{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:3TDZOES26W2NUASFGEU323UARE","short_pith_number":"pith:3TDZOES2","schema_version":"1.0","canonical_sha256":"dcc797125af5b4da02453129bd6e80891d7b90d1d2a3d80fe859eaad4f857d9a","source":{"kind":"arxiv","id":"2509.06338","version":1},"attestation_state":"computed","paper":{"title":"Embedding Poisoning: Bypassing Safety Alignment via Embedding Semantic Shift","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Guangdong Bai, Shuai Yuan, Wang Kailong, Yuxi Li, Zhibo Zhang","submitted_at":"2025-09-08T05:00:58Z","abstract_excerpt":"The widespread distribution of Large Language Models (LLMs) through public platforms like Hugging Face introduces significant security challenges. While these platforms perform basic security scans, they often fail to detect subtle manipulations within the embedding layer. This work identifies a novel class of deployment phase attacks that exploit this vulnerability by injecting imperceptible perturbations directly into the embedding layer outputs without modifying model weights or input text. These perturbations, though statistically benign, systematically bypass safety alignment mechanisms a"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2509.06338","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-09-08T05:00:58Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"2804e5f36d00d03d52fbf132a6c92f110579e82de356d2c53534ab04f3dcdabe","abstract_canon_sha256":"b2d06aa265d57f39dd988b694f45f69f585a24df79fecea80d0a592574ec7909"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T12:06:33.980517Z","signature_b64":"SORLq32wzkXsVUJWxcIXyid3rQcQDTXPwdkBQ4ybhq2QOz2wWabKtfvs6miyaTg7OQsuNtqpjJETh5tqSTHtCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"dcc797125af5b4da02453129bd6e80891d7b90d1d2a3d80fe859eaad4f857d9a","last_reissued_at":"2026-07-05T12:06:33.980069Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T12:06:33.980069Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Embedding Poisoning: Bypassing Safety Alignment via Embedding Semantic Shift","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Guangdong Bai, Shuai Yuan, Wang Kailong, Yuxi Li, Zhibo Zhang","submitted_at":"2025-09-08T05:00:58Z","abstract_excerpt":"The widespread distribution of Large Language Models (LLMs) through public platforms like Hugging Face introduces significant security challenges. While these platforms perform basic security scans, they often fail to detect subtle manipulations within the embedding layer. This work identifies a novel class of deployment phase attacks that exploit this vulnerability by injecting imperceptible perturbations directly into the embedding layer outputs without modifying model weights or input text. These perturbations, though statistically benign, systematically bypass safety alignment mechanisms a"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2509.06338","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2509.06338/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2509.06338","created_at":"2026-07-05T12:06:33.980120+00:00"},{"alias_kind":"arxiv_version","alias_value":"2509.06338v1","created_at":"2026-07-05T12:06:33.980120+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2509.06338","created_at":"2026-07-05T12:06:33.980120+00:00"},{"alias_kind":"pith_short_12","alias_value":"3TDZOES26W2N","created_at":"2026-07-05T12:06:33.980120+00:00"},{"alias_kind":"pith_short_16","alias_value":"3TDZOES26W2NUASF","created_at":"2026-07-05T12:06:33.980120+00:00"},{"alias_kind":"pith_short_8","alias_value":"3TDZOES2","created_at":"2026-07-05T12:06:33.980120+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/3TDZOES26W2NUASFGEU323UARE","json":"https://pith.science/pith/3TDZOES26W2NUASFGEU323UARE.json","graph_json":"https://pith.science/api/pith-number/3TDZOES26W2NUASFGEU323UARE/graph.json","events_json":"https://pith.science/api/pith-number/3TDZOES26W2NUASFGEU323UARE/events.json","paper":"https://pith.science/paper/3TDZOES2"},"agent_actions":{"view_html":"https://pith.science/pith/3TDZOES26W2NUASFGEU323UARE","download_json":"https://pith.science/pith/3TDZOES26W2NUASFGEU323UARE.json","view_paper":"https://pith.science/paper/3TDZOES2","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2509.06338&json=true","fetch_graph":"https://pith.science/api/pith-number/3TDZOES26W2NUASFGEU323UARE/graph.json","fetch_events":"https://pith.science/api/pith-number/3TDZOES26W2NUASFGEU323UARE/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/3TDZOES26W2NUASFGEU323UARE/action/timestamp_anchor","attest_storage":"https://pith.science/pith/3TDZOES26W2NUASFGEU323UARE/action/storage_attestation","attest_author":"https://pith.science/pith/3TDZOES26W2NUASFGEU323UARE/action/author_attestation","sign_citation":"https://pith.science/pith/3TDZOES26W2NUASFGEU323UARE/action/citation_signature","submit_replication":"https://pith.science/pith/3TDZOES26W2NUASFGEU323UARE/action/replication_record"}},"created_at":"2026-07-05T12:06:33.980120+00:00","updated_at":"2026-07-05T12:06:33.980120+00:00"}