{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:X5UAB5UQH34LIQX6E4QTWAAIHB","short_pith_number":"pith:X5UAB5UQ","canonical_record":{"source":{"id":"2606.25182","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-06-23T21:14:53Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"93c9addc9526ca95f34b06e3c1f96370d5e2d6cd91baa8464f7809619cafa221","abstract_canon_sha256":"06b1f381d7e046b2bd588a21bb9b89f4366a262338b2719429f498ba5ab90a89"},"schema_version":"1.0"},"canonical_sha256":"bf6800f6903ef8b442fe27213b0008384bb2e0d1b882ed3fdf1fefddf0de7968","source":{"kind":"arxiv","id":"2606.25182","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.25182","created_at":"2026-06-25T00:18:20Z"},{"alias_kind":"arxiv_version","alias_value":"2606.25182v1","created_at":"2026-06-25T00:18:20Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.25182","created_at":"2026-06-25T00:18:20Z"},{"alias_kind":"pith_short_12","alias_value":"X5UAB5UQH34L","created_at":"2026-06-25T00:18:20Z"},{"alias_kind":"pith_short_16","alias_value":"X5UAB5UQH34LIQX6","created_at":"2026-06-25T00:18:20Z"},{"alias_kind":"pith_short_8","alias_value":"X5UAB5UQ","created_at":"2026-06-25T00:18:20Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:X5UAB5UQH34LIQX6E4QTWAAIHB","target":"record","payload":{"canonical_record":{"source":{"id":"2606.25182","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-06-23T21:14:53Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"93c9addc9526ca95f34b06e3c1f96370d5e2d6cd91baa8464f7809619cafa221","abstract_canon_sha256":"06b1f381d7e046b2bd588a21bb9b89f4366a262338b2719429f498ba5ab90a89"},"schema_version":"1.0"},"canonical_sha256":"bf6800f6903ef8b442fe27213b0008384bb2e0d1b882ed3fdf1fefddf0de7968","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-25T00:18:20.235257Z","signature_b64":"f1zs3TpI6FfmVgZYMXq8JQnrMDqMNogZ2+mFxAJh5dYbXgAMMYKBnFQ9hGKES+0nFFDqUx+zK3Os9k+oaVmsBQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"bf6800f6903ef8b442fe27213b0008384bb2e0d1b882ed3fdf1fefddf0de7968","last_reissued_at":"2026-06-25T00:18:20.234894Z","signature_status":"signed_v1","first_computed_at":"2026-06-25T00:18:20.234894Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.25182","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-25T00:18:20Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"jqshM8gFQodzV1Q4TGT6ypaHyf4taaUP9eM7nj42q7ApCSw9IMylYA8ROJQw06E/zXgTrTm9m5y+dU4j8YNJBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T22:48:39.825530Z"},"content_sha256":"9d20d6c705e5b4b01da2465f69ac3e7859700daf14a0c9d374c93a3e8f78f53b","schema_version":"1.0","event_id":"sha256:9d20d6c705e5b4b01da2465f69ac3e7859700daf14a0c9d374c93a3e8f78f53b"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:X5UAB5UQH34LIQX6E4QTWAAIHB","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"What Intermediate Layers Know: Detecting Jailbreaks from Entropy Dynamics","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CL","authors_text":"Michele Papucci, Mina Rezaei, Shireen Kudukkil Manchingal, Sofiia Nikolenko","submitted_at":"2026-06-23T21:14:53Z","abstract_excerpt":"Jailbreak attacks reveal a persistent weakness in aligned Large Language Models: carefully crafted prompts can elicit policy-violating responses despite safety training. While most defenses operate at the prompt or output level, it remains unclear how harmful intent is encoded within the model's internal representations. We investigate this question by analyzing token-level predictive entropy trajectories across layers of a frozen LLM using the logit lens. We find that static aggregate statistics of prompt-level entropy (e.g., mean, variance) carry little discriminative signal, whereas feature"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.25182","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.25182/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-25T00:18:20Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"3KPQsR7dWnXw7D7Trp+2U4FOTnKEdQfIod20sJcdOQwn3Njuck+7VKgAWT2cVz8WqiiLCKxTX5esYZvyrGz1DQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T22:48:39.825894Z"},"content_sha256":"a52bf8bc6f204a52c1e6d7cd66ce267cf5a4281d643163e9285bffa8be346732","schema_version":"1.0","event_id":"sha256:a52bf8bc6f204a52c1e6d7cd66ce267cf5a4281d643163e9285bffa8be346732"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/X5UAB5UQH34LIQX6E4QTWAAIHB/bundle.json","state_url":"https://pith.science/pith/X5UAB5UQH34LIQX6E4QTWAAIHB/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/X5UAB5UQH34LIQX6E4QTWAAIHB/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-27T22:48:39Z","links":{"resolver":"https://pith.science/pith/X5UAB5UQH34LIQX6E4QTWAAIHB","bundle":"https://pith.science/pith/X5UAB5UQH34LIQX6E4QTWAAIHB/bundle.json","state":"https://pith.science/pith/X5UAB5UQH34LIQX6E4QTWAAIHB/state.json","well_known_bundle":"https://pith.science/.well-known/pith/X5UAB5UQH34LIQX6E4QTWAAIHB/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:X5UAB5UQH34LIQX6E4QTWAAIHB","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"06b1f381d7e046b2bd588a21bb9b89f4366a262338b2719429f498ba5ab90a89","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-06-23T21:14:53Z","title_canon_sha256":"93c9addc9526ca95f34b06e3c1f96370d5e2d6cd91baa8464f7809619cafa221"},"schema_version":"1.0","source":{"id":"2606.25182","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.25182","created_at":"2026-06-25T00:18:20Z"},{"alias_kind":"arxiv_version","alias_value":"2606.25182v1","created_at":"2026-06-25T00:18:20Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.25182","created_at":"2026-06-25T00:18:20Z"},{"alias_kind":"pith_short_12","alias_value":"X5UAB5UQH34L","created_at":"2026-06-25T00:18:20Z"},{"alias_kind":"pith_short_16","alias_value":"X5UAB5UQH34LIQX6","created_at":"2026-06-25T00:18:20Z"},{"alias_kind":"pith_short_8","alias_value":"X5UAB5UQ","created_at":"2026-06-25T00:18:20Z"}],"graph_snapshots":[{"event_id":"sha256:a52bf8bc6f204a52c1e6d7cd66ce267cf5a4281d643163e9285bffa8be346732","target":"graph","created_at":"2026-06-25T00:18:20Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.25182/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Jailbreak attacks reveal a persistent weakness in aligned Large Language Models: carefully crafted prompts can elicit policy-violating responses despite safety training. While most defenses operate at the prompt or output level, it remains unclear how harmful intent is encoded within the model's internal representations. We investigate this question by analyzing token-level predictive entropy trajectories across layers of a frozen LLM using the logit lens. We find that static aggregate statistics of prompt-level entropy (e.g., mean, variance) carry little discriminative signal, whereas feature","authors_text":"Michele Papucci, Mina Rezaei, Shireen Kudukkil Manchingal, Sofiia Nikolenko","cross_cats":["cs.AI","cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-06-23T21:14:53Z","title":"What Intermediate Layers Know: Detecting Jailbreaks from Entropy Dynamics"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.25182","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:9d20d6c705e5b4b01da2465f69ac3e7859700daf14a0c9d374c93a3e8f78f53b","target":"record","created_at":"2026-06-25T00:18:20Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"06b1f381d7e046b2bd588a21bb9b89f4366a262338b2719429f498ba5ab90a89","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-06-23T21:14:53Z","title_canon_sha256":"93c9addc9526ca95f34b06e3c1f96370d5e2d6cd91baa8464f7809619cafa221"},"schema_version":"1.0","source":{"id":"2606.25182","kind":"arxiv","version":1}},"canonical_sha256":"bf6800f6903ef8b442fe27213b0008384bb2e0d1b882ed3fdf1fefddf0de7968","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"bf6800f6903ef8b442fe27213b0008384bb2e0d1b882ed3fdf1fefddf0de7968","first_computed_at":"2026-06-25T00:18:20.234894Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-25T00:18:20.234894Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"f1zs3TpI6FfmVgZYMXq8JQnrMDqMNogZ2+mFxAJh5dYbXgAMMYKBnFQ9hGKES+0nFFDqUx+zK3Os9k+oaVmsBQ==","signature_status":"signed_v1","signed_at":"2026-06-25T00:18:20.235257Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.25182","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:9d20d6c705e5b4b01da2465f69ac3e7859700daf14a0c9d374c93a3e8f78f53b","sha256:a52bf8bc6f204a52c1e6d7cd66ce267cf5a4281d643163e9285bffa8be346732"],"state_sha256":"b5e84427f1b20d1a3fdd00522acef72b5c7fd0707a8b78d00a2c46327ca99bc0"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"HflxPv4oWfXB6v4UOhiYtFVjhMkIGSzxLSzM3lzxjkpdKnwdhFpZfjoCJAIlzS3I11oGspqYePM226mKbEfxBQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-27T22:48:39.827874Z","bundle_sha256":"b992315654c3da2f52972eea7bd8c34df122ac8748f96f91264897f98f828c6a"}}