{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:GVFVZWSJ724DF7YEWKXP3DHQDR","short_pith_number":"pith:GVFVZWSJ","canonical_record":{"source":{"id":"2606.11648","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T04:26:57Z","cross_cats_sorted":["cs.CL"],"title_canon_sha256":"b943d6fb0ebf0a4ab240feb8c505aaf9e43cc59229440f39200ddf06fcfebd75","abstract_canon_sha256":"b0f2c261f15a704cf68d2fd706ceb6ed759260f0f38b29642f02eb7c41a38d2b"},"schema_version":"1.0"},"canonical_sha256":"354b5cda49feb832ff04b2aefd8cf01c71005a668875adbfa692664b4b5f33aa","source":{"kind":"arxiv","id":"2606.11648","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.11648","created_at":"2026-06-11T01:10:00Z"},{"alias_kind":"arxiv_version","alias_value":"2606.11648v1","created_at":"2026-06-11T01:10:00Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.11648","created_at":"2026-06-11T01:10:00Z"},{"alias_kind":"pith_short_12","alias_value":"GVFVZWSJ724D","created_at":"2026-06-11T01:10:00Z"},{"alias_kind":"pith_short_16","alias_value":"GVFVZWSJ724DF7YE","created_at":"2026-06-11T01:10:00Z"},{"alias_kind":"pith_short_8","alias_value":"GVFVZWSJ","created_at":"2026-06-11T01:10:00Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:GVFVZWSJ724DF7YEWKXP3DHQDR","target":"record","payload":{"canonical_record":{"source":{"id":"2606.11648","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T04:26:57Z","cross_cats_sorted":["cs.CL"],"title_canon_sha256":"b943d6fb0ebf0a4ab240feb8c505aaf9e43cc59229440f39200ddf06fcfebd75","abstract_canon_sha256":"b0f2c261f15a704cf68d2fd706ceb6ed759260f0f38b29642f02eb7c41a38d2b"},"schema_version":"1.0"},"canonical_sha256":"354b5cda49feb832ff04b2aefd8cf01c71005a668875adbfa692664b4b5f33aa","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-11T01:10:00.891297Z","signature_b64":"IJdIz3gZ+6ZmjEQH+SyUsMxFXLZaPj2HE4bX1FtkG8VfDb5yeu4uroHdybg+9f8+98s9h1EWD0uEVyToCpgTCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"354b5cda49feb832ff04b2aefd8cf01c71005a668875adbfa692664b4b5f33aa","last_reissued_at":"2026-06-11T01:10:00.890542Z","signature_status":"signed_v1","first_computed_at":"2026-06-11T01:10:00.890542Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.11648","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-11T01:10:00Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"fmZczZ2qz06TWKoMav0xv+7oHgWbg4cJeBhP9ow0Unwxp/cv+uSpN2yLwt9SK6N5bC7Vt6TspUIPRSXpCwSNAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-20T06:55:04.871983Z"},"content_sha256":"12b1c6da277d3aede1ffa09cd32c6041d8d61d287485527137b9070b93546b7b","schema_version":"1.0","event_id":"sha256:12b1c6da277d3aede1ffa09cd32c6041d8d61d287485527137b9070b93546b7b"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:GVFVZWSJ724DF7YEWKXP3DHQDR","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Dummy Backdoor as a Defense: Removing Unknown Backdoors via Shared Internal Mechanisms for Generative LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.CR","authors_text":"Akira Ito, Kazuki Iwahana, Kenichiro Omintato, Masaru Matsubayashi, Takuma Koyama, Toshiki Shibahara","submitted_at":"2026-06-10T04:26:57Z","abstract_excerpt":"Backdoor attacks pose a serious threat to the safety and reliability of Large Language Models (LLMs), as they cause models to behave normally on clean inputs while producing attacker-specified responses when hidden triggers are present. Removing such unknown backdoors is particularly challenging when the defender does not know the backdoor attack types or the internal mechanisms formed through backdoor training. In this work, we propose a simple but effective backdoor removal method based on shared internal mechanisms across different backdoors. First, we show that different backdoors with the"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.11648","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.11648/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-11T01:10:00Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hscLOS8RiESvdBnXqpKGG3Q3VzGvZfeMkbDyUlId40yE9PAyoUVUCTEAoTLXslLSpfDo3dA8+O02vYBnXINFDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-20T06:55:04.872367Z"},"content_sha256":"0720448d517bc53b93cb9466ba42a06ac0bcd0a7a9d91abd570e5ad15778697f","schema_version":"1.0","event_id":"sha256:0720448d517bc53b93cb9466ba42a06ac0bcd0a7a9d91abd570e5ad15778697f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/GVFVZWSJ724DF7YEWKXP3DHQDR/bundle.json","state_url":"https://pith.science/pith/GVFVZWSJ724DF7YEWKXP3DHQDR/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/GVFVZWSJ724DF7YEWKXP3DHQDR/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-20T06:55:04Z","links":{"resolver":"https://pith.science/pith/GVFVZWSJ724DF7YEWKXP3DHQDR","bundle":"https://pith.science/pith/GVFVZWSJ724DF7YEWKXP3DHQDR/bundle.json","state":"https://pith.science/pith/GVFVZWSJ724DF7YEWKXP3DHQDR/state.json","well_known_bundle":"https://pith.science/.well-known/pith/GVFVZWSJ724DF7YEWKXP3DHQDR/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:GVFVZWSJ724DF7YEWKXP3DHQDR","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"b0f2c261f15a704cf68d2fd706ceb6ed759260f0f38b29642f02eb7c41a38d2b","cross_cats_sorted":["cs.CL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T04:26:57Z","title_canon_sha256":"b943d6fb0ebf0a4ab240feb8c505aaf9e43cc59229440f39200ddf06fcfebd75"},"schema_version":"1.0","source":{"id":"2606.11648","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.11648","created_at":"2026-06-11T01:10:00Z"},{"alias_kind":"arxiv_version","alias_value":"2606.11648v1","created_at":"2026-06-11T01:10:00Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.11648","created_at":"2026-06-11T01:10:00Z"},{"alias_kind":"pith_short_12","alias_value":"GVFVZWSJ724D","created_at":"2026-06-11T01:10:00Z"},{"alias_kind":"pith_short_16","alias_value":"GVFVZWSJ724DF7YE","created_at":"2026-06-11T01:10:00Z"},{"alias_kind":"pith_short_8","alias_value":"GVFVZWSJ","created_at":"2026-06-11T01:10:00Z"}],"graph_snapshots":[{"event_id":"sha256:0720448d517bc53b93cb9466ba42a06ac0bcd0a7a9d91abd570e5ad15778697f","target":"graph","created_at":"2026-06-11T01:10:00Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.11648/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Backdoor attacks pose a serious threat to the safety and reliability of Large Language Models (LLMs), as they cause models to behave normally on clean inputs while producing attacker-specified responses when hidden triggers are present. Removing such unknown backdoors is particularly challenging when the defender does not know the backdoor attack types or the internal mechanisms formed through backdoor training. In this work, we propose a simple but effective backdoor removal method based on shared internal mechanisms across different backdoors. First, we show that different backdoors with the","authors_text":"Akira Ito, Kazuki Iwahana, Kenichiro Omintato, Masaru Matsubayashi, Takuma Koyama, Toshiki Shibahara","cross_cats":["cs.CL"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T04:26:57Z","title":"Dummy Backdoor as a Defense: Removing Unknown Backdoors via Shared Internal Mechanisms for Generative LLMs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.11648","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:12b1c6da277d3aede1ffa09cd32c6041d8d61d287485527137b9070b93546b7b","target":"record","created_at":"2026-06-11T01:10:00Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"b0f2c261f15a704cf68d2fd706ceb6ed759260f0f38b29642f02eb7c41a38d2b","cross_cats_sorted":["cs.CL"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-10T04:26:57Z","title_canon_sha256":"b943d6fb0ebf0a4ab240feb8c505aaf9e43cc59229440f39200ddf06fcfebd75"},"schema_version":"1.0","source":{"id":"2606.11648","kind":"arxiv","version":1}},"canonical_sha256":"354b5cda49feb832ff04b2aefd8cf01c71005a668875adbfa692664b4b5f33aa","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"354b5cda49feb832ff04b2aefd8cf01c71005a668875adbfa692664b4b5f33aa","first_computed_at":"2026-06-11T01:10:00.890542Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-11T01:10:00.890542Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"IJdIz3gZ+6ZmjEQH+SyUsMxFXLZaPj2HE4bX1FtkG8VfDb5yeu4uroHdybg+9f8+98s9h1EWD0uEVyToCpgTCg==","signature_status":"signed_v1","signed_at":"2026-06-11T01:10:00.891297Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.11648","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:12b1c6da277d3aede1ffa09cd32c6041d8d61d287485527137b9070b93546b7b","sha256:0720448d517bc53b93cb9466ba42a06ac0bcd0a7a9d91abd570e5ad15778697f"],"state_sha256":"6262a1939710d007d2a555e73659733309753fc7455b0b68a64168bebc799be8"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ULc61997vDmXNOBS6Pgo3+uaJwuS1aktrfDHywoIKq3ApoIL09S1TU7KXI5QCjLq1+Rj1jN3dF4rUBoeZ4yhCQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-20T06:55:04.874278Z","bundle_sha256":"22bffc88339943f5372fc2dbb5dc535a0ac6381904c8cefba2836bb7e46f2de6"}}