{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:ZQ7EFNMPREAFLFF76DCA7SHH2I","short_pith_number":"pith:ZQ7EFNMP","schema_version":"1.0","canonical_sha256":"cc3e42b58f89005594bff0c40fc8e7d202766fa8c57cd4613c14378254537448","source":{"kind":"arxiv","id":"2509.03117","version":3},"attestation_state":"computed","paper":{"title":"PromptCOS: Towards Content-only System Prompt Copyright Auditing for LLMs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Dacheng Tao, Enhao Huang, Hongwei Yao, Shuo Shao, Yiming Li, Yuchen Yang, Yuyi Wang, Zhan Qin, Zhibo Wang","submitted_at":"2025-09-03T08:19:40Z","abstract_excerpt":"System prompts are critical for shaping the behavior and output quality of large language model (LLM)-based applications, driving substantial investment in optimizing high-quality prompts beyond traditional handcrafted designs. However, as system prompts become valuable intellectual property, they are increasingly vulnerable to prompt theft and unauthorized use, highlighting the urgent need for effective copyright auditing, especially watermarking. Existing methods rely on verifying subtle logit distribution shifts triggered by a query. We observe that this logit-dependent verification framewo"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2509.03117","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-09-03T08:19:40Z","cross_cats_sorted":[],"title_canon_sha256":"caaea8ace01c0b9cd49b0266bd9d7366b83e7ee5e0286982e609c3b77f1d00a7","abstract_canon_sha256":"f66b93ec57b51943834480b3dbad32302f6548ba6d18ef0bc559158ce12990e1"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-25T02:02:08.736836Z","signature_b64":"7+IwmjRCYbOBgN/IjQJkZmk+wkAzctCl6u3CyGteQfX1ON12TXToGYlcQN8V6UFNvMZenl/bhecKEBp4objZDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"cc3e42b58f89005594bff0c40fc8e7d202766fa8c57cd4613c14378254537448","last_reissued_at":"2026-05-25T02:02:08.735850Z","signature_status":"signed_v1","first_computed_at":"2026-05-25T02:02:08.735850Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"PromptCOS: Towards Content-only System Prompt Copyright Auditing for LLMs","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Dacheng Tao, Enhao Huang, Hongwei Yao, Shuo Shao, Yiming Li, Yuchen Yang, Yuyi Wang, Zhan Qin, Zhibo Wang","submitted_at":"2025-09-03T08:19:40Z","abstract_excerpt":"System prompts are critical for shaping the behavior and output quality of large language model (LLM)-based applications, driving substantial investment in optimizing high-quality prompts beyond traditional handcrafted designs. However, as system prompts become valuable intellectual property, they are increasingly vulnerable to prompt theft and unauthorized use, highlighting the urgent need for effective copyright auditing, especially watermarking. Existing methods rely on verifying subtle logit distribution shifts triggered by a query. We observe that this logit-dependent verification framewo"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2509.03117","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2509.03117/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2509.03117","created_at":"2026-05-25T02:02:08.735983+00:00"},{"alias_kind":"arxiv_version","alias_value":"2509.03117v3","created_at":"2026-05-25T02:02:08.735983+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2509.03117","created_at":"2026-05-25T02:02:08.735983+00:00"},{"alias_kind":"pith_short_12","alias_value":"ZQ7EFNMPREAF","created_at":"2026-05-25T02:02:08.735983+00:00"},{"alias_kind":"pith_short_16","alias_value":"ZQ7EFNMPREAFLFF7","created_at":"2026-05-25T02:02:08.735983+00:00"},{"alias_kind":"pith_short_8","alias_value":"ZQ7EFNMP","created_at":"2026-05-25T02:02:08.735983+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":2,"sample":[{"citing_arxiv_id":"2605.05974","citing_title":"PragLocker: Protecting Agent Intellectual Property in Untrusted Deployments via Non-Portable Prompts","ref_index":76,"is_internal_anchor":true},{"citing_arxiv_id":"2605.05974","citing_title":"PragLocker: Protecting Agent Intellectual Property in Untrusted Deployments via Non-Portable Prompts","ref_index":76,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/ZQ7EFNMPREAFLFF76DCA7SHH2I","json":"https://pith.science/pith/ZQ7EFNMPREAFLFF76DCA7SHH2I.json","graph_json":"https://pith.science/api/pith-number/ZQ7EFNMPREAFLFF76DCA7SHH2I/graph.json","events_json":"https://pith.science/api/pith-number/ZQ7EFNMPREAFLFF76DCA7SHH2I/events.json","paper":"https://pith.science/paper/ZQ7EFNMP"},"agent_actions":{"view_html":"https://pith.science/pith/ZQ7EFNMPREAFLFF76DCA7SHH2I","download_json":"https://pith.science/pith/ZQ7EFNMPREAFLFF76DCA7SHH2I.json","view_paper":"https://pith.science/paper/ZQ7EFNMP","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2509.03117&json=true","fetch_graph":"https://pith.science/api/pith-number/ZQ7EFNMPREAFLFF76DCA7SHH2I/graph.json","fetch_events":"https://pith.science/api/pith-number/ZQ7EFNMPREAFLFF76DCA7SHH2I/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/ZQ7EFNMPREAFLFF76DCA7SHH2I/action/timestamp_anchor","attest_storage":"https://pith.science/pith/ZQ7EFNMPREAFLFF76DCA7SHH2I/action/storage_attestation","attest_author":"https://pith.science/pith/ZQ7EFNMPREAFLFF76DCA7SHH2I/action/author_attestation","sign_citation":"https://pith.science/pith/ZQ7EFNMPREAFLFF76DCA7SHH2I/action/citation_signature","submit_replication":"https://pith.science/pith/ZQ7EFNMPREAFLFF76DCA7SHH2I/action/replication_record"}},"created_at":"2026-05-25T02:02:08.735983+00:00","updated_at":"2026-05-25T02:02:08.735983+00:00"}