{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:UN4A2GH7Z7NWPT4LHVYCGCJQ2F","short_pith_number":"pith:UN4A2GH7","canonical_record":{"source":{"id":"2605.22122","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-21T07:53:10Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"a33ee7fdd62c30636a869165a4f930355112e977009b785cf71016867ade5c82","abstract_canon_sha256":"578c0629df9b4475323056201fe79bda6b5462c3fc81e7cc153bc0879ba05db5"},"schema_version":"1.0"},"canonical_sha256":"a3780d18ffcfdb67cf8b3d70230930d14cb775d49db2df999df3104daf765df3","source":{"kind":"arxiv","id":"2605.22122","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.22122","created_at":"2026-05-22T01:04:26Z"},{"alias_kind":"arxiv_version","alias_value":"2605.22122v1","created_at":"2026-05-22T01:04:26Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.22122","created_at":"2026-05-22T01:04:26Z"},{"alias_kind":"pith_short_12","alias_value":"UN4A2GH7Z7NW","created_at":"2026-05-22T01:04:26Z"},{"alias_kind":"pith_short_16","alias_value":"UN4A2GH7Z7NWPT4L","created_at":"2026-05-22T01:04:26Z"},{"alias_kind":"pith_short_8","alias_value":"UN4A2GH7","created_at":"2026-05-22T01:04:26Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:UN4A2GH7Z7NWPT4LHVYCGCJQ2F","target":"record","payload":{"canonical_record":{"source":{"id":"2605.22122","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-21T07:53:10Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"a33ee7fdd62c30636a869165a4f930355112e977009b785cf71016867ade5c82","abstract_canon_sha256":"578c0629df9b4475323056201fe79bda6b5462c3fc81e7cc153bc0879ba05db5"},"schema_version":"1.0"},"canonical_sha256":"a3780d18ffcfdb67cf8b3d70230930d14cb775d49db2df999df3104daf765df3","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-22T01:04:26.962504Z","signature_b64":"aihDEyFn1OySpsTWNH9rznsxowdhgzRYdXqvZmHtBMI5ftc1yFLrpTvKMlxHPsOzhw1AiSmu3PbZeMiwVZv2DQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a3780d18ffcfdb67cf8b3d70230930d14cb775d49db2df999df3104daf765df3","last_reissued_at":"2026-05-22T01:04:26.961639Z","signature_status":"signed_v1","first_computed_at":"2026-05-22T01:04:26.961639Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.22122","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:04:26Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Afxqaek9OzwzNLMEYvYcUofXij2196vgsLiD1uMZCoVf7FE/DVYm6Y3PWQ/p1MFVjhGV7dYv5P1RMZbhh4xqBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T19:19:10.597873Z"},"content_sha256":"fdca49f9c780f1e0331c2ffeb49c1a5772f214f949047e2087b2170d6517f5e9","schema_version":"1.0","event_id":"sha256:fdca49f9c780f1e0331c2ffeb49c1a5772f214f949047e2087b2170d6517f5e9"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:UN4A2GH7Z7NWPT4LHVYCGCJQ2F","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Adversarial Trust Poisoning in Vehicular Collaborative Perception","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Chenyi Wang, Ming F. Li, Qingzhao Zhang, Yutong Liu","submitted_at":"2026-05-21T07:53:10Z","abstract_excerpt":"Collaborative perception (CP) enables connected and autonomous vehicles to share sensor data and jointly reason about their environment. To defend against adversaries that fabricate or manipulate shared data, existing systems employ cross-vehicle inconsistency detection and trust estimation, penalizing vehicles whose observations conflict with the majority. In this work, we show that these defenses themselves introduce a new attack surface. We present TrustFlip, a novel attack that weaponizes consistency-based defenses to poison the trust assigned to benign vehicles. Instead of injecting false"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.22122","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.22122/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:04:26Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"V9rKxZtHWYDbgX1PO11kUGtcAfiw3iLRuaSDNJUfX3pzBVadhVTH5FbO2CDnlc/NKdmMsnJmS0ZOWaBlvjjTAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T19:19:10.598254Z"},"content_sha256":"b55e0febd113e03dfa667ddc1cd46a5ae900d064726946affcb753b0f507a167","schema_version":"1.0","event_id":"sha256:b55e0febd113e03dfa667ddc1cd46a5ae900d064726946affcb753b0f507a167"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/UN4A2GH7Z7NWPT4LHVYCGCJQ2F/bundle.json","state_url":"https://pith.science/pith/UN4A2GH7Z7NWPT4LHVYCGCJQ2F/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/UN4A2GH7Z7NWPT4LHVYCGCJQ2F/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-27T19:19:10Z","links":{"resolver":"https://pith.science/pith/UN4A2GH7Z7NWPT4LHVYCGCJQ2F","bundle":"https://pith.science/pith/UN4A2GH7Z7NWPT4LHVYCGCJQ2F/bundle.json","state":"https://pith.science/pith/UN4A2GH7Z7NWPT4LHVYCGCJQ2F/state.json","well_known_bundle":"https://pith.science/.well-known/pith/UN4A2GH7Z7NWPT4LHVYCGCJQ2F/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:UN4A2GH7Z7NWPT4LHVYCGCJQ2F","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"578c0629df9b4475323056201fe79bda6b5462c3fc81e7cc153bc0879ba05db5","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-21T07:53:10Z","title_canon_sha256":"a33ee7fdd62c30636a869165a4f930355112e977009b785cf71016867ade5c82"},"schema_version":"1.0","source":{"id":"2605.22122","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.22122","created_at":"2026-05-22T01:04:26Z"},{"alias_kind":"arxiv_version","alias_value":"2605.22122v1","created_at":"2026-05-22T01:04:26Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.22122","created_at":"2026-05-22T01:04:26Z"},{"alias_kind":"pith_short_12","alias_value":"UN4A2GH7Z7NW","created_at":"2026-05-22T01:04:26Z"},{"alias_kind":"pith_short_16","alias_value":"UN4A2GH7Z7NWPT4L","created_at":"2026-05-22T01:04:26Z"},{"alias_kind":"pith_short_8","alias_value":"UN4A2GH7","created_at":"2026-05-22T01:04:26Z"}],"graph_snapshots":[{"event_id":"sha256:b55e0febd113e03dfa667ddc1cd46a5ae900d064726946affcb753b0f507a167","target":"graph","created_at":"2026-05-22T01:04:26Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.22122/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Collaborative perception (CP) enables connected and autonomous vehicles to share sensor data and jointly reason about their environment. To defend against adversaries that fabricate or manipulate shared data, existing systems employ cross-vehicle inconsistency detection and trust estimation, penalizing vehicles whose observations conflict with the majority. In this work, we show that these defenses themselves introduce a new attack surface. We present TrustFlip, a novel attack that weaponizes consistency-based defenses to poison the trust assigned to benign vehicles. Instead of injecting false","authors_text":"Chenyi Wang, Ming F. Li, Qingzhao Zhang, Yutong Liu","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-21T07:53:10Z","title":"Adversarial Trust Poisoning in Vehicular Collaborative Perception"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.22122","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:fdca49f9c780f1e0331c2ffeb49c1a5772f214f949047e2087b2170d6517f5e9","target":"record","created_at":"2026-05-22T01:04:26Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"578c0629df9b4475323056201fe79bda6b5462c3fc81e7cc153bc0879ba05db5","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-21T07:53:10Z","title_canon_sha256":"a33ee7fdd62c30636a869165a4f930355112e977009b785cf71016867ade5c82"},"schema_version":"1.0","source":{"id":"2605.22122","kind":"arxiv","version":1}},"canonical_sha256":"a3780d18ffcfdb67cf8b3d70230930d14cb775d49db2df999df3104daf765df3","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a3780d18ffcfdb67cf8b3d70230930d14cb775d49db2df999df3104daf765df3","first_computed_at":"2026-05-22T01:04:26.961639Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-22T01:04:26.961639Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"aihDEyFn1OySpsTWNH9rznsxowdhgzRYdXqvZmHtBMI5ftc1yFLrpTvKMlxHPsOzhw1AiSmu3PbZeMiwVZv2DQ==","signature_status":"signed_v1","signed_at":"2026-05-22T01:04:26.962504Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.22122","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:fdca49f9c780f1e0331c2ffeb49c1a5772f214f949047e2087b2170d6517f5e9","sha256:b55e0febd113e03dfa667ddc1cd46a5ae900d064726946affcb753b0f507a167"],"state_sha256":"76afcb6720d4d36b65c754b0897c24d9a4298d0b89cbe62ab92c18c5b05c12fb"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"NsBbbUdJXRy4oVOD0v8nKXl0G2tymdNAxbweI1yMHHPsJt5+mKetNblxI2sZhZ28TOrmqI1yA9A9Q/XgfnDWBA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-27T19:19:10.600499Z","bundle_sha256":"103b331976f3f9322b7fd0bcf727e45db1e73cce99e0996ad895f5540b6c801d"}}