{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:F6SCZME2US3S4SJLUBZ4HJ7SIW","short_pith_number":"pith:F6SCZME2","canonical_record":{"source":{"id":"2605.28609","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2026-05-27T15:24:31Z","cross_cats_sorted":[],"title_canon_sha256":"7e312f1f393d5b924d44306cd0d710d7da87fbbd9c1d27d348b621063c5540f0","abstract_canon_sha256":"a61e7e044f8ace03dbefa86d0824876b5e9a87a5f5ce55a73e4d130ed09242ed"},"schema_version":"1.0"},"canonical_sha256":"2fa42cb09aa4b72e492ba073c3a7f245b1e0f2d04dad66c3126929a9ad5da770","source":{"kind":"arxiv","id":"2605.28609","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.28609","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"arxiv_version","alias_value":"2605.28609v1","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.28609","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"pith_short_12","alias_value":"F6SCZME2US3S","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"pith_short_16","alias_value":"F6SCZME2US3S4SJL","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"pith_short_8","alias_value":"F6SCZME2","created_at":"2026-05-28T02:04:57Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:F6SCZME2US3S4SJLUBZ4HJ7SIW","target":"record","payload":{"canonical_record":{"source":{"id":"2605.28609","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2026-05-27T15:24:31Z","cross_cats_sorted":[],"title_canon_sha256":"7e312f1f393d5b924d44306cd0d710d7da87fbbd9c1d27d348b621063c5540f0","abstract_canon_sha256":"a61e7e044f8ace03dbefa86d0824876b5e9a87a5f5ce55a73e4d130ed09242ed"},"schema_version":"1.0"},"canonical_sha256":"2fa42cb09aa4b72e492ba073c3a7f245b1e0f2d04dad66c3126929a9ad5da770","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-28T02:04:57.653842Z","signature_b64":"5MlULgtCh5Whtbl5UmiB0pH74YeDxSblMltGds9ufjSpgqIAuIcYDOEdtbWDIMvmBUs/YunzAcL0VFBl780lDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"2fa42cb09aa4b72e492ba073c3a7f245b1e0f2d04dad66c3126929a9ad5da770","last_reissued_at":"2026-05-28T02:04:57.653450Z","signature_status":"signed_v1","first_computed_at":"2026-05-28T02:04:57.653450Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.28609","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-28T02:04:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"7iEZirx15O+XVEWS/qvMEBytgnvG1RtZw18fjkC1Uldy403uqpb6P/7ciwF0bchHYVQX+OVTwzmfkRD/le40Cg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T04:00:52.207661Z"},"content_sha256":"eaf57ce7183931bf7c0f0fea7f0c3f8ccb8be6bc711ca82c5310c874adcef89a","schema_version":"1.0","event_id":"sha256:eaf57ce7183931bf7c0f0fea7f0c3f8ccb8be6bc711ca82c5310c874adcef89a"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:F6SCZME2US3S4SJLUBZ4HJ7SIW","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"JECA^2: Judgment-Explanation Consistent Adversarial Attack against Forensic Vision-Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CV","authors_text":"Jiachen Qian","submitted_at":"2026-05-27T15:24:31Z","abstract_excerpt":"Forensic vision-language models (VLMs) have recently been developed to detect image tampering and provide natural-language explanations. However, their robustness against adversarial manipulation remains underexplored. Existing adversarial attacks typically aim to flip the model's binary judgment, while the accompanying explanation may still reveal forensic cues and contradict the attacked judgment. In this paper, we study judgment-explanation consistent adversarial attacks against forensic VLMs and propose JECA^2, a controlled white-box red-team diagnostic that jointly redirects visual attrib"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.28609","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.28609/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-28T02:04:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"N1bC1MocbR6yAWtR510W/S0W5tueaEueq127ajPcHoc9MrgTeaSazGOk+PzhaHpz+LfGaSZwrqx5DnGrEkrNDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T04:00:52.208299Z"},"content_sha256":"2c6a6252e480ac211fb74ed7988a9966fd537b78eed70b97b2c006fb76fc63ae","schema_version":"1.0","event_id":"sha256:2c6a6252e480ac211fb74ed7988a9966fd537b78eed70b97b2c006fb76fc63ae"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/F6SCZME2US3S4SJLUBZ4HJ7SIW/bundle.json","state_url":"https://pith.science/pith/F6SCZME2US3S4SJLUBZ4HJ7SIW/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/F6SCZME2US3S4SJLUBZ4HJ7SIW/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-30T04:00:52Z","links":{"resolver":"https://pith.science/pith/F6SCZME2US3S4SJLUBZ4HJ7SIW","bundle":"https://pith.science/pith/F6SCZME2US3S4SJLUBZ4HJ7SIW/bundle.json","state":"https://pith.science/pith/F6SCZME2US3S4SJLUBZ4HJ7SIW/state.json","well_known_bundle":"https://pith.science/.well-known/pith/F6SCZME2US3S4SJLUBZ4HJ7SIW/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:F6SCZME2US3S4SJLUBZ4HJ7SIW","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"a61e7e044f8ace03dbefa86d0824876b5e9a87a5f5ce55a73e4d130ed09242ed","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2026-05-27T15:24:31Z","title_canon_sha256":"7e312f1f393d5b924d44306cd0d710d7da87fbbd9c1d27d348b621063c5540f0"},"schema_version":"1.0","source":{"id":"2605.28609","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.28609","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"arxiv_version","alias_value":"2605.28609v1","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.28609","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"pith_short_12","alias_value":"F6SCZME2US3S","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"pith_short_16","alias_value":"F6SCZME2US3S4SJL","created_at":"2026-05-28T02:04:57Z"},{"alias_kind":"pith_short_8","alias_value":"F6SCZME2","created_at":"2026-05-28T02:04:57Z"}],"graph_snapshots":[{"event_id":"sha256:2c6a6252e480ac211fb74ed7988a9966fd537b78eed70b97b2c006fb76fc63ae","target":"graph","created_at":"2026-05-28T02:04:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.28609/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Forensic vision-language models (VLMs) have recently been developed to detect image tampering and provide natural-language explanations. However, their robustness against adversarial manipulation remains underexplored. Existing adversarial attacks typically aim to flip the model's binary judgment, while the accompanying explanation may still reveal forensic cues and contradict the attacked judgment. In this paper, we study judgment-explanation consistent adversarial attacks against forensic VLMs and propose JECA^2, a controlled white-box red-team diagnostic that jointly redirects visual attrib","authors_text":"Jiachen Qian","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2026-05-27T15:24:31Z","title":"JECA^2: Judgment-Explanation Consistent Adversarial Attack against Forensic Vision-Language Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.28609","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:eaf57ce7183931bf7c0f0fea7f0c3f8ccb8be6bc711ca82c5310c874adcef89a","target":"record","created_at":"2026-05-28T02:04:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"a61e7e044f8ace03dbefa86d0824876b5e9a87a5f5ce55a73e4d130ed09242ed","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CV","submitted_at":"2026-05-27T15:24:31Z","title_canon_sha256":"7e312f1f393d5b924d44306cd0d710d7da87fbbd9c1d27d348b621063c5540f0"},"schema_version":"1.0","source":{"id":"2605.28609","kind":"arxiv","version":1}},"canonical_sha256":"2fa42cb09aa4b72e492ba073c3a7f245b1e0f2d04dad66c3126929a9ad5da770","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"2fa42cb09aa4b72e492ba073c3a7f245b1e0f2d04dad66c3126929a9ad5da770","first_computed_at":"2026-05-28T02:04:57.653450Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-28T02:04:57.653450Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"5MlULgtCh5Whtbl5UmiB0pH74YeDxSblMltGds9ufjSpgqIAuIcYDOEdtbWDIMvmBUs/YunzAcL0VFBl780lDA==","signature_status":"signed_v1","signed_at":"2026-05-28T02:04:57.653842Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.28609","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:eaf57ce7183931bf7c0f0fea7f0c3f8ccb8be6bc711ca82c5310c874adcef89a","sha256:2c6a6252e480ac211fb74ed7988a9966fd537b78eed70b97b2c006fb76fc63ae"],"state_sha256":"5130b5b5b402a435dd99d2c758a87f29c93ffcc8af3f66eb0daba28327d4a2f5"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2AqjES7gI/W9HOzv7T9F/aemnPshjEyuuDoZiPgomrGwX8vpyakatCbnhT+NqyOAgiIr3xSDfKfVLCKvfw7sDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-30T04:00:52.211349Z","bundle_sha256":"f613c6d5c6273f232f36bafeb6b4612c954bac213709a1c793963e9f42929c74"}}