{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:XHPKBRMT6GUKGG46AV64WP2ES2","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0f9f0110d59ef8be8f264776804e1e79711589feb6e957743ab9c10bb2dc6497","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-25T10:24:10Z","title_canon_sha256":"809da94441bd44b3c8572ed71c3cd37b195a5e640e66d56c15a0a919231436cc"},"schema_version":"1.0","source":{"id":"2605.25673","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.25673","created_at":"2026-05-26T02:04:49Z"},{"alias_kind":"arxiv_version","alias_value":"2605.25673v1","created_at":"2026-05-26T02:04:49Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.25673","created_at":"2026-05-26T02:04:49Z"},{"alias_kind":"pith_short_12","alias_value":"XHPKBRMT6GUK","created_at":"2026-05-26T02:04:49Z"},{"alias_kind":"pith_short_16","alias_value":"XHPKBRMT6GUKGG46","created_at":"2026-05-26T02:04:49Z"},{"alias_kind":"pith_short_8","alias_value":"XHPKBRMT","created_at":"2026-05-26T02:04:49Z"}],"graph_snapshots":[{"event_id":"sha256:0244e3e837561ba7fbd5b6657e4f55dea8db1e620f9b0f18966c3f57cc56c26b","target":"graph","created_at":"2026-05-26T02:04:49Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.25673/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Security evaluations inherently depend on stable identifiers. Any finding, audit, or regulatory decision must remain attached to the specific artifact it pertains to. Continuously updated artificial intelligence systems violate this core assumption, with public model designations remaining static while underlying weights, prompts, retrieval mechanisms, misuse classifiers, inference settings, and serving infrastructures undergo unannounced modifications. Consequently, current evaluations frequently apply to superficial labels rather than identifiable and distinct systems.\n  To resolve this, we ","authors_text":"Dan Ristea, Vasilios Mavroudis","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-25T10:24:10Z","title":"Referential Security as a New Paradigm for AI Evaluations"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.25673","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:928bca8470769cbba1c8dfead1d32b26199e3cb5ff5b335b92b4907eb07e4d9f","target":"record","created_at":"2026-05-26T02:04:49Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0f9f0110d59ef8be8f264776804e1e79711589feb6e957743ab9c10bb2dc6497","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-25T10:24:10Z","title_canon_sha256":"809da94441bd44b3c8572ed71c3cd37b195a5e640e66d56c15a0a919231436cc"},"schema_version":"1.0","source":{"id":"2605.25673","kind":"arxiv","version":1}},"canonical_sha256":"b9dea0c593f1a8a31b9e057dcb3f4496b86de28ebc459fb38ccdfbf4e95e0594","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b9dea0c593f1a8a31b9e057dcb3f4496b86de28ebc459fb38ccdfbf4e95e0594","first_computed_at":"2026-05-26T02:04:49.475035Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-26T02:04:49.475035Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"L2KPDkzkFfnIC66XTBBC2cPaWxXRa3pNNjdmzi+wpkfCd5QyRGdciO2b4SkRyGEzVyWF9SQ+XDUJ9umjiwUAAA==","signature_status":"signed_v1","signed_at":"2026-05-26T02:04:49.475790Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.25673","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:928bca8470769cbba1c8dfead1d32b26199e3cb5ff5b335b92b4907eb07e4d9f","sha256:0244e3e837561ba7fbd5b6657e4f55dea8db1e620f9b0f18966c3f57cc56c26b"],"state_sha256":"a71862f5c346759a4cef1fcd95f3ee31f96b378db6fca092c1d0eed7f9ffb5da"}