{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:WP3HSQ3VIHGEIL7ZIX3M5S4TJP","short_pith_number":"pith:WP3HSQ3V","canonical_record":{"source":{"id":"2606.18710","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T05:51:14Z","cross_cats_sorted":[],"title_canon_sha256":"6cb4ba61d37b536f0a7e5a7c605c905f947970ca5b0ef4a8d1deccf3970f7346","abstract_canon_sha256":"8cdb0f67e5381248679693de8a82007f37e153ef86ad66abad61884443f92d73"},"schema_version":"1.0"},"canonical_sha256":"b3f679437541cc442ff945f6cecb934beb54b8f8567f848ce7ae3f289fdf4faf","source":{"kind":"arxiv","id":"2606.18710","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.18710","created_at":"2026-06-19T16:11:45Z"},{"alias_kind":"arxiv_version","alias_value":"2606.18710v1","created_at":"2026-06-19T16:11:45Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.18710","created_at":"2026-06-19T16:11:45Z"},{"alias_kind":"pith_short_12","alias_value":"WP3HSQ3VIHGE","created_at":"2026-06-19T16:11:45Z"},{"alias_kind":"pith_short_16","alias_value":"WP3HSQ3VIHGEIL7Z","created_at":"2026-06-19T16:11:45Z"},{"alias_kind":"pith_short_8","alias_value":"WP3HSQ3V","created_at":"2026-06-19T16:11:45Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:WP3HSQ3VIHGEIL7ZIX3M5S4TJP","target":"record","payload":{"canonical_record":{"source":{"id":"2606.18710","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T05:51:14Z","cross_cats_sorted":[],"title_canon_sha256":"6cb4ba61d37b536f0a7e5a7c605c905f947970ca5b0ef4a8d1deccf3970f7346","abstract_canon_sha256":"8cdb0f67e5381248679693de8a82007f37e153ef86ad66abad61884443f92d73"},"schema_version":"1.0"},"canonical_sha256":"b3f679437541cc442ff945f6cecb934beb54b8f8567f848ce7ae3f289fdf4faf","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-19T16:11:45.317970Z","signature_b64":"112d+6btV43DgNb2fe2drWH0Nzs31ow8VRtI16H+CwP3CtHlGf0fRCUsg0H4SvED2GprLUqhX1yXRU/2Jj9aBg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b3f679437541cc442ff945f6cecb934beb54b8f8567f848ce7ae3f289fdf4faf","last_reissued_at":"2026-06-19T16:11:45.317527Z","signature_status":"signed_v1","first_computed_at":"2026-06-19T16:11:45.317527Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2606.18710","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:11:45Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iMm1keIekAQcwr/czO5MuYpHpfM03SI89K7MoN3jTD2OG7azYKkT1f8dKsDs/KjwCrMYE3n1RsWEKVBRxYbSAw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-20T05:12:31.786523Z"},"content_sha256":"f05ba58c3cd4b390716f6ee9faf5d26b5d4fa6292ee5de759959cd58fb142f00","schema_version":"1.0","event_id":"sha256:f05ba58c3cd4b390716f6ee9faf5d26b5d4fa6292ee5de759959cd58fb142f00"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:WP3HSQ3VIHGEIL7ZIX3M5S4TJP","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Image Prompt Reconstruction Attacks on Distributed MLLM Inference Frameworks","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Hongyan Chang, Jianxin Wei, Meikang Qiu, Ting Yu, Xiaofeng Gao, Xinjian Luo, Xue Liu, Yuncheng Wu","submitted_at":"2026-06-17T05:51:14Z","abstract_excerpt":"Distributed large language model (LLM) inference frameworks connect isolated consumer-grade devices for large-scale model inference, substantially reducing hardware constraints. However, recent studies show that intermediate embeddings transmitted among participants can leak private prompts. As LLMs evolve into multimodal LLMs (MLLMs), this risk extends beyond text: image prompts contain rich visual and semantic information, making their intermediate embeddings highly privacy-sensitive. Yet, image-prompt leakage in distributed MLLM inference remains largely unexplored.\n  In this paper, we inve"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.18710","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.18710/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-06-19T16:11:45Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"s5y+YZ8m32x/SBgFgr9NdziGi3AbHbQ9UQmpOjBX4YKVIfo5k3y850xYXbnndI4cg+6UKmbfHbv2vxiiMawHAg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-20T05:12:31.786896Z"},"content_sha256":"95c764577f4f60d435db4e639c86b3a3c5db9d93c0324eb2099aa6e4b14a59a8","schema_version":"1.0","event_id":"sha256:95c764577f4f60d435db4e639c86b3a3c5db9d93c0324eb2099aa6e4b14a59a8"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/WP3HSQ3VIHGEIL7ZIX3M5S4TJP/bundle.json","state_url":"https://pith.science/pith/WP3HSQ3VIHGEIL7ZIX3M5S4TJP/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/WP3HSQ3VIHGEIL7ZIX3M5S4TJP/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-20T05:12:31Z","links":{"resolver":"https://pith.science/pith/WP3HSQ3VIHGEIL7ZIX3M5S4TJP","bundle":"https://pith.science/pith/WP3HSQ3VIHGEIL7ZIX3M5S4TJP/bundle.json","state":"https://pith.science/pith/WP3HSQ3VIHGEIL7ZIX3M5S4TJP/state.json","well_known_bundle":"https://pith.science/.well-known/pith/WP3HSQ3VIHGEIL7ZIX3M5S4TJP/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:WP3HSQ3VIHGEIL7ZIX3M5S4TJP","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"8cdb0f67e5381248679693de8a82007f37e153ef86ad66abad61884443f92d73","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T05:51:14Z","title_canon_sha256":"6cb4ba61d37b536f0a7e5a7c605c905f947970ca5b0ef4a8d1deccf3970f7346"},"schema_version":"1.0","source":{"id":"2606.18710","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2606.18710","created_at":"2026-06-19T16:11:45Z"},{"alias_kind":"arxiv_version","alias_value":"2606.18710v1","created_at":"2026-06-19T16:11:45Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.18710","created_at":"2026-06-19T16:11:45Z"},{"alias_kind":"pith_short_12","alias_value":"WP3HSQ3VIHGE","created_at":"2026-06-19T16:11:45Z"},{"alias_kind":"pith_short_16","alias_value":"WP3HSQ3VIHGEIL7Z","created_at":"2026-06-19T16:11:45Z"},{"alias_kind":"pith_short_8","alias_value":"WP3HSQ3V","created_at":"2026-06-19T16:11:45Z"}],"graph_snapshots":[{"event_id":"sha256:95c764577f4f60d435db4e639c86b3a3c5db9d93c0324eb2099aa6e4b14a59a8","target":"graph","created_at":"2026-06-19T16:11:45Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2606.18710/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Distributed large language model (LLM) inference frameworks connect isolated consumer-grade devices for large-scale model inference, substantially reducing hardware constraints. However, recent studies show that intermediate embeddings transmitted among participants can leak private prompts. As LLMs evolve into multimodal LLMs (MLLMs), this risk extends beyond text: image prompts contain rich visual and semantic information, making their intermediate embeddings highly privacy-sensitive. Yet, image-prompt leakage in distributed MLLM inference remains largely unexplored.\n  In this paper, we inve","authors_text":"Hongyan Chang, Jianxin Wei, Meikang Qiu, Ting Yu, Xiaofeng Gao, Xinjian Luo, Xue Liu, Yuncheng Wu","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T05:51:14Z","title":"Image Prompt Reconstruction Attacks on Distributed MLLM Inference Frameworks"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.18710","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:f05ba58c3cd4b390716f6ee9faf5d26b5d4fa6292ee5de759959cd58fb142f00","target":"record","created_at":"2026-06-19T16:11:45Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"8cdb0f67e5381248679693de8a82007f37e153ef86ad66abad61884443f92d73","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-06-17T05:51:14Z","title_canon_sha256":"6cb4ba61d37b536f0a7e5a7c605c905f947970ca5b0ef4a8d1deccf3970f7346"},"schema_version":"1.0","source":{"id":"2606.18710","kind":"arxiv","version":1}},"canonical_sha256":"b3f679437541cc442ff945f6cecb934beb54b8f8567f848ce7ae3f289fdf4faf","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b3f679437541cc442ff945f6cecb934beb54b8f8567f848ce7ae3f289fdf4faf","first_computed_at":"2026-06-19T16:11:45.317527Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-06-19T16:11:45.317527Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"112d+6btV43DgNb2fe2drWH0Nzs31ow8VRtI16H+CwP3CtHlGf0fRCUsg0H4SvED2GprLUqhX1yXRU/2Jj9aBg==","signature_status":"signed_v1","signed_at":"2026-06-19T16:11:45.317970Z","signed_message":"canonical_sha256_bytes"},"source_id":"2606.18710","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:f05ba58c3cd4b390716f6ee9faf5d26b5d4fa6292ee5de759959cd58fb142f00","sha256:95c764577f4f60d435db4e639c86b3a3c5db9d93c0324eb2099aa6e4b14a59a8"],"state_sha256":"8e8ec8cba69da18aea6ce36f66a99a22f48dc682623b970b2c9dc0af8f513be8"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"MIdmBztI1J3tuiOhg+dpc+HUsxioXNoDKIuXPm0lPvms7+ahhTB4ZxsLwRNWI2BRLkqMiiFycN9CC+qwbrTgAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-20T05:12:31.788916Z","bundle_sha256":"7b69e7bf5c7d3914a5d0b86a4637aa2a3a9bc1c6b519812dbe1eeff081d42a88"}}