{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2025:ZDN4ON3FCVBTK6ODRNVU7GAG74","short_pith_number":"pith:ZDN4ON3F","canonical_record":{"source":{"id":"2505.14289","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2025-05-20T12:41:05Z","cross_cats_sorted":[],"title_canon_sha256":"e626dcccf6e121f6bd2645c204b1d2cfdae2694c9ee47d8ff664a3fa76e8b342","abstract_canon_sha256":"9989d8ade7e1e8de3d0410c04a12a9089a271ec1046d7440d05b8c01aba83d2b"},"schema_version":"1.0"},"canonical_sha256":"c8dbc7376515433579c38b6b4f9806ff0dfbd89a8ad6e8bea33b1ddce8b7b2f0","source":{"kind":"arxiv","id":"2505.14289","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2505.14289","created_at":"2026-06-08T01:03:44Z"},{"alias_kind":"arxiv_version","alias_value":"2505.14289v2","created_at":"2026-06-08T01:03:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2505.14289","created_at":"2026-06-08T01:03:44Z"},{"alias_kind":"pith_short_12","alias_value":"ZDN4ON3FCVBT","created_at":"2026-06-08T01:03:44Z"},{"alias_kind":"pith_short_16","alias_value":"ZDN4ON3FCVBTK6OD","created_at":"2026-06-08T01:03:44Z"},{"alias_kind":"pith_short_8","alias_value":"ZDN4ON3F","created_at":"2026-06-08T01:03:44Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2025:ZDN4ON3FCVBTK6ODRNVU7GAG74","target":"record","payload":{"canonical_record":{"source":{"id":"2505.14289","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2025-05-20T12:41:05Z","cross_cats_sorted":[],"title_canon_sha256":"e626dcccf6e121f6bd2645c204b1d2cfdae2694c9ee47d8ff664a3fa76e8b342","abstract_canon_sha256":"9989d8ade7e1e8de3d0410c04a12a9089a271ec1046d7440d05b8c01aba83d2b"},"schema_version":"1.0"},"canonical_sha256":"c8dbc7376515433579c38b6b4f9806ff0dfbd89a8ad6e8bea33b1ddce8b7b2f0","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-08T01:03:44.969043Z","signature_b64":"EHWJ+9TmbYFitcApaGJJhlxt6lzGTOtnTY3Xkt5dVEhV5dhQILF9Y4dv+nq53NdNPb7L8reG6AuyKeLwMHgJAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c8dbc7376515433579c38b6b4f9806ff0dfbd89a8ad6e8bea33b1ddce8b7b2f0","last_reissued_at":"2026-06-08T01:03:44.968211Z","signature_status":"signed_v1","first_computed_at":"2026-06-08T01:03:44.968211Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2505.14289","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-08T01:03:44Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"kMOOYJTFmYfjybQBKi790QhnryT8VlBzYIOspyDY2SkLew+/sW6oPX2mBQd7Hm5iaMaGrw+fNa0pNm2KcWjqBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T10:35:18.217978Z"},"content_sha256":"8d71228910b34ceecc39146ac3e5dbb2b1c3d85c7a237601b063fb2a652e81b5","schema_version":"1.0","event_id":"sha256:8d71228910b34ceecc39146ac3e5dbb2b1c3d85c7a237601b063fb2a652e81b5"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2025:ZDN4ON3FCVBTK6ODRNVU7GAG74","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.AI","authors_text":"Daizong Ding, Gongshen Liu, Manman Zhao, Tianjie Ju, Xinbei Ma, Yijie Lu, Yuan Guo, Zhuosheng Zhang, Zihe Yan","submitted_at":"2025-05-20T12:41:05Z","abstract_excerpt":"Graphical User Interface (GUI) agents powered by Multimodal Large Language Models (MLLMs) are increasingly deployed yet vulnerable to Environmental Injection Attacks (EIAs).However, current red-teaming methods are hindered by prohibitive computational costs and limited adaptability. A fundamental question remains unaddressed: does the bottleneck of attack success lie in visual perception or semantic understanding? Through controlled experiments, we observe that semantic deception, rather than visual appearance, serves as the primary determinant of attack success. Based on this insight, we intr"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2505.14289","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2505.14289/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-08T01:03:44Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"WbBEAryQCFdFqPx5X70eF7lEp6ynJvWI7dKhz7E9PI5UvStmb0HT6cBxD9+dpoDNwMBkA2QOCG11h2TW4w62Ag==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-10T10:35:18.218800Z"},"content_sha256":"851e53d413c472321f2e8cf2983ca595de909d19290ea46230463a7f9d380bfe","schema_version":"1.0","event_id":"sha256:851e53d413c472321f2e8cf2983ca595de909d19290ea46230463a7f9d380bfe"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/ZDN4ON3FCVBTK6ODRNVU7GAG74/bundle.json","state_url":"https://pith.science/pith/ZDN4ON3FCVBTK6ODRNVU7GAG74/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/ZDN4ON3FCVBTK6ODRNVU7GAG74/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-10T10:35:18Z","links":{"resolver":"https://pith.science/pith/ZDN4ON3FCVBTK6ODRNVU7GAG74","bundle":"https://pith.science/pith/ZDN4ON3FCVBTK6ODRNVU7GAG74/bundle.json","state":"https://pith.science/pith/ZDN4ON3FCVBTK6ODRNVU7GAG74/state.json","well_known_bundle":"https://pith.science/.well-known/pith/ZDN4ON3FCVBTK6ODRNVU7GAG74/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2025:ZDN4ON3FCVBTK6ODRNVU7GAG74","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"9989d8ade7e1e8de3d0410c04a12a9089a271ec1046d7440d05b8c01aba83d2b","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2025-05-20T12:41:05Z","title_canon_sha256":"e626dcccf6e121f6bd2645c204b1d2cfdae2694c9ee47d8ff664a3fa76e8b342"},"schema_version":"1.0","source":{"id":"2505.14289","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2505.14289","created_at":"2026-06-08T01:03:44Z"},{"alias_kind":"arxiv_version","alias_value":"2505.14289v2","created_at":"2026-06-08T01:03:44Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2505.14289","created_at":"2026-06-08T01:03:44Z"},{"alias_kind":"pith_short_12","alias_value":"ZDN4ON3FCVBT","created_at":"2026-06-08T01:03:44Z"},{"alias_kind":"pith_short_16","alias_value":"ZDN4ON3FCVBTK6OD","created_at":"2026-06-08T01:03:44Z"},{"alias_kind":"pith_short_8","alias_value":"ZDN4ON3F","created_at":"2026-06-08T01:03:44Z"}],"graph_snapshots":[{"event_id":"sha256:851e53d413c472321f2e8cf2983ca595de909d19290ea46230463a7f9d380bfe","target":"graph","created_at":"2026-06-08T01:03:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2505.14289/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Graphical User Interface (GUI) agents powered by Multimodal Large Language Models (MLLMs) are increasingly deployed yet vulnerable to Environmental Injection Attacks (EIAs).However, current red-teaming methods are hindered by prohibitive computational costs and limited adaptability. A fundamental question remains unaddressed: does the bottleneck of attack success lie in visual perception or semantic understanding? Through controlled experiments, we observe that semantic deception, rather than visual appearance, serves as the primary determinant of attack success. Based on this insight, we intr","authors_text":"Daizong Ding, Gongshen Liu, Manman Zhao, Tianjie Ju, Xinbei Ma, Yijie Lu, Yuan Guo, Zhuosheng Zhang, Zihe Yan","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2025-05-20T12:41:05Z","title":"EVA: Evolving Semantic Adversaries for Red-Teaming GUI Agents Against Environmental Injection Attacks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2505.14289","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8d71228910b34ceecc39146ac3e5dbb2b1c3d85c7a237601b063fb2a652e81b5","target":"record","created_at":"2026-06-08T01:03:44Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"9989d8ade7e1e8de3d0410c04a12a9089a271ec1046d7440d05b8c01aba83d2b","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2025-05-20T12:41:05Z","title_canon_sha256":"e626dcccf6e121f6bd2645c204b1d2cfdae2694c9ee47d8ff664a3fa76e8b342"},"schema_version":"1.0","source":{"id":"2505.14289","kind":"arxiv","version":2}},"canonical_sha256":"c8dbc7376515433579c38b6b4f9806ff0dfbd89a8ad6e8bea33b1ddce8b7b2f0","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"c8dbc7376515433579c38b6b4f9806ff0dfbd89a8ad6e8bea33b1ddce8b7b2f0","first_computed_at":"2026-06-08T01:03:44.968211Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-08T01:03:44.968211Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"EHWJ+9TmbYFitcApaGJJhlxt6lzGTOtnTY3Xkt5dVEhV5dhQILF9Y4dv+nq53NdNPb7L8reG6AuyKeLwMHgJAg==","signature_status":"signed_v1","signed_at":"2026-06-08T01:03:44.969043Z","signed_message":"canonical_sha256_bytes"},"source_id":"2505.14289","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8d71228910b34ceecc39146ac3e5dbb2b1c3d85c7a237601b063fb2a652e81b5","sha256:851e53d413c472321f2e8cf2983ca595de909d19290ea46230463a7f9d380bfe"],"state_sha256":"d34031cb5ed5f680c722407c8ffe2bf1ed97af5c4d4313c62b0b2614a82833ee"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"RJNwShEoNfC3AG7ECzSd1kWhUji+GyAKVi5jk2Hx4o67V7G35mkywQbTeHpfeKhvqgLdcrSr9T35RQhq/efQDA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-10T10:35:18.222979Z","bundle_sha256":"a4a6df90a4d6ea3449cc0e1c22203c8b62c0950610b9c5ff0cea6529ad2a809f"}}