{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:YY4C7Y5ERMMWUJZERVBQVU6AYZ","short_pith_number":"pith:YY4C7Y5E","schema_version":"1.0","canonical_sha256":"c6382fe3a48b196a27248d430ad3c0c65c3fec0a1af7fcd5973bfa67136518b7","source":{"kind":"arxiv","id":"2606.07968","version":1},"attestation_state":"computed","paper":{"title":"RecurGuard: Runtime Monitoring for Reasoning-Token Consumption Attacks","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Abid Aziz, Hafsa Binte Kibria","submitted_at":"2026-06-06T03:52:27Z","abstract_excerpt":"Reasoning-capable large language models can be induced to spend their generation budget on injected decoy tasks rather than answering the user's question, causing denial of service when no final answer is produced and denial of wallet when excess output tokens are billed. Input-side safety classifiers often miss these attacks because the injected prompts can appear syntactically benign. We build RecurGuard, a runtime monitor for detecting reasoning-chain consumption attacks when reasoning traces are exposed by the model. RecurGuard analyzes reasoning traces as they are generated and tracks thr"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2606.07968","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-06T03:52:27Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"b9354d5fc514dd6137e5744f453f6e623cc3a76364535f9e68970caa7da09739","abstract_canon_sha256":"a28aa4d610456b373546b263cc7053d77e4eb64b221d3e72ba2e4b7b1da14fa1"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-09T01:04:56.741494Z","signature_b64":"hCHAYIGhDi6GsFUDicH05bOIf8pQnQvtJ5lYPcsoW0ntK/zo1rajlf7Nffr01lkb7Ci0IIZEeLm/lZ8txavyDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c6382fe3a48b196a27248d430ad3c0c65c3fec0a1af7fcd5973bfa67136518b7","last_reissued_at":"2026-06-09T01:04:56.741051Z","signature_status":"signed_v1","first_computed_at":"2026-06-09T01:04:56.741051Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"RecurGuard: Runtime Monitoring for Reasoning-Token Consumption Attacks","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Abid Aziz, Hafsa Binte Kibria","submitted_at":"2026-06-06T03:52:27Z","abstract_excerpt":"Reasoning-capable large language models can be induced to spend their generation budget on injected decoy tasks rather than answering the user's question, causing denial of service when no final answer is produced and denial of wallet when excess output tokens are billed. Input-side safety classifiers often miss these attacks because the injected prompts can appear syntactically benign. We build RecurGuard, a runtime monitor for detecting reasoning-chain consumption attacks when reasoning traces are exposed by the model. RecurGuard analyzes reasoning traces as they are generated and tracks thr"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.07968","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.07968/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2606.07968","created_at":"2026-06-09T01:04:56.741115+00:00"},{"alias_kind":"arxiv_version","alias_value":"2606.07968v1","created_at":"2026-06-09T01:04:56.741115+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.07968","created_at":"2026-06-09T01:04:56.741115+00:00"},{"alias_kind":"pith_short_12","alias_value":"YY4C7Y5ERMMW","created_at":"2026-06-09T01:04:56.741115+00:00"},{"alias_kind":"pith_short_16","alias_value":"YY4C7Y5ERMMWUJZE","created_at":"2026-06-09T01:04:56.741115+00:00"},{"alias_kind":"pith_short_8","alias_value":"YY4C7Y5E","created_at":"2026-06-09T01:04:56.741115+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/YY4C7Y5ERMMWUJZERVBQVU6AYZ","json":"https://pith.science/pith/YY4C7Y5ERMMWUJZERVBQVU6AYZ.json","graph_json":"https://pith.science/api/pith-number/YY4C7Y5ERMMWUJZERVBQVU6AYZ/graph.json","events_json":"https://pith.science/api/pith-number/YY4C7Y5ERMMWUJZERVBQVU6AYZ/events.json","paper":"https://pith.science/paper/YY4C7Y5E"},"agent_actions":{"view_html":"https://pith.science/pith/YY4C7Y5ERMMWUJZERVBQVU6AYZ","download_json":"https://pith.science/pith/YY4C7Y5ERMMWUJZERVBQVU6AYZ.json","view_paper":"https://pith.science/paper/YY4C7Y5E","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2606.07968&json=true","fetch_graph":"https://pith.science/api/pith-number/YY4C7Y5ERMMWUJZERVBQVU6AYZ/graph.json","fetch_events":"https://pith.science/api/pith-number/YY4C7Y5ERMMWUJZERVBQVU6AYZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/YY4C7Y5ERMMWUJZERVBQVU6AYZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/YY4C7Y5ERMMWUJZERVBQVU6AYZ/action/storage_attestation","attest_author":"https://pith.science/pith/YY4C7Y5ERMMWUJZERVBQVU6AYZ/action/author_attestation","sign_citation":"https://pith.science/pith/YY4C7Y5ERMMWUJZERVBQVU6AYZ/action/citation_signature","submit_replication":"https://pith.science/pith/YY4C7Y5ERMMWUJZERVBQVU6AYZ/action/replication_record"}},"created_at":"2026-06-09T01:04:56.741115+00:00","updated_at":"2026-06-09T01:04:56.741115+00:00"}