{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_db1ad716ecd43b30ca35c5f933d72e3baf7ce0824239bb55cc1d746e9ba196be","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_db1ad716ecd43b30ca35c5f933d72e3baf7ce0824239bb55cc1d746e9ba196be","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"e8a727dc60708c9d1edace320bf85f076851fb606f52525ec1a7bbb4d9fbf260","published":"Mon, 01 Jun 2026 00:00:00 -0400","receipt_hash":"e8a727dc60708c9d1edace320bf85f076851fb606f52525ec1a7bbb4d9fbf260","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"e8a727dc60708c9d1edace320bf85f076851fb606f52525ec1a7bbb4d9fbf260","observed_at":"2026-06-01T04:43:13.859018Z","parent_run_hash":"8993bbc535dae8c9669e099af3624cb39166b8d9bbfd66f26ae5c338cbb21be2","published":"Mon, 01 Jun 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2605.30667v1 Announce Type: cross \nAbstract: Software tools for reverse engineering executable binary files, such as Ghidra, enable malware analysts to safely conduct robust static analysis without having access to original source code. Coupled with the analytic power of large language models (LLM), agentic systems enabled with tools, such as GhidraMCP, can allow analysts to automate a previously human driven process. Although this automation can increase the productivity of a single malware analyst, it also introduces a new area of vulnerability for malware obfuscation. This paper presents an adversarial technique using genetic algorithm-based prompt generation, a modification of an adversarial attack known as AutoDAN, to demonstrate the ability to deceive LLM-powered disassembly and decompilation systems into misinterpreting binary executables, effectively corrupting their analytical output. This proof-of-concept methodology exploits inherent vulnerabilities in how LLMs process","title":"Automatically Attacking Software Reverse Engineering AI Agents","url":"https://arxiv.org/abs/2605.30667","vendor":"arxiv_cs_ai"},"summary":"arXiv:2605.30667v1 Announce Type: cross \nAbstract: Software tools for reverse engineering executable binary files, such as Ghidra, enable malware analysts to safely conduct robust static analysis without having access to original source code. Coupled with the analytic power of large language models (LLM), agentic systems enabled with tools, such as GhidraMCP, can allow analysts to automate a previously human driven process. Although this automation can increase the productivity of a single malware analyst, it also introduces a new area of vulnerability for malware obfuscation. This paper presents an adversarial technique using genetic algorithm-based prompt generation, a modification of an adversarial attack known as AutoDAN, to demonstrate the ability to deceive LLM-powered disassembly and decompilation systems into misinterpreting binary executables, effectively corrupting their analytical output. This proof-of-concept methodology exploits inherent vulnerabilities in how LLMs process","title":"Automatically Attacking Software Reverse Engineering AI Agents","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-06-01T04:43:13Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2605.30667"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:5a58d8e30c001f388ed3e3bc09cb13d00b1abef860cb81833937c96139d2caed34b81094840a116f53e8f9a162b02bd9f82e95daa7ba5dadcd65589971da7f07","signer":"crovia.substrate","subject":{"observed_at":"2026-06-01T04:43:13Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2605.30667"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"14eceb44b244cf975a1cabb3fd3c62afd5ea37b13e3e50db0624f3172967e86a","leaf_index":163856,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"a598653365ef3bfe3fb0d029b978d42cf7467c0e394425fdd62a2e1de7323b6e","side":"right"},{"sibling":"b02996b720de225f78bec970f107a7624e8809156f0dbc61723f8be5d4f2809d","side":"right"},{"sibling":"189e4f0922d544b95a1eedd997168e9f3517b9a880fb0ca47cf72b09fabcfddc","side":"right"},{"sibling":"5b82fd28d86a77211b12a3f3da4f2c002155bf3214235ee91c583dc7f5aebebb","side":"right"},{"sibling":"980f3a4c466abd0a2ad29cbe835480da4722566d41909b7d12d5ee4357214c25","side":"left"},{"sibling":"e043a5135c0f47d58e20f1339e1f8e8d5d103e0d903342279d0db8b7201a9af0","side":"right"},{"sibling":"8759b29a2f5a0cbc7e311e83a6c64093a22568f86085e1c65bead39ebc241c88","side":"right"},{"sibling":"c80f3e378be31136ba3005ae1d4e6fb73ee42b46d44ded3d5ec7b012545b00f5","side":"right"},{"sibling":"86fede29e507d01bfe35484a1579149e8e99b3527ff48559423f6056d11af46a","side":"right"},{"sibling":"fc601f0745c37fc5f7c249300e654db05d61bb9059885eeb0b0a5047b5d28408","side":"right"},{"sibling":"6ed9290cdae063f13bfeb71c4c5440595cabb61fd4b39225b9cc913ffb336dd7","side":"right"},{"sibling":"a0446b923d1ce90021e78edff07f6bfc7cc2a1326a565c5f0786b82a24dd0a2a","side":"right"},{"sibling":"e598fd53912c30e58ca8e58d7d8a338fe0f2ecb63fdd99225bc703c499c948ec","side":"right"},{"sibling":"fc4873333221ec8167697f75b6f6a8a08491a8cf18952defb65fb6d4958fa5e7","side":"right"},{"sibling":"05c8a827da2a05549ee3250310777009120c687885816bf6c7c74801bfaa346d","side":"right"},{"sibling":"5ea2f2dc9f046df723b6bd9932d61a9a3d80a76e79ce1b939b3d93ff79b5a91c","side":"left"},{"sibling":"ce41d9b82f34b16efd653dfb3552acc4e2512939e47903e5fc979fbed00c5764","side":"right"},{"sibling":"d841ad93efda0869e5eb97678f348f03f5caab4353e05ff4bf18f47fb945b822","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":164217,"merkle_root":"a1098816aea1b60b8fe37b62410469bc5024a2c335bbec4f6ef2add7875dbdf2","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260601T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-06-01T05:37:41Z","sig_algorithm":"ed25519","signature":"d7f91db1d54b9495c499440c2828f4bd53360555391ce6e25adea5183bc1fa0f697d80708a099d0b0429e6f8cb6c71e7fccf82acb3c84481149974fb26074708","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_db1ad716ecd43b30ca35c5f933d72e3baf7ce0824239bb55cc1d746e9ba196be"}}