{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_2f5b6584de796f7369a910d91d23f9ad8a7084b1a4c2b582516fe61bc7a90744","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_2f5b6584de796f7369a910d91d23f9ad8a7084b1a4c2b582516fe61bc7a90744","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"54e5d386b8eacbbf843036eaf710a03da47c63a38ae2d496d3bfd64ad7db9fc5","published":"Thu, 23 Jul 2026 00:00:00 -0400","receipt_hash":"54e5d386b8eacbbf843036eaf710a03da47c63a38ae2d496d3bfd64ad7db9fc5","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"54e5d386b8eacbbf843036eaf710a03da47c63a38ae2d496d3bfd64ad7db9fc5","observed_at":"2026-07-23T04:43:18.446221Z","parent_run_hash":"b3f5e4095688e31d15c25de2607bca42111343bdfdac967d48e47905415ddea0","published":"Thu, 23 Jul 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2607.19430v1 Announce Type: cross \nAbstract: Multi-agent LLM applications chain a planner, worker agents, a verifier, and a synthesizer, and every hop between agents is an unmonitored channel through which an adversary can smuggle instructions. Existing defenses guard only the input boundary (IBProtector, Llama Guard, perplexity filters, SmoothLLM) or run outside the application as opaque, stochastic provider-side filters. We show this gap carries a consequence rarely measured: on a 2,100-trace evaluation across eight attack families, five defenses, and three model backends, an undefended pipeline that appears fully safe under standard reporting (attack success 0.000 on tool- and memory-poisoning) owes that safety almost entirely to the cloud provider's server-side filter (54 of 60 blocks on Azure GPT-5), and silently shifts to the agent model's own alignment on a backend without such a filter. Outcome-only reporting hides this dependence. We present ChannelGuard, a training-free","title":"ChannelGuard: Safe Models Do Not Compose into Safe Multi-Agent Systems","url":"https://arxiv.org/abs/2607.19430","vendor":"arxiv_cs_ai"},"summary":"arXiv:2607.19430v1 Announce Type: cross \nAbstract: Multi-agent LLM applications chain a planner, worker agents, a verifier, and a synthesizer, and every hop between agents is an unmonitored channel through which an adversary can smuggle instructions. Existing defenses guard only the input boundary (IBProtector, Llama Guard, perplexity filters, SmoothLLM) or run outside the application as opaque, stochastic provider-side filters. We show this gap carries a consequence rarely measured: on a 2,100-trace evaluation across eight attack families, five defenses, and three model backends, an undefended pipeline that appears fully safe under standard reporting (attack success 0.000 on tool- and memory-poisoning) owes that safety almost entirely to the cloud provider's server-side filter (54 of 60 blocks on Azure GPT-5), and silently shifts to the agent model's own alignment on a backend without such a filter. Outcome-only reporting hides this dependence. We present ChannelGuard, a training-free","title":"ChannelGuard: Safe Models Do Not Compose into Safe Multi-Agent Systems","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-07-23T04:43:18Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2607.19430"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:08ad8df553c66c3302a3ec2b2b948bfd4bd34d6b6331ab079c5cb23d378da1f0e22b6f76363e17e8988fc3ffab9069054e12199d04d079f583f356fe2a7ae60f","signer":"crovia.substrate","subject":{"observed_at":"2026-07-23T04:43:18Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2607.19430"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"f4968902f120396a4625d7fc288c33f0bd78d82ec410a22320e23899319751a7","leaf_index":343657,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"2b789ab2c66a8c709c69b815e3f9d8c0b416ac8734d6bbbfe691e8abd7f51f8a","side":"left"},{"sibling":"0de859e88ffbd1d2a771600b1949d49d76bf2a05144ec9e6ac632e9f077072ce","side":"right"},{"sibling":"ee585f94ac092ec620e39a4e490088e5d43ea22291ebc730365a8b0a66188ebd","side":"right"},{"sibling":"4d0e215eb6aad19b815bc61cc02c1aaa42fcaed316c3499960874021c7cef72a","side":"left"},{"sibling":"489d17fe34dbbb58606a7eaf0e687c790a8af7612f52e00aacc8f373025614a6","side":"right"},{"sibling":"099254e33d9098db07bde3a9a97ce251a7497619e6b26704d223c16f1370afea","side":"left"},{"sibling":"f1bdad0b747ea102cc58af1ef43ba9823c47e1e8da7945feed779a074a032485","side":"left"},{"sibling":"51ebf5c79aac8726e953f8d1f4d9fb442a2733a55a74c3ce7be5e84fcff3f592","side":"right"},{"sibling":"6ecdcc1e2fb6ab44777fffbb7c8297d723018c63aac9d90c7a1bbebe728d84cf","side":"right"},{"sibling":"93d7d8e0e882d05b2a15bb707a824979a0427907eb47e687c712906674a0d345","side":"left"},{"sibling":"92219a3ef58cd145d94f071b0b9396cec3707812b02a8c7c63f2d0e22340552b","side":"left"},{"sibling":"4eb402d67bd4bf583b0434363061166fe259c34cc6c42adb32dcfbff0a9f5767","side":"left"},{"sibling":"2dd9cb2521044ee7c6b74f2315e0a0253b8df0d04a7b810bbbbe7da5a9788769","side":"left"},{"sibling":"21d66dd41003813f710b7617944f1bfba3258658a5d3370c21cad8f9e945bc99","side":"left"},{"sibling":"941f71d7ce3990a507b8f485de3f872a51d0e9a8c59405d76c2ae6f4a6af494a","side":"right"},{"sibling":"6281b6f7a93c44e3c4895bc65cfcb6f2be24dd725f4f46540ec022a6e215f4e8","side":"right"},{"sibling":"77025bcb374a7ad74f520643e20a8ae1205a7ee78507b0beb93117760f1c29d3","side":"left"},{"sibling":"6baede22892163664bb2e4d92cf75e6b290761533a6c39491c3afd89bb3a0252","side":"right"},{"sibling":"1cecb7f447febd025aac272837c80de218aecc6485d2395a509b2a1f1b9c746e","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":343944,"merkle_root":"afab58f71597d393a7a61b857dac2eacb72fd1c04cd1432c2622d7b19309dffd","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260723T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-07-23T05:38:39Z","sig_algorithm":"ed25519","signature":"1a58fdc6367d0c86f83d2385be748e0800a64bcf9987c92fadca53deda009cd390d2070302c2b6e44841febfd864637c323ba12c7a1e9ae58fdf2a0cf546ac01","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_2f5b6584de796f7369a910d91d23f9ad8a7084b1a4c2b582516fe61bc7a90744"}}