{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:MANZFWOB3ORHOST2CTY7JWH5W2","short_pith_number":"pith:MANZFWOB","schema_version":"1.0","canonical_sha256":"601b92d9c1dba2774a7a14f1f4d8fdb69cf53af514d9711f18b833027deefbfa","source":{"kind":"arxiv","id":"2607.23147","version":1},"attestation_state":"computed","paper":{"title":"False Prophets: On the Security of World Models in Agentic Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Anna Wimbauer, Erik Imgrund, Klim Kireev, Konrad Rieck","submitted_at":"2026-07-25T10:55:14Z","abstract_excerpt":"Large language models now power autonomous agents capable of complex, multi-step tasks in different environments. Accurate and reliable execution of these tasks requires the agent to predict the results of its actions. Recent research proposes to enhance predictive capabilities via specially trained environment simulators-world models. While world models can improve performance, they can also mislead agents into executing harmful actions, creating significant security and privacy risks. In this paper, we raise security concerns regarding the usage of world models in agentic systems. We discove"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2607.23147","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-07-25T10:55:14Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"ffc01be86ed060dd85fe1c89ee140f0ae3d01650475f8ff787a2ca9e6185f803","abstract_canon_sha256":"13fa04a7af9a1f762716e63a694cb68de5a53dfd9d6fc23f440c6cff8b8750db"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-28T01:22:09.463622Z","signature_b64":"Jayr9wLcl2xnxXFxYewnzQr1We60wve1GsCSxVquA1XRyvQSO6/FDkAt6GVwwPa2J+RRlqHjLS4hiDOOaHY3Aw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"601b92d9c1dba2774a7a14f1f4d8fdb69cf53af514d9711f18b833027deefbfa","last_reissued_at":"2026-07-28T01:22:09.462827Z","signature_status":"signed_v1","first_computed_at":"2026-07-28T01:22:09.462827Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"False Prophets: On the Security of World Models in Agentic Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Anna Wimbauer, Erik Imgrund, Klim Kireev, Konrad Rieck","submitted_at":"2026-07-25T10:55:14Z","abstract_excerpt":"Large language models now power autonomous agents capable of complex, multi-step tasks in different environments. Accurate and reliable execution of these tasks requires the agent to predict the results of its actions. Recent research proposes to enhance predictive capabilities via specially trained environment simulators-world models. While world models can improve performance, they can also mislead agents into executing harmful actions, creating significant security and privacy risks. In this paper, we raise security concerns regarding the usage of world models in agentic systems. We discove"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.23147","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2607.23147/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2607.23147","created_at":"2026-07-28T01:22:09.463248+00:00"},{"alias_kind":"arxiv_version","alias_value":"2607.23147v1","created_at":"2026-07-28T01:22:09.463248+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.23147","created_at":"2026-07-28T01:22:09.463248+00:00"},{"alias_kind":"pith_short_12","alias_value":"MANZFWOB3ORH","created_at":"2026-07-28T01:22:09.463248+00:00"},{"alias_kind":"pith_short_16","alias_value":"MANZFWOB3ORHOST2","created_at":"2026-07-28T01:22:09.463248+00:00"},{"alias_kind":"pith_short_8","alias_value":"MANZFWOB","created_at":"2026-07-28T01:22:09.463248+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/MANZFWOB3ORHOST2CTY7JWH5W2","json":"https://pith.science/pith/MANZFWOB3ORHOST2CTY7JWH5W2.json","graph_json":"https://pith.science/api/pith-number/MANZFWOB3ORHOST2CTY7JWH5W2/graph.json","events_json":"https://pith.science/api/pith-number/MANZFWOB3ORHOST2CTY7JWH5W2/events.json","paper":"https://pith.science/paper/MANZFWOB"},"agent_actions":{"view_html":"https://pith.science/pith/MANZFWOB3ORHOST2CTY7JWH5W2","download_json":"https://pith.science/pith/MANZFWOB3ORHOST2CTY7JWH5W2.json","view_paper":"https://pith.science/paper/MANZFWOB","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2607.23147&json=true","fetch_graph":"https://pith.science/api/pith-number/MANZFWOB3ORHOST2CTY7JWH5W2/graph.json","fetch_events":"https://pith.science/api/pith-number/MANZFWOB3ORHOST2CTY7JWH5W2/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/MANZFWOB3ORHOST2CTY7JWH5W2/action/timestamp_anchor","attest_storage":"https://pith.science/pith/MANZFWOB3ORHOST2CTY7JWH5W2/action/storage_attestation","attest_author":"https://pith.science/pith/MANZFWOB3ORHOST2CTY7JWH5W2/action/author_attestation","sign_citation":"https://pith.science/pith/MANZFWOB3ORHOST2CTY7JWH5W2/action/citation_signature","submit_replication":"https://pith.science/pith/MANZFWOB3ORHOST2CTY7JWH5W2/action/replication_record"}},"created_at":"2026-07-28T01:22:09.463248+00:00","updated_at":"2026-07-28T01:22:09.463248+00:00"}