{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:V2FYZIU4CC5GFVNKOT2PTCHOQX","short_pith_number":"pith:V2FYZIU4","canonical_record":{"source":{"id":"2605.23723","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-22T15:03:13Z","cross_cats_sorted":[],"title_canon_sha256":"55f8fbcb9151e45eba258425e2158687eb3256eba9a1440185291c0288ee6ee9","abstract_canon_sha256":"c0537a00305d266d09ba3cb3746675a4ce7223f7e4d821786b4fcb1e25f4aaa0"},"schema_version":"1.0"},"canonical_sha256":"ae8b8ca29c10ba62d5aa74f4f988ee85e0414dd77075c60527f28db76a43bdd1","source":{"kind":"arxiv","id":"2605.23723","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.23723","created_at":"2026-05-25T02:02:28Z"},{"alias_kind":"arxiv_version","alias_value":"2605.23723v1","created_at":"2026-05-25T02:02:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.23723","created_at":"2026-05-25T02:02:28Z"},{"alias_kind":"pith_short_12","alias_value":"V2FYZIU4CC5G","created_at":"2026-05-25T02:02:28Z"},{"alias_kind":"pith_short_16","alias_value":"V2FYZIU4CC5GFVNK","created_at":"2026-05-25T02:02:28Z"},{"alias_kind":"pith_short_8","alias_value":"V2FYZIU4","created_at":"2026-05-25T02:02:28Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:V2FYZIU4CC5GFVNKOT2PTCHOQX","target":"record","payload":{"canonical_record":{"source":{"id":"2605.23723","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-22T15:03:13Z","cross_cats_sorted":[],"title_canon_sha256":"55f8fbcb9151e45eba258425e2158687eb3256eba9a1440185291c0288ee6ee9","abstract_canon_sha256":"c0537a00305d266d09ba3cb3746675a4ce7223f7e4d821786b4fcb1e25f4aaa0"},"schema_version":"1.0"},"canonical_sha256":"ae8b8ca29c10ba62d5aa74f4f988ee85e0414dd77075c60527f28db76a43bdd1","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-25T02:02:28.537392Z","signature_b64":"1iQh9DBPc6BHejH9NSnJM6fpPnyMOXL2yl06AR2AVMLY7kqToQUV1PI0LQfm9EC+TavjA02L/VNhsNCQEiQ+Aw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ae8b8ca29c10ba62d5aa74f4f988ee85e0414dd77075c60527f28db76a43bdd1","last_reissued_at":"2026-05-25T02:02:28.536770Z","signature_status":"signed_v1","first_computed_at":"2026-05-25T02:02:28.536770Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.23723","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-25T02:02:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"o7KqSbo/HjS5EOa2a6/lCq6npxuRey17zvDZsPMAzyNnboGb9j05H7u4fIhH0gKV/Spw+mjoXaGd6juLls1KDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T17:21:12.021618Z"},"content_sha256":"bbe70e342d74e95934564f5226ca21ea670aeae896c5387ae6f8368131d8e4d2","schema_version":"1.0","event_id":"sha256:bbe70e342d74e95934564f5226ca21ea670aeae896c5387ae6f8368131d8e4d2"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:V2FYZIU4CC5GFVNKOT2PTCHOQX","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"MemAudit: Post-hoc Auditing of Poisoned Agent Memory via Causal Attribution and Structural Anomaly Detection","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.AI","authors_text":"Duohe Ma, Feng Liu, Guoan Wang, Huiyan Jin, Liang Lu, Lin Sun, Mengyuan Fan, Tong Yang, Wenhan Yu, Xiangzheng Zhang, Yilun Yao, Zhewen Tan","submitted_at":"2026-05-22T15:03:13Z","abstract_excerpt":"Large language model agents increasingly rely on persistent memory to store past interactions, retrieve relevant demonstrations, and improve long-horizon task execution. However, this memory mechanism also creates a practical security vulnerability: an adversarial user may inject malicious records into the agent's memory through ordinary interaction, and these records can later be retrieved to steer the agent's reasoning and actions. Existing defenses primarily focus on online intervention, such as prompt filtering or output blocking, but they do not address the post-hoc question of which stor"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.23723","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.23723/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-25T02:02:28Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jbha7qir+cobbwcPqqjgXuxHGET7Ah1oJnbM5yDeVp9Di5oNhmoqYK17IcKCL6pxllZ1QArr+yBbJ/ptyzqqCQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T17:21:12.022369Z"},"content_sha256":"75d1d2eb560fd18042e0395e7629f868c1a9eec844cbfcd5bb573440c68e6dde","schema_version":"1.0","event_id":"sha256:75d1d2eb560fd18042e0395e7629f868c1a9eec844cbfcd5bb573440c68e6dde"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/V2FYZIU4CC5GFVNKOT2PTCHOQX/bundle.json","state_url":"https://pith.science/pith/V2FYZIU4CC5GFVNKOT2PTCHOQX/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/V2FYZIU4CC5GFVNKOT2PTCHOQX/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T17:21:12Z","links":{"resolver":"https://pith.science/pith/V2FYZIU4CC5GFVNKOT2PTCHOQX","bundle":"https://pith.science/pith/V2FYZIU4CC5GFVNKOT2PTCHOQX/bundle.json","state":"https://pith.science/pith/V2FYZIU4CC5GFVNKOT2PTCHOQX/state.json","well_known_bundle":"https://pith.science/.well-known/pith/V2FYZIU4CC5GFVNKOT2PTCHOQX/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:V2FYZIU4CC5GFVNKOT2PTCHOQX","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"c0537a00305d266d09ba3cb3746675a4ce7223f7e4d821786b4fcb1e25f4aaa0","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-22T15:03:13Z","title_canon_sha256":"55f8fbcb9151e45eba258425e2158687eb3256eba9a1440185291c0288ee6ee9"},"schema_version":"1.0","source":{"id":"2605.23723","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.23723","created_at":"2026-05-25T02:02:28Z"},{"alias_kind":"arxiv_version","alias_value":"2605.23723v1","created_at":"2026-05-25T02:02:28Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.23723","created_at":"2026-05-25T02:02:28Z"},{"alias_kind":"pith_short_12","alias_value":"V2FYZIU4CC5G","created_at":"2026-05-25T02:02:28Z"},{"alias_kind":"pith_short_16","alias_value":"V2FYZIU4CC5GFVNK","created_at":"2026-05-25T02:02:28Z"},{"alias_kind":"pith_short_8","alias_value":"V2FYZIU4","created_at":"2026-05-25T02:02:28Z"}],"graph_snapshots":[{"event_id":"sha256:75d1d2eb560fd18042e0395e7629f868c1a9eec844cbfcd5bb573440c68e6dde","target":"graph","created_at":"2026-05-25T02:02:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.23723/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language model agents increasingly rely on persistent memory to store past interactions, retrieve relevant demonstrations, and improve long-horizon task execution. However, this memory mechanism also creates a practical security vulnerability: an adversarial user may inject malicious records into the agent's memory through ordinary interaction, and these records can later be retrieved to steer the agent's reasoning and actions. Existing defenses primarily focus on online intervention, such as prompt filtering or output blocking, but they do not address the post-hoc question of which stor","authors_text":"Duohe Ma, Feng Liu, Guoan Wang, Huiyan Jin, Liang Lu, Lin Sun, Mengyuan Fan, Tong Yang, Wenhan Yu, Xiangzheng Zhang, Yilun Yao, Zhewen Tan","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-22T15:03:13Z","title":"MemAudit: Post-hoc Auditing of Poisoned Agent Memory via Causal Attribution and Structural Anomaly Detection"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.23723","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:bbe70e342d74e95934564f5226ca21ea670aeae896c5387ae6f8368131d8e4d2","target":"record","created_at":"2026-05-25T02:02:28Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"c0537a00305d266d09ba3cb3746675a4ce7223f7e4d821786b4fcb1e25f4aaa0","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-05-22T15:03:13Z","title_canon_sha256":"55f8fbcb9151e45eba258425e2158687eb3256eba9a1440185291c0288ee6ee9"},"schema_version":"1.0","source":{"id":"2605.23723","kind":"arxiv","version":1}},"canonical_sha256":"ae8b8ca29c10ba62d5aa74f4f988ee85e0414dd77075c60527f28db76a43bdd1","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"ae8b8ca29c10ba62d5aa74f4f988ee85e0414dd77075c60527f28db76a43bdd1","first_computed_at":"2026-05-25T02:02:28.536770Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-25T02:02:28.536770Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"1iQh9DBPc6BHejH9NSnJM6fpPnyMOXL2yl06AR2AVMLY7kqToQUV1PI0LQfm9EC+TavjA02L/VNhsNCQEiQ+Aw==","signature_status":"signed_v1","signed_at":"2026-05-25T02:02:28.537392Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.23723","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:bbe70e342d74e95934564f5226ca21ea670aeae896c5387ae6f8368131d8e4d2","sha256:75d1d2eb560fd18042e0395e7629f868c1a9eec844cbfcd5bb573440c68e6dde"],"state_sha256":"07f3a4eea668f767e594b07db75d543e30040842722a29fe948c7a13273a5681"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"NJa12xptxFw1sscOSuWTsnBuDuAoeNw2TjET2XYGIkukUhh8q4k38C4FL30Ntk3ewXV5SS2Ju0RFQsFscgbhBg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T17:21:12.026464Z","bundle_sha256":"871aa1bd9f3e58964c5021dbcca4069feddf32c658c6fe5b2856ee9ae7c5a8a0"}}