{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:ZGDPW4V4HMKIB6HLVWTBELBKTA","short_pith_number":"pith:ZGDPW4V4","canonical_record":{"source":{"id":"2605.28893","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2026-05-27T08:11:37Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"a459e4122b533595ee6e93f5f681c5360df54892bba620c42c6a41e3a45eff96","abstract_canon_sha256":"ba3dae928ad6d59e0223be1775e32b61eae833c8b59979c896e938e188b8027f"},"schema_version":"1.0"},"canonical_sha256":"c986fb72bc3b1480f8ebada6122c2a982583cec6d533622fa1422e58d45fc31d","source":{"kind":"arxiv","id":"2605.28893","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.28893","created_at":"2026-05-29T00:04:15Z"},{"alias_kind":"arxiv_version","alias_value":"2605.28893v1","created_at":"2026-05-29T00:04:15Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.28893","created_at":"2026-05-29T00:04:15Z"},{"alias_kind":"pith_short_12","alias_value":"ZGDPW4V4HMKI","created_at":"2026-05-29T00:04:15Z"},{"alias_kind":"pith_short_16","alias_value":"ZGDPW4V4HMKIB6HL","created_at":"2026-05-29T00:04:15Z"},{"alias_kind":"pith_short_8","alias_value":"ZGDPW4V4","created_at":"2026-05-29T00:04:15Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:ZGDPW4V4HMKIB6HLVWTBELBKTA","target":"record","payload":{"canonical_record":{"source":{"id":"2605.28893","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2026-05-27T08:11:37Z","cross_cats_sorted":["cs.CR"],"title_canon_sha256":"a459e4122b533595ee6e93f5f681c5360df54892bba620c42c6a41e3a45eff96","abstract_canon_sha256":"ba3dae928ad6d59e0223be1775e32b61eae833c8b59979c896e938e188b8027f"},"schema_version":"1.0"},"canonical_sha256":"c986fb72bc3b1480f8ebada6122c2a982583cec6d533622fa1422e58d45fc31d","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-29T00:04:15.660018Z","signature_b64":"oSpqFzAinovxfFSznKZqb1grrh6G1/jGwBcxrsh0iZuik+Sk0fpSLxbHwqK7qtqBwJrxNmVr5s2a9xhfkwv3BA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"c986fb72bc3b1480f8ebada6122c2a982583cec6d533622fa1422e58d45fc31d","last_reissued_at":"2026-05-29T00:04:15.659563Z","signature_status":"signed_v1","first_computed_at":"2026-05-29T00:04:15.659563Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.28893","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T00:04:15Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"XMPi6qcM6M2Dz3Chnbx2YQdh/OOWJEwAiJbzXt//vpftJMjjeFJ43YLfgP76WY0NkQl0M4rsutg010HdL6xZDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T08:07:51.869560Z"},"content_sha256":"8f01c7306d706d70ef649655ec916dce01ca5b66002aefe6117601aaa6203a41","schema_version":"1.0","event_id":"sha256:8f01c7306d706d70ef649655ec916dce01ca5b66002aefe6117601aaa6203a41"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:ZGDPW4V4HMKIB6HLVWTBELBKTA","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Towards Demystifying and Repairing LLM-in-the-Loop Vulnerabilities","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CR"],"primary_cat":"cs.SE","authors_text":"Chenxi Yang, Jialin Rong, Lili Quan, Qiang Hu, Xiaofei Xie, Yongqiang Lyu, Yujie Ma","submitted_at":"2026-05-27T08:11:37Z","abstract_excerpt":"Large Language Models(LLMs) have been actively integrated into modern software systems as critical components. LLM-in-the-loop vulnerabilities, where vulnerabilities are introduced by LLMs and their dependent downstream components, such as frameworks, introduce new risks. Although some benchmark datasets have been constructed to study the impact of such vulnerabilities, most works still remain at the analysis from the conventional software level, ignoring the harm actually caused by LLMs. Understanding real-world LLM-in-the-loop vulnerabilities is still an open problem. To address this gap, we"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.28893","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.28893/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T00:04:15Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"sqrCgIcFvU/LgCHwyvQuJ/vN9gZ/w6oyvU33bdHTKmcGkdvG8Eotu0/1wpOBSb8La9BpzdMD+vXrhLqjkYxRAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-02T08:07:51.869926Z"},"content_sha256":"24071acf65ae2201eb03f9bedbab743234eaecb7cb6e6d546c7381ca8c3ddd76","schema_version":"1.0","event_id":"sha256:24071acf65ae2201eb03f9bedbab743234eaecb7cb6e6d546c7381ca8c3ddd76"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/ZGDPW4V4HMKIB6HLVWTBELBKTA/bundle.json","state_url":"https://pith.science/pith/ZGDPW4V4HMKIB6HLVWTBELBKTA/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/ZGDPW4V4HMKIB6HLVWTBELBKTA/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-02T08:07:51Z","links":{"resolver":"https://pith.science/pith/ZGDPW4V4HMKIB6HLVWTBELBKTA","bundle":"https://pith.science/pith/ZGDPW4V4HMKIB6HLVWTBELBKTA/bundle.json","state":"https://pith.science/pith/ZGDPW4V4HMKIB6HLVWTBELBKTA/state.json","well_known_bundle":"https://pith.science/.well-known/pith/ZGDPW4V4HMKIB6HLVWTBELBKTA/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:ZGDPW4V4HMKIB6HLVWTBELBKTA","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"ba3dae928ad6d59e0223be1775e32b61eae833c8b59979c896e938e188b8027f","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2026-05-27T08:11:37Z","title_canon_sha256":"a459e4122b533595ee6e93f5f681c5360df54892bba620c42c6a41e3a45eff96"},"schema_version":"1.0","source":{"id":"2605.28893","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.28893","created_at":"2026-05-29T00:04:15Z"},{"alias_kind":"arxiv_version","alias_value":"2605.28893v1","created_at":"2026-05-29T00:04:15Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.28893","created_at":"2026-05-29T00:04:15Z"},{"alias_kind":"pith_short_12","alias_value":"ZGDPW4V4HMKI","created_at":"2026-05-29T00:04:15Z"},{"alias_kind":"pith_short_16","alias_value":"ZGDPW4V4HMKIB6HL","created_at":"2026-05-29T00:04:15Z"},{"alias_kind":"pith_short_8","alias_value":"ZGDPW4V4","created_at":"2026-05-29T00:04:15Z"}],"graph_snapshots":[{"event_id":"sha256:24071acf65ae2201eb03f9bedbab743234eaecb7cb6e6d546c7381ca8c3ddd76","target":"graph","created_at":"2026-05-29T00:04:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.28893/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large Language Models(LLMs) have been actively integrated into modern software systems as critical components. LLM-in-the-loop vulnerabilities, where vulnerabilities are introduced by LLMs and their dependent downstream components, such as frameworks, introduce new risks. Although some benchmark datasets have been constructed to study the impact of such vulnerabilities, most works still remain at the analysis from the conventional software level, ignoring the harm actually caused by LLMs. Understanding real-world LLM-in-the-loop vulnerabilities is still an open problem. To address this gap, we","authors_text":"Chenxi Yang, Jialin Rong, Lili Quan, Qiang Hu, Xiaofei Xie, Yongqiang Lyu, Yujie Ma","cross_cats":["cs.CR"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2026-05-27T08:11:37Z","title":"Towards Demystifying and Repairing LLM-in-the-Loop Vulnerabilities"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.28893","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:8f01c7306d706d70ef649655ec916dce01ca5b66002aefe6117601aaa6203a41","target":"record","created_at":"2026-05-29T00:04:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"ba3dae928ad6d59e0223be1775e32b61eae833c8b59979c896e938e188b8027f","cross_cats_sorted":["cs.CR"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.SE","submitted_at":"2026-05-27T08:11:37Z","title_canon_sha256":"a459e4122b533595ee6e93f5f681c5360df54892bba620c42c6a41e3a45eff96"},"schema_version":"1.0","source":{"id":"2605.28893","kind":"arxiv","version":1}},"canonical_sha256":"c986fb72bc3b1480f8ebada6122c2a982583cec6d533622fa1422e58d45fc31d","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"c986fb72bc3b1480f8ebada6122c2a982583cec6d533622fa1422e58d45fc31d","first_computed_at":"2026-05-29T00:04:15.659563Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-29T00:04:15.659563Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"oSpqFzAinovxfFSznKZqb1grrh6G1/jGwBcxrsh0iZuik+Sk0fpSLxbHwqK7qtqBwJrxNmVr5s2a9xhfkwv3BA==","signature_status":"signed_v1","signed_at":"2026-05-29T00:04:15.660018Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.28893","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:8f01c7306d706d70ef649655ec916dce01ca5b66002aefe6117601aaa6203a41","sha256:24071acf65ae2201eb03f9bedbab743234eaecb7cb6e6d546c7381ca8c3ddd76"],"state_sha256":"ffb6309209877403930451df7ef707b91344f69c406e37d9b3e1126514d5501f"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"cB+X88kbCBBow6AzQ7ErNDsQQsw5N4N2ZJHJ1xrBOEM6ouJoaAD2qacLr+jG1Neke/b/IcbXR/K7OtNalKBPAg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-02T08:07:51.871793Z","bundle_sha256":"025b8eb99274c5a09cd8192b954ca9e06a07a063b6c70186797a92e12f0e98d4"}}