{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:Y5XGOJPOQRN3QZYS5G3HBB65RE","short_pith_number":"pith:Y5XGOJPO","canonical_record":{"source":{"id":"2607.00362","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T03:00:30Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"dbfc160548c3ef547622c7f75be5a07f8912388213e1acc01905a3961392abe5","abstract_canon_sha256":"e38dc8f2bc92cee781a03e57a9664be37a854b7e9e8f733bd69496b727ec4e52"},"schema_version":"1.0"},"canonical_sha256":"c76e6725ee845bb86712e9b67087dd891f6b08be4d8eadfd0e9def59874c460e","source":{"kind":"arxiv","id":"2607.00362","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2607.00362","created_at":"2026-07-02T01:17:41Z"},{"alias_kind":"arxiv_version","alias_value":"2607.00362v1","created_at":"2026-07-02T01:17:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.00362","created_at":"2026-07-02T01:17:41Z"},{"alias_kind":"pith_short_12","alias_value":"Y5XGOJPOQRN3","created_at":"2026-07-02T01:17:41Z"},{"alias_kind":"pith_short_16","alias_value":"Y5XGOJPOQRN3QZYS","created_at":"2026-07-02T01:17:41Z"},{"alias_kind":"pith_short_8","alias_value":"Y5XGOJPO","created_at":"2026-07-02T01:17:41Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:Y5XGOJPOQRN3QZYS5G3HBB65RE","target":"record","payload":{"canonical_record":{"source":{"id":"2607.00362","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T03:00:30Z","cross_cats_sorted":["cs.AI","cs.LG"],"title_canon_sha256":"dbfc160548c3ef547622c7f75be5a07f8912388213e1acc01905a3961392abe5","abstract_canon_sha256":"e38dc8f2bc92cee781a03e57a9664be37a854b7e9e8f733bd69496b727ec4e52"},"schema_version":"1.0"},"canonical_sha256":"c76e6725ee845bb86712e9b67087dd891f6b08be4d8eadfd0e9def59874c460e","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-02T01:17:41.181390Z","signature_b64":"kYWDJO1tpbKiJKtEiTB1yTnQseojrP0B/rHDn8f0mPArzyrJwod5wHVOcOqahl2Jm4Oc0Mrv0s8fyFkvrN6cCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c76e6725ee845bb86712e9b67087dd891f6b08be4d8eadfd0e9def59874c460e","last_reissued_at":"2026-07-02T01:17:41.180932Z","signature_status":"signed_v1","first_computed_at":"2026-07-02T01:17:41.180932Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2607.00362","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-02T01:17:41Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"SIOT9gV9E8qR64FkUdLOjrnd5Z6a+p7sGYq3/AgYa2HT6oyrWODzcsEyFm/Mf/TCjzflK85pfkg0sYoeaGpDDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-04T23:44:25.447124Z"},"content_sha256":"8098e03ea40193abbad2d7a6d31a630c3ddbfdf590cc0a67b55c513b9a03efd6","schema_version":"1.0","event_id":"sha256:8098e03ea40193abbad2d7a6d31a630c3ddbfdf590cc0a67b55c513b9a03efd6"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:Y5XGOJPOQRN3QZYS5G3HBB65RE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"SoK: Attack and Defense Landscape of Mobile On-device AI Systems","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.LG"],"primary_cat":"cs.CR","authors_text":"Kwok-Yan Lam, Xingliang Yuan, Xin Zheng, Yujin Huang","submitted_at":"2026-07-01T03:00:30Z","abstract_excerpt":"Mobile on-device AI (MoAI) systems that integrate locally deployed AI models with conventional mobile software components are emerging as a key paradigm for delivering intelligent functionality directly on end-user devices. By moving inference from remote cloud services to the local mobile environment, such systems enable privacy-preserving, low-latency, and offline-capable AI functionality, yet introduce new security risks arising from the local storage of AI models. This paper presents the first comprehensive systematization of knowledge on MoAI security, covering security pillars, attack la"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.00362","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2607.00362/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-02T01:17:41Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"4rxRVB3N93h2aku8TlCWOLnAgwCCp0Ow2c5LstJ6v6F+0MjXuw6prPtDHdzNPehikdFr/K3tvKjjSSSQePE4AQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-04T23:44:25.447518Z"},"content_sha256":"ddcf17918b631766e86700a3aa2b08b9bc8c8a9a8d652b5133fd3203ed286c5b","schema_version":"1.0","event_id":"sha256:ddcf17918b631766e86700a3aa2b08b9bc8c8a9a8d652b5133fd3203ed286c5b"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/Y5XGOJPOQRN3QZYS5G3HBB65RE/bundle.json","state_url":"https://pith.science/pith/Y5XGOJPOQRN3QZYS5G3HBB65RE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/Y5XGOJPOQRN3QZYS5G3HBB65RE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-04T23:44:25Z","links":{"resolver":"https://pith.science/pith/Y5XGOJPOQRN3QZYS5G3HBB65RE","bundle":"https://pith.science/pith/Y5XGOJPOQRN3QZYS5G3HBB65RE/bundle.json","state":"https://pith.science/pith/Y5XGOJPOQRN3QZYS5G3HBB65RE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/Y5XGOJPOQRN3QZYS5G3HBB65RE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:Y5XGOJPOQRN3QZYS5G3HBB65RE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e38dc8f2bc92cee781a03e57a9664be37a854b7e9e8f733bd69496b727ec4e52","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T03:00:30Z","title_canon_sha256":"dbfc160548c3ef547622c7f75be5a07f8912388213e1acc01905a3961392abe5"},"schema_version":"1.0","source":{"id":"2607.00362","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2607.00362","created_at":"2026-07-02T01:17:41Z"},{"alias_kind":"arxiv_version","alias_value":"2607.00362v1","created_at":"2026-07-02T01:17:41Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.00362","created_at":"2026-07-02T01:17:41Z"},{"alias_kind":"pith_short_12","alias_value":"Y5XGOJPOQRN3","created_at":"2026-07-02T01:17:41Z"},{"alias_kind":"pith_short_16","alias_value":"Y5XGOJPOQRN3QZYS","created_at":"2026-07-02T01:17:41Z"},{"alias_kind":"pith_short_8","alias_value":"Y5XGOJPO","created_at":"2026-07-02T01:17:41Z"}],"graph_snapshots":[{"event_id":"sha256:ddcf17918b631766e86700a3aa2b08b9bc8c8a9a8d652b5133fd3203ed286c5b","target":"graph","created_at":"2026-07-02T01:17:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2607.00362/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Mobile on-device AI (MoAI) systems that integrate locally deployed AI models with conventional mobile software components are emerging as a key paradigm for delivering intelligent functionality directly on end-user devices. By moving inference from remote cloud services to the local mobile environment, such systems enable privacy-preserving, low-latency, and offline-capable AI functionality, yet introduce new security risks arising from the local storage of AI models. This paper presents the first comprehensive systematization of knowledge on MoAI security, covering security pillars, attack la","authors_text":"Kwok-Yan Lam, Xingliang Yuan, Xin Zheng, Yujin Huang","cross_cats":["cs.AI","cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T03:00:30Z","title":"SoK: Attack and Defense Landscape of Mobile On-device AI Systems"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.00362","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8098e03ea40193abbad2d7a6d31a630c3ddbfdf590cc0a67b55c513b9a03efd6","target":"record","created_at":"2026-07-02T01:17:41Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e38dc8f2bc92cee781a03e57a9664be37a854b7e9e8f733bd69496b727ec4e52","cross_cats_sorted":["cs.AI","cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T03:00:30Z","title_canon_sha256":"dbfc160548c3ef547622c7f75be5a07f8912388213e1acc01905a3961392abe5"},"schema_version":"1.0","source":{"id":"2607.00362","kind":"arxiv","version":1}},"canonical_sha256":"c76e6725ee845bb86712e9b67087dd891f6b08be4d8eadfd0e9def59874c460e","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"c76e6725ee845bb86712e9b67087dd891f6b08be4d8eadfd0e9def59874c460e","first_computed_at":"2026-07-02T01:17:41.180932Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-02T01:17:41.180932Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"kYWDJO1tpbKiJKtEiTB1yTnQseojrP0B/rHDn8f0mPArzyrJwod5wHVOcOqahl2Jm4Oc0Mrv0s8fyFkvrN6cCw==","signature_status":"signed_v1","signed_at":"2026-07-02T01:17:41.181390Z","signed_message":"canonical_sha256_bytes"},"source_id":"2607.00362","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8098e03ea40193abbad2d7a6d31a630c3ddbfdf590cc0a67b55c513b9a03efd6","sha256:ddcf17918b631766e86700a3aa2b08b9bc8c8a9a8d652b5133fd3203ed286c5b"],"state_sha256":"d6e68e2d33f0ef35afc99019f7b62f6feae1bf993140e50b1f75efcab4fe3879"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"11SQAE6cFtp+V0CzCUSdjI7ubrE0KtzNWEZVM4DXErTS7TXgDDwBf0zvywp88t27p2qlpKxp5g8z8No3zcvABg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-04T23:44:25.450088Z","bundle_sha256":"db44861b05186951b1c826554b2f00537576973dabf6b7cec16cb69d6875a092"}}