{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:7H4AGXZ32B7ZZ2RFTUDOWYC3SU","short_pith_number":"pith:7H4AGXZ3","canonical_record":{"source":{"id":"2606.24081","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-23T02:49:10Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"a52ecb6e892bd65fa87c1a991ba9946d56d8d4f0551e15ec25d2aadf7d5a9cb3","abstract_canon_sha256":"d3885f873b3bac9011213b9f170801354c32c7e0fa235550e59433081c213c86"},"schema_version":"1.0"},"canonical_sha256":"f9f8035f3bd07f9cea259d06eb605b953266cf3e5e7a1968ae7d1949d018ac37","source":{"kind":"arxiv","id":"2606.24081","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.24081","created_at":"2026-06-24T01:14:39Z"},{"alias_kind":"arxiv_version","alias_value":"2606.24081v1","created_at":"2026-06-24T01:14:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.24081","created_at":"2026-06-24T01:14:39Z"},{"alias_kind":"pith_short_12","alias_value":"7H4AGXZ32B7Z","created_at":"2026-06-24T01:14:39Z"},{"alias_kind":"pith_short_16","alias_value":"7H4AGXZ32B7ZZ2RF","created_at":"2026-06-24T01:14:39Z"},{"alias_kind":"pith_short_8","alias_value":"7H4AGXZ3","created_at":"2026-06-24T01:14:39Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:7H4AGXZ32B7ZZ2RFTUDOWYC3SU","target":"record","payload":{"canonical_record":{"source":{"id":"2606.24081","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-23T02:49:10Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"a52ecb6e892bd65fa87c1a991ba9946d56d8d4f0551e15ec25d2aadf7d5a9cb3","abstract_canon_sha256":"d3885f873b3bac9011213b9f170801354c32c7e0fa235550e59433081c213c86"},"schema_version":"1.0"},"canonical_sha256":"f9f8035f3bd07f9cea259d06eb605b953266cf3e5e7a1968ae7d1949d018ac37","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-24T01:14:39.813986Z","signature_b64":"0E05FoAmNVkItaKlHjVq1cbAknQ2QhQYt4Ee9kJEu1QUb3lBLDCaex7k/TLoj5pUwLwYRup31BQbfGYPLuGqCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"f9f8035f3bd07f9cea259d06eb605b953266cf3e5e7a1968ae7d1949d018ac37","last_reissued_at":"2026-06-24T01:14:39.813592Z","signature_status":"signed_v1","first_computed_at":"2026-06-24T01:14:39.813592Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.24081","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-24T01:14:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hpnIXBMN57Ja+lbFx/D/GcyFZTUOXaYofa1500mY0uAKvGuJZWbCn292wx2mzCC0M2JD/PK5X9NQ5r2oMPXMCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-26T12:54:04.214899Z"},"content_sha256":"6d936d6fa2f827c95c65f9d80b8b048abffb3cc0be68a727261ec8bdb81ad005","schema_version":"1.0","event_id":"sha256:6d936d6fa2f827c95c65f9d80b8b048abffb3cc0be68a727261ec8bdb81ad005"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:7H4AGXZ32B7ZZ2RFTUDOWYC3SU","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"PixJail: Self-Evolving Paper-to-Pipeline Reproduction for Text-to-Image Jailbreak Evaluation","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Han Sun, Jiaheng Wei, Jinlin Wu, Leyi Sheng, Xinlei He, Yuntao Yue, Zhen Sun","submitted_at":"2026-06-23T02:49:10Z","abstract_excerpt":"As Text-to-Image (T2I) jailbreak techniques evolve rapidly, existing benchmarks and reproduction workflows often struggle to keep pace. More importantly, T2I jailbreak evaluation is not a single prompt-level test, but a pipeline-level problem shaped by multiple stages, including prompt transformation, image generation, safety filtering, and multimodal judging. This makes results across papers difficult to reliably reproduce and fairly compare. To bridge this gap, we propose PixJail, a self-evolving paper-to-pipeline agent framework for reproducible T2I jailbreak evaluation. Given a T2I jailbre"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.24081","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.24081/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-24T01:14:39Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7H4tB6+/t8sN3yHaO4N0pO8JPMmtZNkXpmJqhbFAlcdtRMrsWvhEoL397ffRttXqw9Q/p7p1UVx9zUPv71cECw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-26T12:54:04.215330Z"},"content_sha256":"c46d6bebac5d32c4c1f56ddbd2abe3595fa3c14f2af6364e0ee27832417d2c67","schema_version":"1.0","event_id":"sha256:c46d6bebac5d32c4c1f56ddbd2abe3595fa3c14f2af6364e0ee27832417d2c67"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/7H4AGXZ32B7ZZ2RFTUDOWYC3SU/bundle.json","state_url":"https://pith.science/pith/7H4AGXZ32B7ZZ2RFTUDOWYC3SU/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/7H4AGXZ32B7ZZ2RFTUDOWYC3SU/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-26T12:54:04Z","links":{"resolver":"https://pith.science/pith/7H4AGXZ32B7ZZ2RFTUDOWYC3SU","bundle":"https://pith.science/pith/7H4AGXZ32B7ZZ2RFTUDOWYC3SU/bundle.json","state":"https://pith.science/pith/7H4AGXZ32B7ZZ2RFTUDOWYC3SU/state.json","well_known_bundle":"https://pith.science/.well-known/pith/7H4AGXZ32B7ZZ2RFTUDOWYC3SU/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:7H4AGXZ32B7ZZ2RFTUDOWYC3SU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"d3885f873b3bac9011213b9f170801354c32c7e0fa235550e59433081c213c86","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-23T02:49:10Z","title_canon_sha256":"a52ecb6e892bd65fa87c1a991ba9946d56d8d4f0551e15ec25d2aadf7d5a9cb3"},"schema_version":"1.0","source":{"id":"2606.24081","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.24081","created_at":"2026-06-24T01:14:39Z"},{"alias_kind":"arxiv_version","alias_value":"2606.24081v1","created_at":"2026-06-24T01:14:39Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.24081","created_at":"2026-06-24T01:14:39Z"},{"alias_kind":"pith_short_12","alias_value":"7H4AGXZ32B7Z","created_at":"2026-06-24T01:14:39Z"},{"alias_kind":"pith_short_16","alias_value":"7H4AGXZ32B7ZZ2RF","created_at":"2026-06-24T01:14:39Z"},{"alias_kind":"pith_short_8","alias_value":"7H4AGXZ3","created_at":"2026-06-24T01:14:39Z"}],"graph_snapshots":[{"event_id":"sha256:c46d6bebac5d32c4c1f56ddbd2abe3595fa3c14f2af6364e0ee27832417d2c67","target":"graph","created_at":"2026-06-24T01:14:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.24081/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"As Text-to-Image (T2I) jailbreak techniques evolve rapidly, existing benchmarks and reproduction workflows often struggle to keep pace. More importantly, T2I jailbreak evaluation is not a single prompt-level test, but a pipeline-level problem shaped by multiple stages, including prompt transformation, image generation, safety filtering, and multimodal judging. This makes results across papers difficult to reliably reproduce and fairly compare. To bridge this gap, we propose PixJail, a self-evolving paper-to-pipeline agent framework for reproducible T2I jailbreak evaluation. Given a T2I jailbre","authors_text":"Han Sun, Jiaheng Wei, Jinlin Wu, Leyi Sheng, Xinlei He, Yuntao Yue, Zhen Sun","cross_cats":["cs.AI"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-23T02:49:10Z","title":"PixJail: Self-Evolving Paper-to-Pipeline Reproduction for Text-to-Image Jailbreak Evaluation"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.24081","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:6d936d6fa2f827c95c65f9d80b8b048abffb3cc0be68a727261ec8bdb81ad005","target":"record","created_at":"2026-06-24T01:14:39Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"d3885f873b3bac9011213b9f170801354c32c7e0fa235550e59433081c213c86","cross_cats_sorted":["cs.AI"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-23T02:49:10Z","title_canon_sha256":"a52ecb6e892bd65fa87c1a991ba9946d56d8d4f0551e15ec25d2aadf7d5a9cb3"},"schema_version":"1.0","source":{"id":"2606.24081","kind":"arxiv","version":1}},"canonical_sha256":"f9f8035f3bd07f9cea259d06eb605b953266cf3e5e7a1968ae7d1949d018ac37","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"f9f8035f3bd07f9cea259d06eb605b953266cf3e5e7a1968ae7d1949d018ac37","first_computed_at":"2026-06-24T01:14:39.813592Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-24T01:14:39.813592Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"0E05FoAmNVkItaKlHjVq1cbAknQ2QhQYt4Ee9kJEu1QUb3lBLDCaex7k/TLoj5pUwLwYRup31BQbfGYPLuGqCQ==","signature_status":"signed_v1","signed_at":"2026-06-24T01:14:39.813986Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.24081","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:6d936d6fa2f827c95c65f9d80b8b048abffb3cc0be68a727261ec8bdb81ad005","sha256:c46d6bebac5d32c4c1f56ddbd2abe3595fa3c14f2af6364e0ee27832417d2c67"],"state_sha256":"2132986af7c977a8b84e0f108eaa41eaa7ffe36517d4948db70124bce55133db"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"UcinTr7Y9/V83TRfjTSXVDyO/xnKS2oQe+khOoed01Ep0KOKTHzju9B6fIVcZrSTc20OdOwvmtU7xRumMENyCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-26T12:54:04.217394Z","bundle_sha256":"6002a7580e8b0854c3dd5aa1ea6e9eae6630665c33dec21b609ae516380a5a20"}}