{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:XBB2X5IMD77VFZQABVZ43HBOAE","short_pith_number":"pith:XBB2X5IM","canonical_record":{"source":{"id":"2605.29979","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-28T14:16:53Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"52f4aa0350fe0ae2b8d906540e18350163549c2e06dd82e8dc9675c8f2b2cedc","abstract_canon_sha256":"515fb2e9f1f4418ed1ef9e4c7fd12c1776943e1210d218dff96d52cf6f7a6968"},"schema_version":"1.0"},"canonical_sha256":"b843abf50c1fff52e6000d73cd9c2e01164932f0a6a0020b0b9f5fa506ce6885","source":{"kind":"arxiv","id":"2605.29979","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.29979","created_at":"2026-05-29T02:06:04Z"},{"alias_kind":"arxiv_version","alias_value":"2605.29979v1","created_at":"2026-05-29T02:06:04Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.29979","created_at":"2026-05-29T02:06:04Z"},{"alias_kind":"pith_short_12","alias_value":"XBB2X5IMD77V","created_at":"2026-05-29T02:06:04Z"},{"alias_kind":"pith_short_16","alias_value":"XBB2X5IMD77VFZQA","created_at":"2026-05-29T02:06:04Z"},{"alias_kind":"pith_short_8","alias_value":"XBB2X5IM","created_at":"2026-05-29T02:06:04Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:XBB2X5IMD77VFZQABVZ43HBOAE","target":"record","payload":{"canonical_record":{"source":{"id":"2605.29979","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-28T14:16:53Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"52f4aa0350fe0ae2b8d906540e18350163549c2e06dd82e8dc9675c8f2b2cedc","abstract_canon_sha256":"515fb2e9f1f4418ed1ef9e4c7fd12c1776943e1210d218dff96d52cf6f7a6968"},"schema_version":"1.0"},"canonical_sha256":"b843abf50c1fff52e6000d73cd9c2e01164932f0a6a0020b0b9f5fa506ce6885","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-29T02:06:04.956826Z","signature_b64":"eUDB7eNdOaVd+oHPc1JAwjhB8vAm5pYw7fibo2KPdtIyaemC5ati1LeljXwqwF1hxDCUFsT6fI5SfLn3ooz9Dg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"b843abf50c1fff52e6000d73cd9c2e01164932f0a6a0020b0b9f5fa506ce6885","last_reissued_at":"2026-05-29T02:06:04.956233Z","signature_status":"signed_v1","first_computed_at":"2026-05-29T02:06:04.956233Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.29979","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T02:06:04Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"DmUItETNyDKvTFXMnkmZRvzFjWf3bIjIVF4CD/nDHl064os/cPcvp3VxzFquUhU89uxGl4o+xofu3U3aiJcXCA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T05:37:39.205336Z"},"content_sha256":"483d98df342b2bb478d55b44f2d077c099e7f868e305e04105715955cda0dca6","schema_version":"1.0","event_id":"sha256:483d98df342b2bb478d55b44f2d077c099e7f868e305e04105715955cda0dca6"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:XBB2X5IMD77VFZQABVZ43HBOAE","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Fingerprinting Inference Systems of Large Language Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Anna Wimbauer, Erik Imgrund, Jonas M\\\"oller, Konrad Rieck","submitted_at":"2026-05-28T14:16:53Z","abstract_excerpt":"The behavior of LLMs does not depend solely on the model itself. Components of the inference system, such as the inference engine, attention backend, and hardware platform, subtly influence how inputs are processed. These components differ in their implementations and thereby induce small numerical deviations across systems when running the same model. While prior work has established the theoretical existence of such deviations, their security implications have remained unexplored. In this paper, we show that these deviations are characteristic of specific components and propagate to observab"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.29979","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.29979/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-29T02:06:04Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"X51xYcT5evsjpMxWv1ZscOkYdiqajCt4EL7Gw9F1qzVXwofX93/+w0pdna+GUMDpBMRI1o5cgYpJV5mEq5WjAQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-30T05:37:39.205725Z"},"content_sha256":"5da4fd1d3bd4f36f557d46a937e514f3c1d3902f25a0777ec58cde8a6bf8d04f","schema_version":"1.0","event_id":"sha256:5da4fd1d3bd4f36f557d46a937e514f3c1d3902f25a0777ec58cde8a6bf8d04f"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/XBB2X5IMD77VFZQABVZ43HBOAE/bundle.json","state_url":"https://pith.science/pith/XBB2X5IMD77VFZQABVZ43HBOAE/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/XBB2X5IMD77VFZQABVZ43HBOAE/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-30T05:37:39Z","links":{"resolver":"https://pith.science/pith/XBB2X5IMD77VFZQABVZ43HBOAE","bundle":"https://pith.science/pith/XBB2X5IMD77VFZQABVZ43HBOAE/bundle.json","state":"https://pith.science/pith/XBB2X5IMD77VFZQABVZ43HBOAE/state.json","well_known_bundle":"https://pith.science/.well-known/pith/XBB2X5IMD77VFZQABVZ43HBOAE/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:XBB2X5IMD77VFZQABVZ43HBOAE","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"515fb2e9f1f4418ed1ef9e4c7fd12c1776943e1210d218dff96d52cf6f7a6968","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-28T14:16:53Z","title_canon_sha256":"52f4aa0350fe0ae2b8d906540e18350163549c2e06dd82e8dc9675c8f2b2cedc"},"schema_version":"1.0","source":{"id":"2605.29979","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.29979","created_at":"2026-05-29T02:06:04Z"},{"alias_kind":"arxiv_version","alias_value":"2605.29979v1","created_at":"2026-05-29T02:06:04Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.29979","created_at":"2026-05-29T02:06:04Z"},{"alias_kind":"pith_short_12","alias_value":"XBB2X5IMD77V","created_at":"2026-05-29T02:06:04Z"},{"alias_kind":"pith_short_16","alias_value":"XBB2X5IMD77VFZQA","created_at":"2026-05-29T02:06:04Z"},{"alias_kind":"pith_short_8","alias_value":"XBB2X5IM","created_at":"2026-05-29T02:06:04Z"}],"graph_snapshots":[{"event_id":"sha256:5da4fd1d3bd4f36f557d46a937e514f3c1d3902f25a0777ec58cde8a6bf8d04f","target":"graph","created_at":"2026-05-29T02:06:04Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2605.29979/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"The behavior of LLMs does not depend solely on the model itself. Components of the inference system, such as the inference engine, attention backend, and hardware platform, subtly influence how inputs are processed. These components differ in their implementations and thereby induce small numerical deviations across systems when running the same model. While prior work has established the theoretical existence of such deviations, their security implications have remained unexplored. In this paper, we show that these deviations are characteristic of specific components and propagate to observab","authors_text":"Anna Wimbauer, Erik Imgrund, Jonas M\\\"oller, Konrad Rieck","cross_cats":["cs.LG"],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-28T14:16:53Z","title":"Fingerprinting Inference Systems of Large Language Models"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.29979","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:483d98df342b2bb478d55b44f2d077c099e7f868e305e04105715955cda0dca6","target":"record","created_at":"2026-05-29T02:06:04Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"515fb2e9f1f4418ed1ef9e4c7fd12c1776943e1210d218dff96d52cf6f7a6968","cross_cats_sorted":["cs.LG"],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-28T14:16:53Z","title_canon_sha256":"52f4aa0350fe0ae2b8d906540e18350163549c2e06dd82e8dc9675c8f2b2cedc"},"schema_version":"1.0","source":{"id":"2605.29979","kind":"arxiv","version":1}},"canonical_sha256":"b843abf50c1fff52e6000d73cd9c2e01164932f0a6a0020b0b9f5fa506ce6885","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"b843abf50c1fff52e6000d73cd9c2e01164932f0a6a0020b0b9f5fa506ce6885","first_computed_at":"2026-05-29T02:06:04.956233Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-29T02:06:04.956233Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"eUDB7eNdOaVd+oHPc1JAwjhB8vAm5pYw7fibo2KPdtIyaemC5ati1LeljXwqwF1hxDCUFsT6fI5SfLn3ooz9Dg==","signature_status":"signed_v1","signed_at":"2026-05-29T02:06:04.956826Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.29979","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:483d98df342b2bb478d55b44f2d077c099e7f868e305e04105715955cda0dca6","sha256:5da4fd1d3bd4f36f557d46a937e514f3c1d3902f25a0777ec58cde8a6bf8d04f"],"state_sha256":"0bd48437efae229de1209a496fce68032ab77943833730422221043095c2e501"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Zfqc6i2o45FOpGY2ZVv9jKcj+v2PxblxGBPbyRC4NzMssxrs1CJP4l6ABWu4sNwgGOQhDoL4A9sLRIYltkDvAw==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-30T05:37:39.207983Z","bundle_sha256":"3aabe624c38a7da2f4968db50acbf49159e7a3e96ee9d939ef93ac52127c7db4"}}