stwwxbfqgFt5SkYronkZXwBF/85d7WDpWkMer3HIiZ7QpkWznY2d9E5Eiu+XDg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-27T01:39:04.533851Z","bundle_sha256":"1fcaca116f7bdc2e6c090c1ba39dadc7ed831c665fe56b39c899c3be870e2e68"}}