{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_252d9ce635678afaff89fffe39bbae2dd8dc1528571ee5874460cbfde0400bc8","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_252d9ce635678afaff89fffe39bbae2dd8dc1528571ee5874460cbfde0400bc8","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"9fb480942f61c6033ba196fbae171c677b2a67a1a6cc6eda39ca8940d1209f56","published":"Mon, 29 Jun 2026 00:00:00 -0400","receipt_hash":"9fb480942f61c6033ba196fbae171c677b2a67a1a6cc6eda39ca8940d1209f56","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"9fb480942f61c6033ba196fbae171c677b2a67a1a6cc6eda39ca8940d1209f56","observed_at":"2026-06-29T04:44:03.414425Z","parent_run_hash":"36b5ab5c57ae76dc9e1a863501c4d38f172868cfae31b4ba5baf3caffaafb2c4","published":"Mon, 29 Jun 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2606.27567v1 Announce Type: cross \nAbstract: Prompt injection is the top security risk for LLM-integrated applications, yet every defense proposed so far has been broken. We prove this is not a coincidence: in shared-embedding architectures that lack enforced control-data separation, perfect prompt-injection prevention is mathematically impossible. We formalize prompted systems as Prompted Action Models whose outputs include control-authoritative actions: refusal decisions, tool authorization, policy routing, and memory writes. We define Semantic-Faithful Control (SFC), the property that such behavior depends only on the meaning of untrusted input, not on how it is encoded. We then prove SFC is unachievable within the shared pipeline, via three results: a provenance-recovery impossibility (shared representations make trusted and untrusted content statistically inseparable, bounded by total variation distance); control-path exposure (untrusted tokens enter control-relevant computa","title":"On the Inseparability of Instructions and Data in Shared-Embedding Sequence Models","url":"https://arxiv.org/abs/2606.27567","vendor":"arxiv_cs_ai"},"summary":"arXiv:2606.27567v1 Announce Type: cross \nAbstract: Prompt injection is the top security risk for LLM-integrated applications, yet every defense proposed so far has been broken. We prove this is not a coincidence: in shared-embedding architectures that lack enforced control-data separation, perfect prompt-injection prevention is mathematically impossible. We formalize prompted systems as Prompted Action Models whose outputs include control-authoritative actions: refusal decisions, tool authorization, policy routing, and memory writes. We define Semantic-Faithful Control (SFC), the property that such behavior depends only on the meaning of untrusted input, not on how it is encoded. We then prove SFC is unachievable within the shared pipeline, via three results: a provenance-recovery impossibility (shared representations make trusted and untrusted content statistically inseparable, bounded by total variation distance); control-path exposure (untrusted tokens enter control-relevant computa","title":"On the Inseparability of Instructions and Data in Shared-Embedding Sequence Models","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-06-29T04:44:03Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2606.27567"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:7abd9d5acf6dd2b024ee4137288c64f39c91c84cf606815a2cec9e7f5b0ed58b2d843f2049f769d01ed8408710b5c82009ac654580bdb9739fc213559a624004","signer":"crovia.substrate","subject":{"observed_at":"2026-06-29T04:44:03Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2606.27567"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"e67f31abb0944c604229da047be810e977ecb3478f7700801c83b0e510d57e05","leaf_index":261352,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"f0b5111c0bd4cf8c6f3e2b2f920ab7a7f235a8cce4e04009b475e2d77f707a98","side":"right"},{"sibling":"7d5532b1e8a8f5a4cbf5deeedc6dcfc4137ac93b2753faf4dff14cacc21df4bc","side":"right"},{"sibling":"1ae756be91a94413a40977642a601cdac67ccb597736727e6e07dd6aa8380ba8","side":"right"},{"sibling":"ac00e1a297988051e734d891f4d3443a685260fb365e1015d1f8125fd53d5a97","side":"left"},{"sibling":"3b890658a211bc7da8c2061c72164f34f08d2975e9db0b28f76410421ff60746","side":"right"},{"sibling":"2d0cbac5b016a15418aa5facb5982a3acd7646a21cfca78d3533483eed73cde6","side":"left"},{"sibling":"ab8f67f857fa81c6ddd6431b5feff1b6dea6f58d2d6384543bad28001936ae23","side":"left"},{"sibling":"daf5279d003dd81baccfe21e3bfac0a3b468c08210a2f76237353b11695cdd73","side":"left"},{"sibling":"3698d5368a778dfd474a1084879c71ccc04d1602253019e48bab7329c680972f","side":"right"},{"sibling":"9f9daa9d12e65b219f34c92aec45450536b79a42b8892050d66961432ae28ed1","side":"right"},{"sibling":"b5725d7b0807dc6da32d9788f20057fa8726be38d30a9ebdabc605ae92739122","side":"left"},{"sibling":"e321b2cac14cbe28f76ccb7938249a40ff60cd5d2128b5634be046ea10e984b8","side":"left"},{"sibling":"5900dc6c7d13855af9d0385baf1691ec386df33e450c422af1cabe0a36e40ad8","side":"left"},{"sibling":"ae636ddee98c71ab7a7dc55ddfab70c7f710a2b6abfdf7a8b5d16a4017d1c0d1","side":"left"},{"sibling":"f29798d8bb6aa9900eab878992d9ff0c53266debd87472f31ab26a6a3fb55880","side":"left"},{"sibling":"a04392fb9f2a3a620840e3b3fecd93d12e6d224e481c162389d8ae64e7194599","side":"left"},{"sibling":"c300cf0154c136afc09b1702a0be98f4ba5b6dc5cf57e8cc714ec1eaf4196eff","side":"left"},{"sibling":"d841ad93efda0869e5eb97678f348f03f5caab4353e05ff4bf18f47fb945b822","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":261662,"merkle_root":"aa8865c239aa2eb6c8aa7c6250f56b3cd5709854a8a07f6a29eb4ddd8802cb6f","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260629T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-06-29T05:38:02Z","sig_algorithm":"ed25519","signature":"476329233e82fb35fba2552ddc5d1d75b2bdd8513bbd281e9c40a0b8e475df374a62dcd8b456b0c5e8815984f5b4bf0983ae95d2cf4d7412ebb13a433b933c0a","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_252d9ce635678afaff89fffe39bbae2dd8dc1528571ee5874460cbfde0400bc8"}}