{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:WO7D6S5W62NRVVL3ZXHIXAE7FC","short_pith_number":"pith:WO7D6S5W","canonical_record":{"source":{"id":"2602.08235","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-02-09T03:20:11Z","cross_cats_sorted":["cs.AI","cs.CR"],"title_canon_sha256":"efc6e670330bfd2a026d7604774e362df1fde66ba04655c9b5eff5aac6674e07","abstract_canon_sha256":"724a5a837ffcde83a7abb52fcd773043ee13431eaf59ba79a49a7550be57d77a"},"schema_version":"1.0"},"canonical_sha256":"b3be3f4bb6f69b1ad57bcdce8b809f28aa62d2fe179d89b12c00cafddc89e844","source":{"kind":"arxiv","id":"2602.08235","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2602.08235","created_at":"2026-06-09T01:05:14Z"},{"alias_kind":"arxiv_version","alias_value":"2602.08235v2","created_at":"2026-06-09T01:05:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2602.08235","created_at":"2026-06-09T01:05:14Z"},{"alias_kind":"pith_short_12","alias_value":"WO7D6S5W62NR","created_at":"2026-06-09T01:05:14Z"},{"alias_kind":"pith_short_16","alias_value":"WO7D6S5W62NRVVL3","created_at":"2026-06-09T01:05:14Z"},{"alias_kind":"pith_short_8","alias_value":"WO7D6S5W","created_at":"2026-06-09T01:05:14Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:WO7D6S5W62NRVVL3ZXHIXAE7FC","target":"record","payload":{"canonical_record":{"source":{"id":"2602.08235","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-02-09T03:20:11Z","cross_cats_sorted":["cs.AI","cs.CR"],"title_canon_sha256":"efc6e670330bfd2a026d7604774e362df1fde66ba04655c9b5eff5aac6674e07","abstract_canon_sha256":"724a5a837ffcde83a7abb52fcd773043ee13431eaf59ba79a49a7550be57d77a"},"schema_version":"1.0"},"canonical_sha256":"b3be3f4bb6f69b1ad57bcdce8b809f28aa62d2fe179d89b12c00cafddc89e844","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-09T01:05:14.051104Z","signature_b64":"YaGPHAwU/sOm1ww3yBDIaPVt5fhndDaISQoCgNgLgyfKgZtfsYuhCKm9amogkrbzB38y4SGAAdLMhTkxUZULDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b3be3f4bb6f69b1ad57bcdce8b809f28aa62d2fe179d89b12c00cafddc89e844","last_reissued_at":"2026-06-09T01:05:14.050591Z","signature_status":"signed_v1","first_computed_at":"2026-06-09T01:05:14.050591Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2602.08235","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T01:05:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"VQyZTD0p677h+CjH6Etko+v695wz6Iwp28sTQOyBuyeUZ983i8xJHxbtlrM+/kKiv3+Ktx44IrT1wKQxMyJJBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T10:53:32.162834Z"},"content_sha256":"f7428eeeb9ae490ff528b60421bcd3644a06e0304ffe822eb00bde51f03c40f7","schema_version":"1.0","event_id":"sha256:f7428eeeb9ae490ff528b60421bcd3644a06e0304ffe822eb00bde51f03c40f7"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:WO7D6S5W62NRVVL3ZXHIXAE7FC","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"When Benign Inputs Lead to Severe Harms: Eliciting Unsafe Unintended Behaviors of Computer-Use Agents","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI","cs.CR"],"primary_cat":"cs.CL","authors_text":"Dawn Song, Eric Fosler-Lussier, Huan Sun, Jaylen Jones, Pierre-Luc St-Charles, Yoshua Bengio, Yu Su, Yuting Ning, Zhehao Zhang","submitted_at":"2026-02-09T03:20:11Z","abstract_excerpt":"Although computer-use agents (CUAs) hold significant potential to automate increasingly complex OS workflows, they can demonstrate unsafe unintended behaviors that deviate from expected outcomes even under benign input contexts. However, exploration of this risk remains largely anecdotal, lacking concrete characterization and automated methods to proactively surface long-tail unintended behaviors under realistic CUA scenarios. To fill this gap, we introduce the first conceptual and methodological framework for unintended CUA behaviors, by defining their key characteristics, automatically elici"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2602.08235","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2602.08235/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-09T01:05:14Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"w5qlt20UnYQwxzBlhRzSCvC10tpvGEj0lkw2IEQW6JZJ1BuBa1il52nVcsv2Ym3fqQpOvblf+NA8hSkdz7o5Bw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-09T10:53:32.163841Z"},"content_sha256":"359096b6428a76feeee8fd75e1b4d3929c813ac2b3b290fa10c78c4583a70dae","schema_version":"1.0","event_id":"sha256:359096b6428a76feeee8fd75e1b4d3929c813ac2b3b290fa10c78c4583a70dae"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/WO7D6S5W62NRVVL3ZXHIXAE7FC/bundle.json","state_url":"https://pith.science/pith/WO7D6S5W62NRVVL3ZXHIXAE7FC/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/WO7D6S5W62NRVVL3ZXHIXAE7FC/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-09T10:53:32Z","links":{"resolver":"https://pith.science/pith/WO7D6S5W62NRVVL3ZXHIXAE7FC","bundle":"https://pith.science/pith/WO7D6S5W62NRVVL3ZXHIXAE7FC/bundle.json","state":"https://pith.science/pith/WO7D6S5W62NRVVL3ZXHIXAE7FC/state.json","well_known_bundle":"https://pith.science/.well-known/pith/WO7D6S5W62NRVVL3ZXHIXAE7FC/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:WO7D6S5W62NRVVL3ZXHIXAE7FC","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"724a5a837ffcde83a7abb52fcd773043ee13431eaf59ba79a49a7550be57d77a","cross_cats_sorted":["cs.AI","cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-02-09T03:20:11Z","title_canon_sha256":"efc6e670330bfd2a026d7604774e362df1fde66ba04655c9b5eff5aac6674e07"},"schema_version":"1.0","source":{"id":"2602.08235","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2602.08235","created_at":"2026-06-09T01:05:14Z"},{"alias_kind":"arxiv_version","alias_value":"2602.08235v2","created_at":"2026-06-09T01:05:14Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2602.08235","created_at":"2026-06-09T01:05:14Z"},{"alias_kind":"pith_short_12","alias_value":"WO7D6S5W62NR","created_at":"2026-06-09T01:05:14Z"},{"alias_kind":"pith_short_16","alias_value":"WO7D6S5W62NRVVL3","created_at":"2026-06-09T01:05:14Z"},{"alias_kind":"pith_short_8","alias_value":"WO7D6S5W","created_at":"2026-06-09T01:05:14Z"}],"graph_snapshots":[{"event_id":"sha256:359096b6428a76feeee8fd75e1b4d3929c813ac2b3b290fa10c78c4583a70dae","target":"graph","created_at":"2026-06-09T01:05:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2602.08235/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Although computer-use agents (CUAs) hold significant potential to automate increasingly complex OS workflows, they can demonstrate unsafe unintended behaviors that deviate from expected outcomes even under benign input contexts. However, exploration of this risk remains largely anecdotal, lacking concrete characterization and automated methods to proactively surface long-tail unintended behaviors under realistic CUA scenarios. To fill this gap, we introduce the first conceptual and methodological framework for unintended CUA behaviors, by defining their key characteristics, automatically elici","authors_text":"Dawn Song, Eric Fosler-Lussier, Huan Sun, Jaylen Jones, Pierre-Luc St-Charles, Yoshua Bengio, Yu Su, Yuting Ning, Zhehao Zhang","cross_cats":["cs.AI","cs.CR"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-02-09T03:20:11Z","title":"When Benign Inputs Lead to Severe Harms: Eliciting Unsafe Unintended Behaviors of Computer-Use Agents"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2602.08235","kind":"arxiv","version":2},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f7428eeeb9ae490ff528b60421bcd3644a06e0304ffe822eb00bde51f03c40f7","target":"record","created_at":"2026-06-09T01:05:14Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"724a5a837ffcde83a7abb52fcd773043ee13431eaf59ba79a49a7550be57d77a","cross_cats_sorted":["cs.AI","cs.CR"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CL","submitted_at":"2026-02-09T03:20:11Z","title_canon_sha256":"efc6e670330bfd2a026d7604774e362df1fde66ba04655c9b5eff5aac6674e07"},"schema_version":"1.0","source":{"id":"2602.08235","kind":"arxiv","version":2}},"canonical_sha256":"b3be3f4bb6f69b1ad57bcdce8b809f28aa62d2fe179d89b12c00cafddc89e844","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b3be3f4bb6f69b1ad57bcdce8b809f28aa62d2fe179d89b12c00cafddc89e844","first_computed_at":"2026-06-09T01:05:14.050591Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-09T01:05:14.050591Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"YaGPHAwU/sOm1ww3yBDIaPVt5fhndDaISQoCgNgLgyfKgZtfsYuhCKm9amogkrbzB38y4SGAAdLMhTkxUZULDg==","signature_status":"signed_v1","signed_at":"2026-06-09T01:05:14.051104Z","signed_message":"canonical_sha256_bytes"},"source_id":"2602.08235","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f7428eeeb9ae490ff528b60421bcd3644a06e0304ffe822eb00bde51f03c40f7","sha256:359096b6428a76feeee8fd75e1b4d3929c813ac2b3b290fa10c78c4583a70dae"],"state_sha256":"ecaf17203bbae773af6f6d79ff47d05e4ce6ec1842cd164aab285cb489af93b9"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"/v043dVscyFHUMkQQP2SHSdKehywUhs3H9iL3N3lUeI121Ce9uXtBHlJ8pHCJ8ZtMCWY9GKcu7tcFqFcckuoDQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-09T10:53:32.167845Z","bundle_sha256":"06487a504ea8778dd5d040534a79355e00a7cc01584f1e7031839ee0781fdc82"}}