{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_349a32574d68c01df25055baee00731d01ce0e4bd0d8d7d7c012cab8bcb5080b","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_349a32574d68c01df25055baee00731d01ce0e4bd0d8d7d7c012cab8bcb5080b","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"0d4d70fb3021fb34479b49cebfb649321737c4965db4ca88ac9f5341d181ac78","published":"Wed, 22 Jul 2026 00:00:00 -0400","receipt_hash":"0d4d70fb3021fb34479b49cebfb649321737c4965db4ca88ac9f5341d181ac78","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"0d4d70fb3021fb34479b49cebfb649321737c4965db4ca88ac9f5341d181ac78","observed_at":"2026-07-22T04:43:18.261256Z","parent_run_hash":"4765c85b8b4b27ff9a690c1ae11c3b009baa2c60297295f395ad422f5afed68c","published":"Wed, 22 Jul 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2607.18567v1 Announce Type: new \nAbstract: A graph foundation model generalizes across graph domains by mapping every input into one shared representation before any task reasoning. We call this map the alignment layer, the component that separates a graph foundation model from a graph neural network, and we show it is a distinct attack surface that prior work has not studied. We attack it at inference time, with no access to training, on six public models spanning spectral tokenizers, text embedding spaces, and a discrete codebook. A directed representation-space perturbation collapses every model, but at a budget comparable to the representation norm a plain graph network also needs, with one exception: OpenGraph, whose spectral tokenizer collapses at a fifth of that budget, an alignment-specific fragility a plain network does not share and which a same-representation control traces to the tokenizer rather than the decoder. A realizable input-space attack that edits edges, feat","title":"Attacking Graph Foundation Models Through Their Shared Representation","url":"https://arxiv.org/abs/2607.18567","vendor":"arxiv_cs_ai"},"summary":"arXiv:2607.18567v1 Announce Type: new \nAbstract: A graph foundation model generalizes across graph domains by mapping every input into one shared representation before any task reasoning. We call this map the alignment layer, the component that separates a graph foundation model from a graph neural network, and we show it is a distinct attack surface that prior work has not studied. We attack it at inference time, with no access to training, on six public models spanning spectral tokenizers, text embedding spaces, and a discrete codebook. A directed representation-space perturbation collapses every model, but at a budget comparable to the representation norm a plain graph network also needs, with one exception: OpenGraph, whose spectral tokenizer collapses at a fifth of that budget, an alignment-specific fragility a plain network does not share and which a same-representation control traces to the tokenizer rather than the decoder. A realizable input-space attack that edits edges, feat","title":"Attacking Graph Foundation Models Through Their Shared Representation","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-07-22T04:43:18Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2607.18567"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:a5208db229cdc041946362e28a03234096784df0384d9b038f014bcf0ae4d712fc80e36e367d8489bce308b8de45ffee495c598bce456cfbdd7b156fb4bde10c","signer":"crovia.substrate","subject":{"observed_at":"2026-07-22T04:43:18Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2607.18567"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"7854c0502b1709b6d190547c3e4c59342f8cf782207a74b568a3afef4cb2ffb7","leaf_index":340152,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"7e8393df377c94c668e52e65f5cf9c0c58e1e1fcfc389c1ad4101d9085f6489d","side":"right"},{"sibling":"e6fdbab7bdc3d72ab5e5b4175bdd0e4adc04f232811975c3204746d95b188a7a","side":"right"},{"sibling":"cc3e73ac7e31b4a01a7911832c49b40b0c010fe6c13ced52dc8b056a10aa7d63","side":"right"},{"sibling":"61a73c87e9887fb6258dc47a448249674f9b50fb6361a61404db5ae7bfdb3e23","side":"left"},{"sibling":"14ea848f0faeff50bb639ad36016f9396398c01701ddfa973a515d20c2291096","side":"left"},{"sibling":"d1e7cb8bdfac0b01dc46042c0605c549b6ce8da203090e6c53c7d0e23e3c24a1","side":"left"},{"sibling":"c19ef9bb4a849405e5f1a70d9ae2c56923c9c29415795620b139019e34e92c35","side":"right"},{"sibling":"acd872eabf3ff3deb3760bc63ca3a4ca483306d9b2eb2ddf59ac880a653ae17a","side":"left"},{"sibling":"c0cb3fbdae423fd11084f7ab87b57c412a0ef2e6dcda395ebb9831d480ad609b","side":"right"},{"sibling":"c7fc9d4187cdc36f4c03b4b13daf4b880ea65536b051f71a5cc2543839d02697","side":"right"},{"sibling":"1758ec6ac206ce40e8368cb702195322fe3737d0fb03d8bd9e3b30acc4fa7d81","side":"right"},{"sibling":"0c407f0d553cf3fab8f9bd79205b8180e090cbf29fa0490ebb55155041ad5c86","side":"right"},{"sibling":"2dd9cb2521044ee7c6b74f2315e0a0253b8df0d04a7b810bbbbe7da5a9788769","side":"left"},{"sibling":"21d66dd41003813f710b7617944f1bfba3258658a5d3370c21cad8f9e945bc99","side":"left"},{"sibling":"787ee3744642ff909d610b0514cb100784f0ef1ba0ef4c70a0dc91f0ab2bb192","side":"right"},{"sibling":"9fc8a8ebbc1bff7e62b9f1e1c681c91e7196092ce9551573df6e23096df13e4d","side":"right"},{"sibling":"77025bcb374a7ad74f520643e20a8ae1205a7ee78507b0beb93117760f1c29d3","side":"left"},{"sibling":"ee6f33920899d9bdef2eb706dfff29e26eea61e29ea9824c6c8e6bcd48275d76","side":"right"},{"sibling":"1cecb7f447febd025aac272837c80de218aecc6485d2395a509b2a1f1b9c746e","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":340557,"merkle_root":"7d45d94f20b5bf82263df45b87749e19e06161972f25141dd573cc138d566338","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260722T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-07-22T05:38:39Z","sig_algorithm":"ed25519","signature":"812cb61e90d3582ba508db8515c4168bbf8ee1c6762885609049d012f680f8068f15c98b9accf2042047dcfc6a6fc3885820ee34b0be350846386f64f2591309","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_349a32574d68c01df25055baee00731d01ce0e4bd0d8d7d7c012cab8bcb5080b"}}