{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:XGNOJDYWGTYWRGNMVZHN2LHUGC","short_pith_number":"pith:XGNOJDYW","canonical_record":{"source":{"id":"2503.24191","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-31T15:08:06Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"53f3c3f6dbd606059d28954f4f844f4c0ac8989739bece38ff58105bb3b6ff58","abstract_canon_sha256":"7e4cb09699cd9d574ac4c0ce7d3e35d01ddde6b71c7ddb96d5ac748784b6cef1"},"schema_version":"1.0"},"canonical_sha256":"b99ae48f1634f16899acae4edd2cf430a4125f0102ca3b741d6da9b84a768e65","source":{"kind":"arxiv","id":"2503.24191","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2503.24191","created_at":"2026-05-22T01:03:42Z"},{"alias_kind":"arxiv_version","alias_value":"2503.24191v3","created_at":"2026-05-22T01:03:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.24191","created_at":"2026-05-22T01:03:42Z"},{"alias_kind":"pith_short_12","alias_value":"XGNOJDYWGTYW","created_at":"2026-05-22T01:03:42Z"},{"alias_kind":"pith_short_16","alias_value":"XGNOJDYWGTYWRGNM","created_at":"2026-05-22T01:03:42Z"},{"alias_kind":"pith_short_8","alias_value":"XGNOJDYW","created_at":"2026-05-22T01:03:42Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:XGNOJDYWGTYWRGNMVZHN2LHUGC","target":"record","payload":{"canonical_record":{"source":{"id":"2503.24191","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-31T15:08:06Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"53f3c3f6dbd606059d28954f4f844f4c0ac8989739bece38ff58105bb3b6ff58","abstract_canon_sha256":"7e4cb09699cd9d574ac4c0ce7d3e35d01ddde6b71c7ddb96d5ac748784b6cef1"},"schema_version":"1.0"},"canonical_sha256":"b99ae48f1634f16899acae4edd2cf430a4125f0102ca3b741d6da9b84a768e65","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-22T01:03:42.468015Z","signature_b64":"BgYa34zkzmCmTnu2ehtKuh98A8wWGWJbmmFh8gtHl8xuMpKybR6YwE+zpkNLnp6n/eKQovOxpVWhFNhJdm3lAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b99ae48f1634f16899acae4edd2cf430a4125f0102ca3b741d6da9b84a768e65","last_reissued_at":"2026-05-22T01:03:42.467016Z","signature_status":"signed_v1","first_computed_at":"2026-05-22T01:03:42.467016Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2503.24191","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:03:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"m34EZ4XJ5Hlr/Zb4tGBll2/8HN3CZbYk5Hu3/9vOjkjx3ZUlaEF1pa4kdygQkeuwvHUXr6dIP5kh8mjk4vIiDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T19:20:14.467036Z"},"content_sha256":"a141360c2cc23306b4d409a8c26715c1bf9df307e08c43a45e628bd34202950b","schema_version":"1.0","event_id":"sha256:a141360c2cc23306b4d409a8c26715c1bf9df307e08c43a45e628bd34202950b"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:XGNOJDYWGTYWRGNMVZHN2LHUGC","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"When Grammar Guides the Attack: Uncovering Control-Plane Vulnerabilities in LLMs with Structured Output","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Chunwei Xia, Hanyuan Dong, Huimin Cui, Jiacheng Zhao, Ruiyuan Xu, Shuaijiang Li, Shuoming Zhang, Xiaobing Feng, Yangyu Zhang, Yuan Wen, Zheng Wang, Zhicheng Li","submitted_at":"2025-03-31T15:08:06Z","abstract_excerpt":"Content Warning: This paper may contain unsafe or harmful content generated by LLMs that may be offensive to readers. Large Language Models (LLMs) increasingly serve as tooling platforms through structured output APIs, but the grammar-guided decoding that powers this feature opens a critical control-plane attack surface orthogonal to traditional data-plane vulnerabilities. We introduce Constrained Decoding Attack (CDA), a new jailbreak class that targets the LLM control plane. CDA is best characterized as a control-to-semantic pipeline: (1) schema-enforced logit masking injects a malicious pre"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.24191","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2503.24191/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-22T01:03:42Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"cpD12kYGYgZnbT7kH0IoxV3+lc+TlH33bl+/Y/9C1+L5yV5dIHqEhjLJtEUAF6XBD1LxzS//QJZeT1PDdXHqAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-05-27T19:20:14.467807Z"},"content_sha256":"f2d14091aa7a50d2e621106049a29878c83a76beb67127af6c9d4c729a8754c8","schema_version":"1.0","event_id":"sha256:f2d14091aa7a50d2e621106049a29878c83a76beb67127af6c9d4c729a8754c8"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/XGNOJDYWGTYWRGNMVZHN2LHUGC/bundle.json","state_url":"https://pith.science/pith/XGNOJDYWGTYWRGNMVZHN2LHUGC/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/XGNOJDYWGTYWRGNMVZHN2LHUGC/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-05-27T19:20:14Z","links":{"resolver":"https://pith.science/pith/XGNOJDYWGTYWRGNMVZHN2LHUGC","bundle":"https://pith.science/pith/XGNOJDYWGTYWRGNMVZHN2LHUGC/bundle.json","state":"https://pith.science/pith/XGNOJDYWGTYWRGNMVZHN2LHUGC/state.json","well_known_bundle":"https://pith.science/.well-known/pith/XGNOJDYWGTYWRGNMVZHN2LHUGC/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:XGNOJDYWGTYWRGNMVZHN2LHUGC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"7e4cb09699cd9d574ac4c0ce7d3e35d01ddde6b71c7ddb96d5ac748784b6cef1","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-31T15:08:06Z","title_canon_sha256":"53f3c3f6dbd606059d28954f4f844f4c0ac8989739bece38ff58105bb3b6ff58"},"schema_version":"1.0","source":{"id":"2503.24191","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2503.24191","created_at":"2026-05-22T01:03:42Z"},{"alias_kind":"arxiv_version","alias_value":"2503.24191v3","created_at":"2026-05-22T01:03:42Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2503.24191","created_at":"2026-05-22T01:03:42Z"},{"alias_kind":"pith_short_12","alias_value":"XGNOJDYWGTYW","created_at":"2026-05-22T01:03:42Z"},{"alias_kind":"pith_short_16","alias_value":"XGNOJDYWGTYWRGNM","created_at":"2026-05-22T01:03:42Z"},{"alias_kind":"pith_short_8","alias_value":"XGNOJDYW","created_at":"2026-05-22T01:03:42Z"}],"graph_snapshots":[{"event_id":"sha256:f2d14091aa7a50d2e621106049a29878c83a76beb67127af6c9d4c729a8754c8","target":"graph","created_at":"2026-05-22T01:03:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2503.24191/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Content Warning: This paper may contain unsafe or harmful content generated by LLMs that may be offensive to readers. Large Language Models (LLMs) increasingly serve as tooling platforms through structured output APIs, but the grammar-guided decoding that powers this feature opens a critical control-plane attack surface orthogonal to traditional data-plane vulnerabilities. We introduce Constrained Decoding Attack (CDA), a new jailbreak class that targets the LLM control plane. CDA is best characterized as a control-to-semantic pipeline: (1) schema-enforced logit masking injects a malicious pre","authors_text":"Chunwei Xia, Hanyuan Dong, Huimin Cui, Jiacheng Zhao, Ruiyuan Xu, Shuaijiang Li, Shuoming Zhang, Xiaobing Feng, Yangyu Zhang, Yuan Wen, Zheng Wang, Zhicheng Li","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-31T15:08:06Z","title":"When Grammar Guides the Attack: Uncovering Control-Plane Vulnerabilities in LLMs with Structured Output"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2503.24191","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:a141360c2cc23306b4d409a8c26715c1bf9df307e08c43a45e628bd34202950b","target":"record","created_at":"2026-05-22T01:03:42Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"7e4cb09699cd9d574ac4c0ce7d3e35d01ddde6b71c7ddb96d5ac748784b6cef1","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2025-03-31T15:08:06Z","title_canon_sha256":"53f3c3f6dbd606059d28954f4f844f4c0ac8989739bece38ff58105bb3b6ff58"},"schema_version":"1.0","source":{"id":"2503.24191","kind":"arxiv","version":3}},"canonical_sha256":"b99ae48f1634f16899acae4edd2cf430a4125f0102ca3b741d6da9b84a768e65","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b99ae48f1634f16899acae4edd2cf430a4125f0102ca3b741d6da9b84a768e65","first_computed_at":"2026-05-22T01:03:42.467016Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-22T01:03:42.467016Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"BgYa34zkzmCmTnu2ehtKuh98A8wWGWJbmmFh8gtHl8xuMpKybR6YwE+zpkNLnp6n/eKQovOxpVWhFNhJdm3lAg==","signature_status":"signed_v1","signed_at":"2026-05-22T01:03:42.468015Z","signed_message":"canonical_sha256_bytes"},"source_id":"2503.24191","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:a141360c2cc23306b4d409a8c26715c1bf9df307e08c43a45e628bd34202950b","sha256:f2d14091aa7a50d2e621106049a29878c83a76beb67127af6c9d4c729a8754c8"],"state_sha256":"d75bc7821de0716d7e121b6cff0c18bdf4b6b6d489c8b2cad34f4ae0b2ba8560"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"s7dQ2FpPEwn5eZfIqYkNfqNIFDPJf6TJe/FajIRXPtP3yuOUWC42NmG4FQ3TH7c3ANCbxYSa9Vu2F+4MlwRVDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-05-27T19:20:14.471654Z","bundle_sha256":"6149b67accf9bbd422d593ada33ad0ea96d41135442ccd87b584583381027b0d"}}