{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:LNYPFHUPR7JOSFNTMEWV65EVAK","short_pith_number":"pith:LNYPFHUP","canonical_record":{"source":{"id":"2606.23277","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-06-22T12:54:04Z","cross_cats_sorted":[],"title_canon_sha256":"4e2b7ce9fe9fd4727eb0c997068b698c2888c76eb18c792e1d9382e87c4fe226","abstract_canon_sha256":"9ea01e9e6e773d4b2f8d01c264b5b4b32e819e7a6ab225911a4b20f56039f404"},"schema_version":"1.0"},"canonical_sha256":"5b70f29e8f8fd2e915b3612d5f749502834a9fa9b6c9e6256bb345a78499f868","source":{"kind":"arxiv","id":"2606.23277","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.23277","created_at":"2026-06-23T03:14:15Z"},{"alias_kind":"arxiv_version","alias_value":"2606.23277v1","created_at":"2026-06-23T03:14:15Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.23277","created_at":"2026-06-23T03:14:15Z"},{"alias_kind":"pith_short_12","alias_value":"LNYPFHUPR7JO","created_at":"2026-06-23T03:14:15Z"},{"alias_kind":"pith_short_16","alias_value":"LNYPFHUPR7JOSFNT","created_at":"2026-06-23T03:14:15Z"},{"alias_kind":"pith_short_8","alias_value":"LNYPFHUP","created_at":"2026-06-23T03:14:15Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:LNYPFHUPR7JOSFNTMEWV65EVAK","target":"record","payload":{"canonical_record":{"source":{"id":"2606.23277","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-06-22T12:54:04Z","cross_cats_sorted":[],"title_canon_sha256":"4e2b7ce9fe9fd4727eb0c997068b698c2888c76eb18c792e1d9382e87c4fe226","abstract_canon_sha256":"9ea01e9e6e773d4b2f8d01c264b5b4b32e819e7a6ab225911a4b20f56039f404"},"schema_version":"1.0"},"canonical_sha256":"5b70f29e8f8fd2e915b3612d5f749502834a9fa9b6c9e6256bb345a78499f868","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-23T03:14:15.549345Z","signature_b64":"uTzVVxQHUuphutdHSxVKJnrEiVgZHcFxZR0J7LzFTXwlq7o4erPIz56WZ+7vqd7K+kmgLoOGQ/+L7DFSRB6TCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"5b70f29e8f8fd2e915b3612d5f749502834a9fa9b6c9e6256bb345a78499f868","last_reissued_at":"2026-06-23T03:14:15.548965Z","signature_status":"signed_v1","first_computed_at":"2026-06-23T03:14:15.548965Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.23277","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-23T03:14:15Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"XLWtrmzS+hhRav66OepQv0kApo+r4aTsD/aJM707NtKKm7lFQViT64+8XaU4uYcUol4yu6Ro9DF/IwULYQt9Bg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T20:15:09.896858Z"},"content_sha256":"7f30e56052b28c5d124a6528c48426e1a9359d5dd21ff52854cce819658d5153","schema_version":"1.0","event_id":"sha256:7f30e56052b28c5d124a6528c48426e1a9359d5dd21ff52854cce819658d5153"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:LNYPFHUPR7JOSFNTMEWV65EVAK","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"GIF: Locally Sound Geometric Information Flow Control for LLMs","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.AI","authors_text":"Adam Storek, Nikolaus Holzer, Suman Jana, Zhuo Zhang","submitted_at":"2026-06-22T12:54:04Z","abstract_excerpt":"Large language models increasingly mediate interactions between sensitive data, untrusted inputs, and privileged actions in agentic systems, creating security and privacy risks. These range from prompt injections that manipulate downstream tool use to leakage of confidential information through model outputs. Recent Information Flow Control (IFC)-based defenses show promise but lack a principled semantic foundation for reasoning about information flow through the model itself. Since any input token may influence any output token in an autoregressive LLM, existing approaches suffer from severe "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.23277","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.23277/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-23T03:14:15Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"M3by9UA7CF7qKBkO9kion9hki7K3pnR3tcJHfe+T12zf4QxaG23sdi7LLkvJsCw+ndzlWbo5L9gyBvfW+Y1vCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-27T20:15:09.897232Z"},"content_sha256":"ab338f3670602ae40071405a64c5227c6e2ed706591eacb9974b8e1c80561c40","schema_version":"1.0","event_id":"sha256:ab338f3670602ae40071405a64c5227c6e2ed706591eacb9974b8e1c80561c40"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/LNYPFHUPR7JOSFNTMEWV65EVAK/bundle.json","state_url":"https://pith.science/pith/LNYPFHUPR7JOSFNTMEWV65EVAK/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/LNYPFHUPR7JOSFNTMEWV65EVAK/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-27T20:15:09Z","links":{"resolver":"https://pith.science/pith/LNYPFHUPR7JOSFNTMEWV65EVAK","bundle":"https://pith.science/pith/LNYPFHUPR7JOSFNTMEWV65EVAK/bundle.json","state":"https://pith.science/pith/LNYPFHUPR7JOSFNTMEWV65EVAK/state.json","well_known_bundle":"https://pith.science/.well-known/pith/LNYPFHUPR7JOSFNTMEWV65EVAK/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:LNYPFHUPR7JOSFNTMEWV65EVAK","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"9ea01e9e6e773d4b2f8d01c264b5b4b32e819e7a6ab225911a4b20f56039f404","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-06-22T12:54:04Z","title_canon_sha256":"4e2b7ce9fe9fd4727eb0c997068b698c2888c76eb18c792e1d9382e87c4fe226"},"schema_version":"1.0","source":{"id":"2606.23277","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.23277","created_at":"2026-06-23T03:14:15Z"},{"alias_kind":"arxiv_version","alias_value":"2606.23277v1","created_at":"2026-06-23T03:14:15Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.23277","created_at":"2026-06-23T03:14:15Z"},{"alias_kind":"pith_short_12","alias_value":"LNYPFHUPR7JO","created_at":"2026-06-23T03:14:15Z"},{"alias_kind":"pith_short_16","alias_value":"LNYPFHUPR7JOSFNT","created_at":"2026-06-23T03:14:15Z"},{"alias_kind":"pith_short_8","alias_value":"LNYPFHUP","created_at":"2026-06-23T03:14:15Z"}],"graph_snapshots":[{"event_id":"sha256:ab338f3670602ae40071405a64c5227c6e2ed706591eacb9974b8e1c80561c40","target":"graph","created_at":"2026-06-23T03:14:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.23277/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Large language models increasingly mediate interactions between sensitive data, untrusted inputs, and privileged actions in agentic systems, creating security and privacy risks. These range from prompt injections that manipulate downstream tool use to leakage of confidential information through model outputs. Recent Information Flow Control (IFC)-based defenses show promise but lack a principled semantic foundation for reasoning about information flow through the model itself. Since any input token may influence any output token in an autoregressive LLM, existing approaches suffer from severe ","authors_text":"Adam Storek, Nikolaus Holzer, Suman Jana, Zhuo Zhang","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-06-22T12:54:04Z","title":"GIF: Locally Sound Geometric Information Flow Control for LLMs"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.23277","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:7f30e56052b28c5d124a6528c48426e1a9359d5dd21ff52854cce819658d5153","target":"record","created_at":"2026-06-23T03:14:15Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"9ea01e9e6e773d4b2f8d01c264b5b4b32e819e7a6ab225911a4b20f56039f404","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.AI","submitted_at":"2026-06-22T12:54:04Z","title_canon_sha256":"4e2b7ce9fe9fd4727eb0c997068b698c2888c76eb18c792e1d9382e87c4fe226"},"schema_version":"1.0","source":{"id":"2606.23277","kind":"arxiv","version":1}},"canonical_sha256":"5b70f29e8f8fd2e915b3612d5f749502834a9fa9b6c9e6256bb345a78499f868","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"5b70f29e8f8fd2e915b3612d5f749502834a9fa9b6c9e6256bb345a78499f868","first_computed_at":"2026-06-23T03:14:15.548965Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-23T03:14:15.548965Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"uTzVVxQHUuphutdHSxVKJnrEiVgZHcFxZR0J7LzFTXwlq7o4erPIz56WZ+7vqd7K+kmgLoOGQ/+L7DFSRB6TCw==","signature_status":"signed_v1","signed_at":"2026-06-23T03:14:15.549345Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.23277","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:7f30e56052b28c5d124a6528c48426e1a9359d5dd21ff52854cce819658d5153","sha256:ab338f3670602ae40071405a64c5227c6e2ed706591eacb9974b8e1c80561c40"],"state_sha256":"bb0a7b2333410b042930b75fb982fb5b7c0bedce93b1297b8c83d514c6d47c4d"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"yaRfsII8XQp/WpL/YlSLILQzhavA1QqRMEU8RwN/2mVxHqHQSx0Nzn2K+DXVzBLcObt2RfyEQbAGTPF2PmzEDA==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-27T20:15:09.899230Z","bundle_sha256":"9356e1125161f7277b0202ba28c09c31e3d3023095bf67f7802c0041ad54dbb4"}}