{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:PEWYOCB64HQ7HQDCQEYZB47WOC","short_pith_number":"pith:PEWYOCB6","schema_version":"1.0","canonical_sha256":"792d87083ee1e1f3c062813190f3f67092422ee07c34fa47b9855b97b984307e","source":{"kind":"arxiv","id":"2501.19012","version":1},"attestation_state":"computed","paper":{"title":"Importing Phantoms: Measuring LLM Package Hallucination Vulnerabilities","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"Arjun Krishna, Erick Galinkin, Jeffrey Martin, Leon Derczynski","submitted_at":"2025-01-31T10:26:18Z","abstract_excerpt":"Large Language Models (LLMs) have become an essential tool in the programmer's toolkit, but their tendency to hallucinate code can be used by malicious actors to introduce vulnerabilities to broad swathes of the software supply chain. In this work, we analyze package hallucination behaviour in LLMs across popular programming languages examining both existing package references and fictional dependencies. By analyzing this package hallucination behaviour we find potential attacks and suggest defensive strategies to defend against these attacks. We discover that package hallucination rate is pre"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2501.19012","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2025-01-31T10:26:18Z","cross_cats_sorted":["cs.CL","cs.CR"],"title_canon_sha256":"a40b0a7cf9e102f70ebeb493d0a18f183e99e513286601612bb1c74d0501166f","abstract_canon_sha256":"6039bce11e1a675dc67b12e2e5b8adc6529c700bbf3adabd7a1ecb7ea151eeb0"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:07:55.014746Z","signature_b64":"h3G3xjOFhw/4IwxEJ5ELuPGiSl0Gu+613wgYHIHZMWJ/FEsuWzgcnpYtm6odLjloidZNbapBClPIJMWmoZYsDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"792d87083ee1e1f3c062813190f3f67092422ee07c34fa47b9855b97b984307e","last_reissued_at":"2026-07-05T10:07:55.014268Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:07:55.014268Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Importing Phantoms: Measuring LLM Package Hallucination Vulnerabilities","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.CL","cs.CR"],"primary_cat":"cs.LG","authors_text":"Arjun Krishna, Erick Galinkin, Jeffrey Martin, Leon Derczynski","submitted_at":"2025-01-31T10:26:18Z","abstract_excerpt":"Large Language Models (LLMs) have become an essential tool in the programmer's toolkit, but their tendency to hallucinate code can be used by malicious actors to introduce vulnerabilities to broad swathes of the software supply chain. In this work, we analyze package hallucination behaviour in LLMs across popular programming languages examining both existing package references and fictional dependencies. By analyzing this package hallucination behaviour we find potential attacks and suggest defensive strategies to defend against these attacks. We discover that package hallucination rate is pre"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2501.19012","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2501.19012/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2501.19012","created_at":"2026-07-05T10:07:55.014324+00:00"},{"alias_kind":"arxiv_version","alias_value":"2501.19012v1","created_at":"2026-07-05T10:07:55.014324+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2501.19012","created_at":"2026-07-05T10:07:55.014324+00:00"},{"alias_kind":"pith_short_12","alias_value":"PEWYOCB64HQ7","created_at":"2026-07-05T10:07:55.014324+00:00"},{"alias_kind":"pith_short_16","alias_value":"PEWYOCB64HQ7HQDC","created_at":"2026-07-05T10:07:55.014324+00:00"},{"alias_kind":"pith_short_8","alias_value":"PEWYOCB6","created_at":"2026-07-05T10:07:55.014324+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":11,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.07433","citing_title":"Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting","ref_index":15,"is_internal_anchor":true},{"citing_arxiv_id":"2607.02052","citing_title":"Mitigating Package Hallucinations in Large Language Models via Model Editing","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2606.08444","citing_title":"When LLMs Invent Rust Crates: An Empirical Study of Hallucination Patterns and Mitigation","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2606.08157","citing_title":"Cross Paraphrastic Invariance Learning for Hallucination Detection","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2605.30777","citing_title":"What Breaks When LLMs Code? Characterizing Operational Safety Failures of Agentic Code Assistants","ref_index":52,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17062","citing_title":"The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2605.24137","citing_title":"Empirical Analysis and Detection of Hallucinations in LLM-Generated Bug Report Summaries","ref_index":18,"is_internal_anchor":false},{"citing_arxiv_id":"2509.22202","citing_title":"Library Hallucinations in LLM-Generated Code: A Risk Analysis Grounded in Developer Queries","ref_index":26,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17062","citing_title":"The Range Shrinks, the Threat Remains: Re-evaluating LLM Package Hallucinations on the 2026 Frontier-Model Cohort","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2605.09594","citing_title":"Trust Me, Import This: Dependency Steering Attacks via Malicious Agent Skills","ref_index":14,"is_internal_anchor":false},{"citing_arxiv_id":"2604.07755","citing_title":"An Empirical Analysis of Static Analysis Methods for Detection and Mitigation of Code Library Hallucinations","ref_index":3,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/PEWYOCB64HQ7HQDCQEYZB47WOC","json":"https://pith.science/pith/PEWYOCB64HQ7HQDCQEYZB47WOC.json","graph_json":"https://pith.science/api/pith-number/PEWYOCB64HQ7HQDCQEYZB47WOC/graph.json","events_json":"https://pith.science/api/pith-number/PEWYOCB64HQ7HQDCQEYZB47WOC/events.json","paper":"https://pith.science/paper/PEWYOCB6"},"agent_actions":{"view_html":"https://pith.science/pith/PEWYOCB64HQ7HQDCQEYZB47WOC","download_json":"https://pith.science/pith/PEWYOCB64HQ7HQDCQEYZB47WOC.json","view_paper":"https://pith.science/paper/PEWYOCB6","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2501.19012&json=true","fetch_graph":"https://pith.science/api/pith-number/PEWYOCB64HQ7HQDCQEYZB47WOC/graph.json","fetch_events":"https://pith.science/api/pith-number/PEWYOCB64HQ7HQDCQEYZB47WOC/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/PEWYOCB64HQ7HQDCQEYZB47WOC/action/timestamp_anchor","attest_storage":"https://pith.science/pith/PEWYOCB64HQ7HQDCQEYZB47WOC/action/storage_attestation","attest_author":"https://pith.science/pith/PEWYOCB64HQ7HQDCQEYZB47WOC/action/author_attestation","sign_citation":"https://pith.science/pith/PEWYOCB64HQ7HQDCQEYZB47WOC/action/citation_signature","submit_replication":"https://pith.science/pith/PEWYOCB64HQ7HQDCQEYZB47WOC/action/replication_record"}},"created_at":"2026-07-05T10:07:55.014324+00:00","updated_at":"2026-07-05T10:07:55.014324+00:00"}