{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:WNBEQELZK2R4QL63IHBERY6UP6","short_pith_number":"pith:WNBEQELZ","canonical_record":{"source":{"id":"2605.19240","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.MA","submitted_at":"2026-05-19T01:16:27Z","cross_cats_sorted":[],"title_canon_sha256":"b94eb4e6e75ce4f18d16802b3b33b2ae76e449406fc37bc12b973d4fb00197ce","abstract_canon_sha256":"00dca76eea436f9256529eed39b3db640f81ebdcc018a07430079f8f11b02353"},"schema_version":"1.0"},"canonical_sha256":"b34248117956a3c82fdb41c248e3d47f8d457c9a1f24684b5c3639d97655038e","source":{"kind":"arxiv","id":"2605.19240","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.19240","created_at":"2026-05-20T01:05:35Z"},{"alias_kind":"arxiv_version","alias_value":"2605.19240v1","created_at":"2026-05-20T01:05:35Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.19240","created_at":"2026-05-20T01:05:35Z"},{"alias_kind":"pith_short_12","alias_value":"WNBEQELZK2R4","created_at":"2026-05-20T01:05:35Z"},{"alias_kind":"pith_short_16","alias_value":"WNBEQELZK2R4QL63","created_at":"2026-05-20T01:05:35Z"},{"alias_kind":"pith_short_8","alias_value":"WNBEQELZ","created_at":"2026-05-20T01:05:35Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:WNBEQELZK2R4QL63IHBERY6UP6","target":"record","payload":{"canonical_record":{"source":{"id":"2605.19240","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.MA","submitted_at":"2026-05-19T01:16:27Z","cross_cats_sorted":[],"title_canon_sha256":"b94eb4e6e75ce4f18d16802b3b33b2ae76e449406fc37bc12b973d4fb00197ce","abstract_canon_sha256":"00dca76eea436f9256529eed39b3db640f81ebdcc018a07430079f8f11b02353"},"schema_version":"1.0"},"canonical_sha256":"b34248117956a3c82fdb41c248e3d47f8d457c9a1f24684b5c3639d97655038e","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-20T01:05:35.315579Z","signature_b64":"iWM8oh9ivQHQ6JfliKmAJd6GGiR9+vw8OUpKoRag9i7O9NzRA4mLOpIVSiJegu2drMjpeiJ5JgDvI2BbdN1sBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b34248117956a3c82fdb41c248e3d47f8d457c9a1f24684b5c3639d97655038e","last_reissued_at":"2026-05-20T01:05:35.314993Z","signature_status":"signed_v1","first_computed_at":"2026-05-20T01:05:35.314993Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.19240","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T01:05:35Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZTOMJvA+fIgWCQ7EfQxXAzdlppvgOIICbhSPJ4miicrVWSuvn1H+mi6AagTs4O3NsRFwIUfTYUSJpuLVpuG6DA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T20:24:09.770801Z"},"content_sha256":"c44af1987b6dd56edef6395e4bceee37720479f51e1c0ba001790c1739da2859","schema_version":"1.0","event_id":"sha256:c44af1987b6dd56edef6395e4bceee37720479f51e1c0ba001790c1739da2859"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:WNBEQELZK2R4QL63IHBERY6UP6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"CASPIAN: Online Detection and Attribution of Cascade Attacks in LLM Multi-Agent Systems via Cross-Channel Causal Monitoring","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.MA","authors_text":"Jafar Isbarov, Jiaming Cui, Kavana Venkatesh, Murat Kantarcioglu, Saad Amin","submitted_at":"2026-05-19T01:16:27Z","abstract_excerpt":"Cascade attacks in LLM multi-agent systems (MAS) arise when adversarial influence propagates across agents and leads to escalated system-level failures through complex agent interactions. Detecting such cascades is challenging, as their signals are distributed, tightly coupled across interaction channels, and often appear plausibly benign locally but may unfold quickly either within a single turn or gradually across multiple turns. Existing defenses, being largely local and text-centric, fail to capture such cross-channel, temporally coordinated dynamics of cascade propagation. Therefore, we p"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.19240","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.19240/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-20T01:05:35Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"PVqJg9a5Tbq1zXSskJbHwT6HLMzcIZcDgKFNhU27G5bssEQ2zpp6+xcSaaHcgcpAJJOa4sn0dBhSonX3fclGAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-25T20:24:09.771574Z"},"content_sha256":"6d8d81c828010185ea9862d96f4870135559264c1ed824c6a8c08d42e91c5c0f","schema_version":"1.0","event_id":"sha256:6d8d81c828010185ea9862d96f4870135559264c1ed824c6a8c08d42e91c5c0f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/WNBEQELZK2R4QL63IHBERY6UP6/bundle.json","state_url":"https://pith.science/pith/WNBEQELZK2R4QL63IHBERY6UP6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/WNBEQELZK2R4QL63IHBERY6UP6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-25T20:24:09Z","links":{"resolver":"https://pith.science/pith/WNBEQELZK2R4QL63IHBERY6UP6","bundle":"https://pith.science/pith/WNBEQELZK2R4QL63IHBERY6UP6/bundle.json","state":"https://pith.science/pith/WNBEQELZK2R4QL63IHBERY6UP6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/WNBEQELZK2R4QL63IHBERY6UP6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:WNBEQELZK2R4QL63IHBERY6UP6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"00dca76eea436f9256529eed39b3db640f81ebdcc018a07430079f8f11b02353","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.MA","submitted_at":"2026-05-19T01:16:27Z","title_canon_sha256":"b94eb4e6e75ce4f18d16802b3b33b2ae76e449406fc37bc12b973d4fb00197ce"},"schema_version":"1.0","source":{"id":"2605.19240","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.19240","created_at":"2026-05-20T01:05:35Z"},{"alias_kind":"arxiv_version","alias_value":"2605.19240v1","created_at":"2026-05-20T01:05:35Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.19240","created_at":"2026-05-20T01:05:35Z"},{"alias_kind":"pith_short_12","alias_value":"WNBEQELZK2R4","created_at":"2026-05-20T01:05:35Z"},{"alias_kind":"pith_short_16","alias_value":"WNBEQELZK2R4QL63","created_at":"2026-05-20T01:05:35Z"},{"alias_kind":"pith_short_8","alias_value":"WNBEQELZ","created_at":"2026-05-20T01:05:35Z"}],"graph_snapshots":[{"event_id":"sha256:6d8d81c828010185ea9862d96f4870135559264c1ed824c6a8c08d42e91c5c0f","target":"graph","created_at":"2026-05-20T01:05:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.19240/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Cascade attacks in LLM multi-agent systems (MAS) arise when adversarial influence propagates across agents and leads to escalated system-level failures through complex agent interactions. Detecting such cascades is challenging, as their signals are distributed, tightly coupled across interaction channels, and often appear plausibly benign locally but may unfold quickly either within a single turn or gradually across multiple turns. Existing defenses, being largely local and text-centric, fail to capture such cross-channel, temporally coordinated dynamics of cascade propagation. Therefore, we p","authors_text":"Jafar Isbarov, Jiaming Cui, Kavana Venkatesh, Murat Kantarcioglu, Saad Amin","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.MA","submitted_at":"2026-05-19T01:16:27Z","title":"CASPIAN: Online Detection and Attribution of Cascade Attacks in LLM Multi-Agent Systems via Cross-Channel Causal Monitoring"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.19240","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:c44af1987b6dd56edef6395e4bceee37720479f51e1c0ba001790c1739da2859","target":"record","created_at":"2026-05-20T01:05:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"00dca76eea436f9256529eed39b3db640f81ebdcc018a07430079f8f11b02353","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.MA","submitted_at":"2026-05-19T01:16:27Z","title_canon_sha256":"b94eb4e6e75ce4f18d16802b3b33b2ae76e449406fc37bc12b973d4fb00197ce"},"schema_version":"1.0","source":{"id":"2605.19240","kind":"arxiv","version":1}},"canonical_sha256":"b34248117956a3c82fdb41c248e3d47f8d457c9a1f24684b5c3639d97655038e","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b34248117956a3c82fdb41c248e3d47f8d457c9a1f24684b5c3639d97655038e","first_computed_at":"2026-05-20T01:05:35.314993Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-20T01:05:35.314993Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"iWM8oh9ivQHQ6JfliKmAJd6GGiR9+vw8OUpKoRag9i7O9NzRA4mLOpIVSiJegu2drMjpeiJ5JgDvI2BbdN1sBQ==","signature_status":"signed_v1","signed_at":"2026-05-20T01:05:35.315579Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.19240","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:c44af1987b6dd56edef6395e4bceee37720479f51e1c0ba001790c1739da2859","sha256:6d8d81c828010185ea9862d96f4870135559264c1ed824c6a8c08d42e91c5c0f"],"state_sha256":"64b76ef9763d22b180e07fb449d10551e861121d896614797083cbfc93f22717"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"aXzDlhz+zEIUdenq4+uHVdSyIdQd0n46eN3arus28xm81CTHMvWCuvczi8re+DNyogSQnHGvc043w4iVfA+IAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-25T20:24:09.775758Z","bundle_sha256":"f4075cb7541ff30489e67b08eaf1dbac5fb258cb1a487e4d84aa3af12674b4f1"}}