{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:JYESUFPPMSVYOVZC6X567W3PCG","short_pith_number":"pith:JYESUFPP","canonical_record":{"source":{"id":"2603.08316","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-03-09T12:38:28Z","cross_cats_sorted":["cs.CL","cs.CV"],"title_canon_sha256":"17189ddb3763dc907cd19fa40a889615cb7290678cf99da29b2d0308f7352c1b","abstract_canon_sha256":"9b375c2660b48f2126a34abff75180d5864c1e6fc88ab5450e54137b460761ee"},"schema_version":"1.0"},"canonical_sha256":"4e092a15ef64ab875722f5fbefdb6f1187dc006ca7dc62648ae411f67df20753","source":{"kind":"arxiv","id":"2603.08316","version":3},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2603.08316","created_at":"2026-07-02T01:17:29Z"},{"alias_kind":"arxiv_version","alias_value":"2603.08316v3","created_at":"2026-07-02T01:17:29Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2603.08316","created_at":"2026-07-02T01:17:29Z"},{"alias_kind":"pith_short_12","alias_value":"JYESUFPPMSVY","created_at":"2026-07-02T01:17:29Z"},{"alias_kind":"pith_short_16","alias_value":"JYESUFPPMSVYOVZC","created_at":"2026-07-02T01:17:29Z"},{"alias_kind":"pith_short_8","alias_value":"JYESUFPP","created_at":"2026-07-02T01:17:29Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:JYESUFPPMSVYOVZC6X567W3PCG","target":"record","payload":{"canonical_record":{"source":{"id":"2603.08316","kind":"arxiv","version":3},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-03-09T12:38:28Z","cross_cats_sorted":["cs.CL","cs.CV"],"title_canon_sha256":"17189ddb3763dc907cd19fa40a889615cb7290678cf99da29b2d0308f7352c1b","abstract_canon_sha256":"9b375c2660b48f2126a34abff75180d5864c1e6fc88ab5450e54137b460761ee"},"schema_version":"1.0"},"canonical_sha256":"4e092a15ef64ab875722f5fbefdb6f1187dc006ca7dc62648ae411f67df20753","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-02T01:17:29.206402Z","signature_b64":"FojkD8XqEGh6xmzOFRhNLGjnE8AVs0+KBfGDNtqGWFyOeNz3aOuInUb5g+JbBM/0NUnIaPg++lBNbhC+rEcWBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"4e092a15ef64ab875722f5fbefdb6f1187dc006ca7dc62648ae411f67df20753","last_reissued_at":"2026-07-02T01:17:29.205914Z","signature_status":"signed_v1","first_computed_at":"2026-07-02T01:17:29.205914Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2603.08316","source_version":3,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-02T01:17:29Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"UHBWM6u+tpQQMgeWc/csiHlxU8hizzxM4oI4n9huO0GH5MxVtglDVvEnnf1j2vs0mtLjL0maQZ2Wm4RRjzZVCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T23:28:50.516650Z"},"content_sha256":"f01c64fe97daf41deb2e5baac4cab3609073647cce9d1aa251840b1e9ba0a752","schema_version":"1.0","event_id":"sha256:f01c64fe97daf41deb2e5baac4cab3609073647cce9d1aa251840b1e9ba0a752"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:JYESUFPPMSVYOVZC6X567W3PCG","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"SlowBA: An efficiency backdoor attack towards VLM-based GUI agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL","cs.CV"],"primary_cat":"cs.CR","authors_text":"Haojin Zhu, Haozhen Tan, Junxian Li, Tu Lan, Yan Meng","submitted_at":"2026-03-09T12:38:28Z","abstract_excerpt":"Modern vision-language-model (VLM) based graphical user interface (GUI) agents are expected not only to execute actions accurately but also to respond to user instructions with low latency. While existing research on GUI-agent security mainly focuses on manipulating action correctness, the security risks related to response efficiency remain largely unexplored. In this paper, we introduce SlowBA, a novel backdoor attack that targets the responsiveness of VLM-based GUI agents. The key idea is to manipulate response latency by inducing excessively long reasoning chains under specific trigger pat"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2603.08316","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2603.08316/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-02T01:17:29Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ux3I4evigPsoz899qlUN9qXofnKiAXXYpegfFlqYDA8ZMNOLYVLQeI/VtUzcgQ6NCjp7U5YTu/y/nO3QeznnAA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-07-02T23:28:50.517019Z"},"content_sha256":"3e697350c8b6c60820d8348ca17ba704019f07f3b3ded35099d579f0444446b8","schema_version":"1.0","event_id":"sha256:3e697350c8b6c60820d8348ca17ba704019f07f3b3ded35099d579f0444446b8"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/JYESUFPPMSVYOVZC6X567W3PCG/bundle.json","state_url":"https://pith.science/pith/JYESUFPPMSVYOVZC6X567W3PCG/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/JYESUFPPMSVYOVZC6X567W3PCG/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-07-02T23:28:50Z","links":{"resolver":"https://pith.science/pith/JYESUFPPMSVYOVZC6X567W3PCG","bundle":"https://pith.science/pith/JYESUFPPMSVYOVZC6X567W3PCG/bundle.json","state":"https://pith.science/pith/JYESUFPPMSVYOVZC6X567W3PCG/state.json","well_known_bundle":"https://pith.science/.well-known/pith/JYESUFPPMSVYOVZC6X567W3PCG/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:JYESUFPPMSVYOVZC6X567W3PCG","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"9b375c2660b48f2126a34abff75180d5864c1e6fc88ab5450e54137b460761ee","cross_cats_sorted":["cs.CL","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-03-09T12:38:28Z","title_canon_sha256":"17189ddb3763dc907cd19fa40a889615cb7290678cf99da29b2d0308f7352c1b"},"schema_version":"1.0","source":{"id":"2603.08316","kind":"arxiv","version":3}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2603.08316","created_at":"2026-07-02T01:17:29Z"},{"alias_kind":"arxiv_version","alias_value":"2603.08316v3","created_at":"2026-07-02T01:17:29Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2603.08316","created_at":"2026-07-02T01:17:29Z"},{"alias_kind":"pith_short_12","alias_value":"JYESUFPPMSVY","created_at":"2026-07-02T01:17:29Z"},{"alias_kind":"pith_short_16","alias_value":"JYESUFPPMSVYOVZC","created_at":"2026-07-02T01:17:29Z"},{"alias_kind":"pith_short_8","alias_value":"JYESUFPP","created_at":"2026-07-02T01:17:29Z"}],"graph_snapshots":[{"event_id":"sha256:3e697350c8b6c60820d8348ca17ba704019f07f3b3ded35099d579f0444446b8","target":"graph","created_at":"2026-07-02T01:17:29Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2603.08316/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Modern vision-language-model (VLM) based graphical user interface (GUI) agents are expected not only to execute actions accurately but also to respond to user instructions with low latency. While existing research on GUI-agent security mainly focuses on manipulating action correctness, the security risks related to response efficiency remain largely unexplored. In this paper, we introduce SlowBA, a novel backdoor attack that targets the responsiveness of VLM-based GUI agents. The key idea is to manipulate response latency by inducing excessively long reasoning chains under specific trigger pat","authors_text":"Haojin Zhu, Haozhen Tan, Junxian Li, Tu Lan, Yan Meng","cross_cats":["cs.CL","cs.CV"],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-03-09T12:38:28Z","title":"SlowBA: An efficiency backdoor attack towards VLM-based GUI agents"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2603.08316","kind":"arxiv","version":3},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f01c64fe97daf41deb2e5baac4cab3609073647cce9d1aa251840b1e9ba0a752","target":"record","created_at":"2026-07-02T01:17:29Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"9b375c2660b48f2126a34abff75180d5864c1e6fc88ab5450e54137b460761ee","cross_cats_sorted":["cs.CL","cs.CV"],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-03-09T12:38:28Z","title_canon_sha256":"17189ddb3763dc907cd19fa40a889615cb7290678cf99da29b2d0308f7352c1b"},"schema_version":"1.0","source":{"id":"2603.08316","kind":"arxiv","version":3}},"canonical_sha256":"4e092a15ef64ab875722f5fbefdb6f1187dc006ca7dc62648ae411f67df20753","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"4e092a15ef64ab875722f5fbefdb6f1187dc006ca7dc62648ae411f67df20753","first_computed_at":"2026-07-02T01:17:29.205914Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-02T01:17:29.205914Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"FojkD8XqEGh6xmzOFRhNLGjnE8AVs0+KBfGDNtqGWFyOeNz3aOuInUb5g+JbBM/0NUnIaPg++lBNbhC+rEcWBw==","signature_status":"signed_v1","signed_at":"2026-07-02T01:17:29.206402Z","signed_message":"canonical_sha256_bytes"},"source_id":"2603.08316","source_kind":"arxiv","source_version":3}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f01c64fe97daf41deb2e5baac4cab3609073647cce9d1aa251840b1e9ba0a752","sha256:3e697350c8b6c60820d8348ca17ba704019f07f3b3ded35099d579f0444446b8"],"state_sha256":"862af4474a74422470ad71004d0643ec9e9beac4ee4183263de1ea651dbe8d2e"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"TRUtKCQ0XJwqdXIeAmmdHL1c5MyIi13NajmHTH/L3HEuXrDhR/lBoqaatGjtx7yWsDayOUhqLTKtAxosp40/CA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-07-02T23:28:50.519080Z","bundle_sha256":"c3a8e72ea549d7404fb17db5223147808f683fecd4310fe940d03c3b95ac52c6"}}