{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:HQSNFHOZWQCRRJQ4TSIG6FESVD","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"6065d164f1e05ac5d82fc6700ccf5d0804838dd97e46388399981b9835625d70","cross_cats_sorted":["cs.CV","cs.SY","eess.SY"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.RO","submitted_at":"2026-06-11T07:12:17Z","title_canon_sha256":"460b9cfa9213a4da91252f381a32944d7d54f992ec58c7de7c17947444906b74"},"schema_version":"1.0","source":{"id":"2606.12978","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.12978","created_at":"2026-06-12T01:09:35Z"},{"alias_kind":"arxiv_version","alias_value":"2606.12978v1","created_at":"2026-06-12T01:09:35Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.12978","created_at":"2026-06-12T01:09:35Z"},{"alias_kind":"pith_short_12","alias_value":"HQSNFHOZWQCR","created_at":"2026-06-12T01:09:35Z"},{"alias_kind":"pith_short_16","alias_value":"HQSNFHOZWQCRRJQ4","created_at":"2026-06-12T01:09:35Z"},{"alias_kind":"pith_short_8","alias_value":"HQSNFHOZ","created_at":"2026-06-12T01:09:35Z"}],"graph_snapshots":[{"event_id":"sha256:c96232a3d052f94460749d3d8db7c4d8ab85dbf1da74ca6fde08ebd2ef77cee3","target":"graph","created_at":"2026-06-12T01:09:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.12978/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Vision-language-action (VLA) policies bring natural language into closed-loop robot control, enabling robots to execute manipulation tasks directly from text instructions. The same interface gives text a recurring role in control because the prompt is reused at every replanning step, and each prompt-conditioned action changes the future observations on which the policy acts. Existing VLA attacks study adversarial prompts that elicit targeted low-level actions or make such actions persist across changing images. We identify a stronger trajectory-level failure mode: a prompt that still $\\textit{","authors_text":"Dilek Hakkani-T\\\"ur, Gokul Puthumanaillam, Hooshang Nayyeri, Melkior Ornik, Pranay Thangeda, Vardhan Dongre","cross_cats":["cs.CV","cs.SY","eess.SY"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.RO","submitted_at":"2026-06-11T07:12:17Z","title":"Trajectory-Level Redirection Attacks on Vision-Language-Action Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.12978","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:cbc4c4ebe55e7af2ae6ac8c75d60f305c2e482b4b41fee4eaecb8670b1f1feec","target":"record","created_at":"2026-06-12T01:09:35Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"6065d164f1e05ac5d82fc6700ccf5d0804838dd97e46388399981b9835625d70","cross_cats_sorted":["cs.CV","cs.SY","eess.SY"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.RO","submitted_at":"2026-06-11T07:12:17Z","title_canon_sha256":"460b9cfa9213a4da91252f381a32944d7d54f992ec58c7de7c17947444906b74"},"schema_version":"1.0","source":{"id":"2606.12978","kind":"arxiv","version":1}},"canonical_sha256":"3c24d29dd9b40518a61c9c906f1492a8f5bc4a855855148758e69f74b3ccf783","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"3c24d29dd9b40518a61c9c906f1492a8f5bc4a855855148758e69f74b3ccf783","first_computed_at":"2026-06-12T01:09:35.967775Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-12T01:09:35.967775Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"0HsdyRrvP6miMet6Y8EDqaf8oOw53FhL2xY1Ca5A8SVB/N6RagoSY+Af+GWYgLV/w4FpcApbzttPnTgJr2aOCw==","signature_status":"signed_v1","signed_at":"2026-06-12T01:09:35.968181Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.12978","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:cbc4c4ebe55e7af2ae6ac8c75d60f305c2e482b4b41fee4eaecb8670b1f1feec","sha256:c96232a3d052f94460749d3d8db7c4d8ab85dbf1da74ca6fde08ebd2ef77cee3"],"state_sha256":"4afdfbcaa0111d0dbc5ddc3bf07c51a20d739c342d0bed14a050a8b6da609f68"}