{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:UQ6H53NJQOJFW3TN2CSFIMFRID","short_pith_number":"pith:UQ6H53NJ","canonical_record":{"source":{"id":"2605.15598","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-15T04:14:04Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"7dc6e6afb187cfae8cb5c34b54742e4b6a99f0afd83edfde0867494a5ca8c963","abstract_canon_sha256":"32e4e051a653bb134b9001ea7b9d3d205b15a85e11daca8726d0dccf733924e0"},"schema_version":"1.0"},"canonical_sha256":"a43c7eeda983925b6e6dd0a45430b140c89af1dd8565877d90c75bc4c9b43933","source":{"kind":"arxiv","id":"2605.15598","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.15598","created_at":"2026-05-20T00:01:07Z"},{"alias_kind":"arxiv_version","alias_value":"2605.15598v1","created_at":"2026-05-20T00:01:07Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.15598","created_at":"2026-05-20T00:01:07Z"},{"alias_kind":"pith_short_12","alias_value":"UQ6H53NJQOJF","created_at":"2026-05-20T00:01:07Z"},{"alias_kind":"pith_short_16","alias_value":"UQ6H53NJQOJFW3TN","created_at":"2026-05-20T00:01:07Z"},{"alias_kind":"pith_short_8","alias_value":"UQ6H53NJ","created_at":"2026-05-20T00:01:07Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:UQ6H53NJQOJFW3TN2CSFIMFRID","target":"record","payload":{"canonical_record":{"source":{"id":"2605.15598","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-15T04:14:04Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"7dc6e6afb187cfae8cb5c34b54742e4b6a99f0afd83edfde0867494a5ca8c963","abstract_canon_sha256":"32e4e051a653bb134b9001ea7b9d3d205b15a85e11daca8726d0dccf733924e0"},"schema_version":"1.0"},"canonical_sha256":"a43c7eeda983925b6e6dd0a45430b140c89af1dd8565877d90c75bc4c9b43933","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-20T00:01:07.398857Z","signature_b64":"xdy8oQWJ/Ff2rpDFOJKthd00r+5FavY6EW7xzv3iWsCs3XUgfo9C+vKmoIBDM38ms8Q9tcr8hnLMvxVCTJO/Cw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a43c7eeda983925b6e6dd0a45430b140c89af1dd8565877d90c75bc4c9b43933","last_reissued_at":"2026-05-20T00:01:07.398061Z","signature_status":"signed_v1","first_computed_at":"2026-05-20T00:01:07.398061Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.15598","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:01:07Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"+n4WSagDBoLTiVjBaegW0Q+bVycnHQA5h7tH8XdlyYmctjxwVu0UIXDfjs7vIm2GuKMB7fs4SvtN9Ybj94c5Dg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T19:28:24.902084Z"},"content_sha256":"fef213fca20a093e4b9fd802e391df901e9c3ebc761c6724d1d1a5d099afb1b6","schema_version":"1.0","event_id":"sha256:fef213fca20a093e4b9fd802e391df901e9c3ebc761c6724d1d1a5d099afb1b6"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:UQ6H53NJQOJFW3TN2CSFIMFRID","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Compositional Jailbreaking: An Empirical Analysis of Mutator Chain Interactions in Aligned LLMs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.SE"],"primary_cat":"cs.CR","authors_text":"Hoon Wei Lim, Reinelle Jan Bugnot, Soohyeon Choi, Yue Duan","submitted_at":"2026-05-15T04:14:04Z","abstract_excerpt":"Jailbreaking attacks on large language models pose a significant threat to AI safety by enabling the generation of harmful or restricted content. While prior work has explored both handcrafted and automated jailbreak strategies, the potential for compositional interaction between simple attacks remains underexplored. This paper presents a systematic study of mutator chaining, in which weak jailbreak transformations are applied sequentially to characterize how they interact: whether they reinforce one another, interfere destructively, or produce no meaningful change. We implement twelve baselin"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.15598","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.15598/integrity.json","findings":[],"available":true,"detectors_run":[{"name":"ai_meta_artifact","ran_at":"2026-05-19T19:34:34.898913Z","status":"skipped","version":"1.0.0","findings_count":0},{"name":"claim_evidence","ran_at":"2026-05-19T17:41:56.056930Z","status":"completed","version":"1.0.0","findings_count":0}],"snapshot_sha256":"7d55190ddd99fd363114895b31f886272419f4b605ff469e92b91884a68ade35"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T00:01:07Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ddTBpDWOgPWazstoC1ShqNlsMhycIEvj01z1F09Huki4nYQaDxousmAH6r2xX8wcNSm9KA78HXHnDeK53LKaBQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T19:28:24.902616Z"},"content_sha256":"d64c9f7639247afbb76dd8a1746b0416e57ab9fa1840551d127c0bc4e612b185","schema_version":"1.0","event_id":"sha256:d64c9f7639247afbb76dd8a1746b0416e57ab9fa1840551d127c0bc4e612b185"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/UQ6H53NJQOJFW3TN2CSFIMFRID/bundle.json","state_url":"https://pith.science/pith/UQ6H53NJQOJFW3TN2CSFIMFRID/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/UQ6H53NJQOJFW3TN2CSFIMFRID/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T19:28:24Z","links":{"resolver":"https://pith.science/pith/UQ6H53NJQOJFW3TN2CSFIMFRID","bundle":"https://pith.science/pith/UQ6H53NJQOJFW3TN2CSFIMFRID/bundle.json","state":"https://pith.science/pith/UQ6H53NJQOJFW3TN2CSFIMFRID/state.json","well_known_bundle":"https://pith.science/.well-known/pith/UQ6H53NJQOJFW3TN2CSFIMFRID/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:UQ6H53NJQOJFW3TN2CSFIMFRID","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"32e4e051a653bb134b9001ea7b9d3d205b15a85e11daca8726d0dccf733924e0","cross_cats_sorted":["cs.SE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-15T04:14:04Z","title_canon_sha256":"7dc6e6afb187cfae8cb5c34b54742e4b6a99f0afd83edfde0867494a5ca8c963"},"schema_version":"1.0","source":{"id":"2605.15598","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.15598","created_at":"2026-05-20T00:01:07Z"},{"alias_kind":"arxiv_version","alias_value":"2605.15598v1","created_at":"2026-05-20T00:01:07Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.15598","created_at":"2026-05-20T00:01:07Z"},{"alias_kind":"pith_short_12","alias_value":"UQ6H53NJQOJF","created_at":"2026-05-20T00:01:07Z"},{"alias_kind":"pith_short_16","alias_value":"UQ6H53NJQOJFW3TN","created_at":"2026-05-20T00:01:07Z"},{"alias_kind":"pith_short_8","alias_value":"UQ6H53NJ","created_at":"2026-05-20T00:01:07Z"}],"graph_snapshots":[{"event_id":"sha256:d64c9f7639247afbb76dd8a1746b0416e57ab9fa1840551d127c0bc4e612b185","target":"graph","created_at":"2026-05-20T00:01:07Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"ai_meta_artifact","ran_at":"2026-05-19T19:34:34.898913Z","status":"skipped","version":"1.0.0"},{"findings_count":0,"name":"claim_evidence","ran_at":"2026-05-19T17:41:56.056930Z","status":"completed","version":"1.0.0"}],"endpoint":"/pith/2605.15598/integrity.json","findings":[],"snapshot_sha256":"7d55190ddd99fd363114895b31f886272419f4b605ff469e92b91884a68ade35","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Jailbreaking attacks on large language models pose a significant threat to AI safety by enabling the generation of harmful or restricted content. While prior work has explored both handcrafted and automated jailbreak strategies, the potential for compositional interaction between simple attacks remains underexplored. This paper presents a systematic study of mutator chaining, in which weak jailbreak transformations are applied sequentially to characterize how they interact: whether they reinforce one another, interfere destructively, or produce no meaningful change. We implement twelve baselin","authors_text":"Hoon Wei Lim, Reinelle Jan Bugnot, Soohyeon Choi, Yue Duan","cross_cats":["cs.SE"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-15T04:14:04Z","title":"Compositional Jailbreaking: An Empirical Analysis of Mutator Chain Interactions in Aligned LLMs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.15598","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:fef213fca20a093e4b9fd802e391df901e9c3ebc761c6724d1d1a5d099afb1b6","target":"record","created_at":"2026-05-20T00:01:07Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"32e4e051a653bb134b9001ea7b9d3d205b15a85e11daca8726d0dccf733924e0","cross_cats_sorted":["cs.SE"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-15T04:14:04Z","title_canon_sha256":"7dc6e6afb187cfae8cb5c34b54742e4b6a99f0afd83edfde0867494a5ca8c963"},"schema_version":"1.0","source":{"id":"2605.15598","kind":"arxiv","version":1}},"canonical_sha256":"a43c7eeda983925b6e6dd0a45430b140c89af1dd8565877d90c75bc4c9b43933","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"a43c7eeda983925b6e6dd0a45430b140c89af1dd8565877d90c75bc4c9b43933","first_computed_at":"2026-05-20T00:01:07.398061Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T00:01:07.398061Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"xdy8oQWJ/Ff2rpDFOJKthd00r+5FavY6EW7xzv3iWsCs3XUgfo9C+vKmoIBDM38ms8Q9tcr8hnLMvxVCTJO/Cw==","signature_status":"signed_v1","signed_at":"2026-05-20T00:01:07.398857Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.15598","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:fef213fca20a093e4b9fd802e391df901e9c3ebc761c6724d1d1a5d099afb1b6","sha256:d64c9f7639247afbb76dd8a1746b0416e57ab9fa1840551d127c0bc4e612b185"],"state_sha256":"d0df15339a0f891adfa8edc12f769b1bd420c2c290e02d498f92ffdc4f20aa01"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ErjPOTCm+hEc93jJTxaMhT2su9eLcDVpGgK+dWwuCFSZSVW4w5xqFI5opJ0hxSVXa5JhrFI9MnjkUccpq+wEBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T19:28:24.905340Z","bundle_sha256":"93e4e46ea9d6ef34bc9edb98e787c7138bfaf0253a6ca7d6131877762d4e683d"}}