{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:LK7PSMNMGWUIPD2OUZOIRVPWXP","short_pith_number":"pith:LK7PSMNM","schema_version":"1.0","canonical_sha256":"5abef931ac35a8878f4ea65c88d5f6bbf9f70a644d4f0087ffbde33c7c9bb0dc","source":{"kind":"arxiv","id":"2606.06697","version":1},"attestation_state":"computed","paper":{"title":"AgileOS: A GPU Operating System Layer for Protected CUDA Services","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.OS"],"primary_cat":"cs.CR","authors_text":"Alex Jones, Peipei Zhou, Yiyu Shi, Zhuoping Yang","submitted_at":"2026-06-04T20:34:56Z","abstract_excerpt":"Modern GPU applications increasingly interact with storage systems, network devices, vendor libraries, and GPU-resident services rather than executing only isolated compute kernels. This shift creates a need for operating-system-like protection around GPU services, where service metadata, device queues, memory-mapped I/O regions, and library-internal state should not be directly exposed to untrusted application kernels. However, today's CUDA programming model, by default, still gives each application direct ownership of its CUDA context, device pointers, runtime handles, module loading path, a"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2606.06697","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2026-06-04T20:34:56Z","cross_cats_sorted":["cs.OS"],"title_canon_sha256":"9bd0a68d6beb4a8ec3e0b5eb69ae851a7d9750e1b2eb5ac396d968fcccfb0b80","abstract_canon_sha256":"298429214ce9370bf991b011656343fcd4464f2c05ed6b146eaf5731f46f7828"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-08T01:04:23.201995Z","signature_b64":"ChJSK+2og/C5uNpWCZ/9AuSfFcwa+mBxxgrMB5udGlZJj8oAeFBmGiyFcRUqe0sociFzzU18e84GHzvGHbfvCg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5abef931ac35a8878f4ea65c88d5f6bbf9f70a644d4f0087ffbde33c7c9bb0dc","last_reissued_at":"2026-06-08T01:04:23.201008Z","signature_status":"signed_v1","first_computed_at":"2026-06-08T01:04:23.201008Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"AgileOS: A GPU Operating System Layer for Protected CUDA Services","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.OS"],"primary_cat":"cs.CR","authors_text":"Alex Jones, Peipei Zhou, Yiyu Shi, Zhuoping Yang","submitted_at":"2026-06-04T20:34:56Z","abstract_excerpt":"Modern GPU applications increasingly interact with storage systems, network devices, vendor libraries, and GPU-resident services rather than executing only isolated compute kernels. This shift creates a need for operating-system-like protection around GPU services, where service metadata, device queues, memory-mapped I/O regions, and library-internal state should not be directly exposed to untrusted application kernels. However, today's CUDA programming model, by default, still gives each application direct ownership of its CUDA context, device pointers, runtime handles, module loading path, a"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.06697","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.06697/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2606.06697","created_at":"2026-06-08T01:04:23.201191+00:00"},{"alias_kind":"arxiv_version","alias_value":"2606.06697v1","created_at":"2026-06-08T01:04:23.201191+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.06697","created_at":"2026-06-08T01:04:23.201191+00:00"},{"alias_kind":"pith_short_12","alias_value":"LK7PSMNMGWUI","created_at":"2026-06-08T01:04:23.201191+00:00"},{"alias_kind":"pith_short_16","alias_value":"LK7PSMNMGWUIPD2O","created_at":"2026-06-08T01:04:23.201191+00:00"},{"alias_kind":"pith_short_8","alias_value":"LK7PSMNM","created_at":"2026-06-08T01:04:23.201191+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/LK7PSMNMGWUIPD2OUZOIRVPWXP","json":"https://pith.science/pith/LK7PSMNMGWUIPD2OUZOIRVPWXP.json","graph_json":"https://pith.science/api/pith-number/LK7PSMNMGWUIPD2OUZOIRVPWXP/graph.json","events_json":"https://pith.science/api/pith-number/LK7PSMNMGWUIPD2OUZOIRVPWXP/events.json","paper":"https://pith.science/paper/LK7PSMNM"},"agent_actions":{"view_html":"https://pith.science/pith/LK7PSMNMGWUIPD2OUZOIRVPWXP","download_json":"https://pith.science/pith/LK7PSMNMGWUIPD2OUZOIRVPWXP.json","view_paper":"https://pith.science/paper/LK7PSMNM","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2606.06697&json=true","fetch_graph":"https://pith.science/api/pith-number/LK7PSMNMGWUIPD2OUZOIRVPWXP/graph.json","fetch_events":"https://pith.science/api/pith-number/LK7PSMNMGWUIPD2OUZOIRVPWXP/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/LK7PSMNMGWUIPD2OUZOIRVPWXP/action/timestamp_anchor","attest_storage":"https://pith.science/pith/LK7PSMNMGWUIPD2OUZOIRVPWXP/action/storage_attestation","attest_author":"https://pith.science/pith/LK7PSMNMGWUIPD2OUZOIRVPWXP/action/author_attestation","sign_citation":"https://pith.science/pith/LK7PSMNMGWUIPD2OUZOIRVPWXP/action/citation_signature","submit_replication":"https://pith.science/pith/LK7PSMNMGWUIPD2OUZOIRVPWXP/action/replication_record"}},"created_at":"2026-06-08T01:04:23.201191+00:00","updated_at":"2026-06-08T01:04:23.201191+00:00"}