{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2024:2NSWDSLFH74AEXZXF6QOU7V44X","short_pith_number":"pith:2NSWDSLF","canonical_record":{"source":{"id":"2412.08108","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2024-12-11T05:23:34Z","cross_cats_sorted":["cs.CL","cs.CR"],"title_canon_sha256":"a5f3dae41e0796a38eb29cddf1d152d653db617109592358f3c485f598344d33","abstract_canon_sha256":"e93b7495d380ea445043254844f79a5a462d020ae5b1e12f82089e555f4091d1"},"schema_version":"1.0"},"canonical_sha256":"d36561c9653ff8025f372fa0ea7ebce5ff20ee1b41a3eb5abc6585d174240fd9","source":{"kind":"arxiv","id":"2412.08108","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2412.08108","created_at":"2026-06-30T02:16:49Z"},{"alias_kind":"arxiv_version","alias_value":"2412.08108v3","created_at":"2026-06-30T02:16:49Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2412.08108","created_at":"2026-06-30T02:16:49Z"},{"alias_kind":"pith_short_12","alias_value":"2NSWDSLFH74A","created_at":"2026-06-30T02:16:49Z"},{"alias_kind":"pith_short_16","alias_value":"2NSWDSLFH74AEXZX","created_at":"2026-06-30T02:16:49Z"},{"alias_kind":"pith_short_8","alias_value":"2NSWDSLF","created_at":"2026-06-30T02:16:49Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2024:2NSWDSLFH74AEXZXF6QOU7V44X","target":"record","payload":{"canonical_record":{"source":{"id":"2412.08108","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2024-12-11T05:23:34Z","cross_cats_sorted":["cs.CL","cs.CR"],"title_canon_sha256":"a5f3dae41e0796a38eb29cddf1d152d653db617109592358f3c485f598344d33","abstract_canon_sha256":"e93b7495d380ea445043254844f79a5a462d020ae5b1e12f82089e555f4091d1"},"schema_version":"1.0"},"canonical_sha256":"d36561c9653ff8025f372fa0ea7ebce5ff20ee1b41a3eb5abc6585d174240fd9","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-30T02:16:49.340554Z","signature_b64":"DqGwFI2w5UrQ+fjnt1ZqNrgdl+yQJskyRVN7SaBblJYlVYIBt8FDSRO5teskQOzIojQ4kGQ7PrCJr/VxgmuoDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d36561c9653ff8025f372fa0ea7ebce5ff20ee1b41a3eb5abc6585d174240fd9","last_reissued_at":"2026-06-30T02:16:49.339750Z","signature_status":"signed_v1","first_computed_at":"2026-06-30T02:16:49.339750Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2412.08108","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-30T02:16:49Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"TElwp9doEphL5WyLOm6ZvZs+etZNU1jCYOURxDPIsSeCWQs49X22sfpnHS2ABh+kZNReUwWDR8l6RnDkyhztBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T13:23:41.911404Z"},"content_sha256":"52812e8fbc1445266fb2ad17b75a27d1ec919a6dcb92a0bc79e49a5854e82217","schema_version":"1.0","event_id":"sha256:52812e8fbc1445266fb2ad17b75a27d1ec919a6dcb92a0bc79e49a5854e82217"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2024:2NSWDSLFH74AEXZXF6QOU7V44X","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Exploiting Vision Encoder Vulnerabilities for Universal Adversarial Perturbations on Large Vision-Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL","cs.CR"],"primary_cat":"cs.CV","authors_text":"Changick Kim, Hee-Seon Kim, Minbeom Kim, Seokil Ham","submitted_at":"2024-12-11T05:23:34Z","abstract_excerpt":"Large Vision-Language Models (LVLMs) have achieved remarkable performance on multimodal tasks but remain highly vulnerable to small adversarial perturbations in input images. Existing attacks typically target the vision encoder's final output embeddings, implicitly treating the encoder as a uniform attack surface, while a systematic analysis of which internal components are most vulnerable has remained largely unexplored. We show such analysis is essential, as adversarial vulnerability in LVLM vision encoders is structurally concentrated rather than uniformly distributed. Building on this, we "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2412.08108","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2412.08108/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-30T02:16:49Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yEgQE8gqA52m2UlViWcHWO7+Xg9my4miUsTAaFpvYkOGIPzM7EQE3KBJyz9+3n4fbC4W4z8ewfAyeO0nEhHlDw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T13:23:41.911794Z"},"content_sha256":"0e1af9b452b2551a08fe139c95a2e0a5a9ed703921c3c4537d333efa78f7ecd6","schema_version":"1.0","event_id":"sha256:0e1af9b452b2551a08fe139c95a2e0a5a9ed703921c3c4537d333efa78f7ecd6"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/2NSWDSLFH74AEXZXF6QOU7V44X/bundle.json","state_url":"https://pith.science/pith/2NSWDSLFH74AEXZXF6QOU7V44X/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/2NSWDSLFH74AEXZXF6QOU7V44X/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-02T13:23:41Z","links":{"resolver":"https://pith.science/pith/2NSWDSLFH74AEXZXF6QOU7V44X","bundle":"https://pith.science/pith/2NSWDSLFH74AEXZXF6QOU7V44X/bundle.json","state":"https://pith.science/pith/2NSWDSLFH74AEXZXF6QOU7V44X/state.json","well_known_bundle":"https://pith.science/.well-known/pith/2NSWDSLFH74AEXZXF6QOU7V44X/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2024:2NSWDSLFH74AEXZXF6QOU7V44X","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"e93b7495d380ea445043254844f79a5a462d020ae5b1e12f82089e555f4091d1","cross_cats_sorted":["cs.CL","cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2024-12-11T05:23:34Z","title_canon_sha256":"a5f3dae41e0796a38eb29cddf1d152d653db617109592358f3c485f598344d33"},"schema_version":"1.0","source":{"id":"2412.08108","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2412.08108","created_at":"2026-06-30T02:16:49Z"},{"alias_kind":"arxiv_version","alias_value":"2412.08108v3","created_at":"2026-06-30T02:16:49Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2412.08108","created_at":"2026-06-30T02:16:49Z"},{"alias_kind":"pith_short_12","alias_value":"2NSWDSLFH74A","created_at":"2026-06-30T02:16:49Z"},{"alias_kind":"pith_short_16","alias_value":"2NSWDSLFH74AEXZX","created_at":"2026-06-30T02:16:49Z"},{"alias_kind":"pith_short_8","alias_value":"2NSWDSLF","created_at":"2026-06-30T02:16:49Z"}],"graph_snapshots":[{"event_id":"sha256:0e1af9b452b2551a08fe139c95a2e0a5a9ed703921c3c4537d333efa78f7ecd6","target":"graph","created_at":"2026-06-30T02:16:49Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2412.08108/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large Vision-Language Models (LVLMs) have achieved remarkable performance on multimodal tasks but remain highly vulnerable to small adversarial perturbations in input images. Existing attacks typically target the vision encoder's final output embeddings, implicitly treating the encoder as a uniform attack surface, while a systematic analysis of which internal components are most vulnerable has remained largely unexplored. We show such analysis is essential, as adversarial vulnerability in LVLM vision encoders is structurally concentrated rather than uniformly distributed. Building on this, we ","authors_text":"Changick Kim, Hee-Seon Kim, Minbeom Kim, Seokil Ham","cross_cats":["cs.CL","cs.CR"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2024-12-11T05:23:34Z","title":"Exploiting Vision Encoder Vulnerabilities for Universal Adversarial Perturbations on Large Vision-Language Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2412.08108","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:52812e8fbc1445266fb2ad17b75a27d1ec919a6dcb92a0bc79e49a5854e82217","target":"record","created_at":"2026-06-30T02:16:49Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"e93b7495d380ea445043254844f79a5a462d020ae5b1e12f82089e555f4091d1","cross_cats_sorted":["cs.CL","cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CV","submitted_at":"2024-12-11T05:23:34Z","title_canon_sha256":"a5f3dae41e0796a38eb29cddf1d152d653db617109592358f3c485f598344d33"},"schema_version":"1.0","source":{"id":"2412.08108","kind":"arxiv","version":3}},"canonical_sha256":"d36561c9653ff8025f372fa0ea7ebce5ff20ee1b41a3eb5abc6585d174240fd9","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d36561c9653ff8025f372fa0ea7ebce5ff20ee1b41a3eb5abc6585d174240fd9","first_computed_at":"2026-06-30T02:16:49.339750Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-30T02:16:49.339750Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"DqGwFI2w5UrQ+fjnt1ZqNrgdl+yQJskyRVN7SaBblJYlVYIBt8FDSRO5teskQOzIojQ4kGQ7PrCJr/VxgmuoDg==","signature_status":"signed_v1","signed_at":"2026-06-30T02:16:49.340554Z","signed_message":"canonical_sha256_bytes"},"source_id":"2412.08108","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:52812e8fbc1445266fb2ad17b75a27d1ec919a6dcb92a0bc79e49a5854e82217","sha256:0e1af9b452b2551a08fe139c95a2e0a5a9ed703921c3c4537d333efa78f7ecd6"],"state_sha256":"65588f6a06b0395ead5939677b1bc2be8cb0805d58866d33ba1e1ee295468ff9"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"dZhnS8UVRCIwizsGR6kV5lhLPzl70utx6PUm8Xco64EW5bj1d7Dpirc2gdzl0Qf3+51WoszBU0OrdwhTJx4JCw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-02T13:23:41.913833Z","bundle_sha256":"b31adf120dd91ce3fd223f1b8f235860f87a58f98d4f38899e4ea7464d860e33"}}