Software Supply Chain Security

Momentum

3 papers in the last four weeks, with none the four weeks before. 0.0% of all new papers.

Jul 13Week of Sep 28

Latest papers 20

All topics
CardsList
  1. Evaluating Whether GPT-6 Astra Performs Unsanctioned Supply-Chain Attacks

    Sep 29, 2026Alexandra Souly, Kai Fronsdal, Abby D'Cruz +2LLM AuditingAI Agent Security

  2. VEX-Bench: Benchmarking LLM Agents for Assessing Exploitability of Software Supply Chain Vulnerabilities

    Sep 7, 2026Jiahao Shi, Edward Tsien, Yifeng Di +10LLM Agent EvaluationSoftware Security

  3. Do AI Coding Assistants Check Before They Install? A Pre-Registered Demand-Side Audit of Trust Signals in the Research Software Supply Chain

    Sep 7, 2026Pengyin ShanAlgorithmic AuditingAI Coding Agents

  4. Stylometric Defenses Against Author Impersonation in Software Repositories

    Aug 3, 2026Leonid Ravich, Michael FireOnline Anomaly DetectionStylometry

  5. Vulnerabilities, Secrets and Misconfiguration in the Highest-Exposure Docker Hub Images

    Aug 2, 2026Cristhian Kapelinski, Beatriz Machado, Diego KreutzSoftware Vulnerability DetectionCybersecurity

  6. A Large-Scale Measurement of AI Bill of Materials Completeness in Hugging Face Models

    Jul 19, 2026Md Erfan, Ahmed Ryan, Md Rayhanur RahmanAI AccountabilitySoftware Supply Chain Security

  7. How Do You Choose Your AI Component? An Interview Study of Secure AI Integration in Practice

    Jul 18, 2026Mahzabin Tamanna, Elizabeth Lin, Sparsha Gowda +2LLM SecuritySoftware Supply Chain Security

  8. LLM-Enhanced Hierarchical Heterogeneous Graph Representation Learning for Malicious Python Package Detection

    Jul 3, 2026Hang Gao, Xiaoyu Chen, Baoquan Cui +4Heterogeneous GNNsHierarchical Representation Learning

  9. Execution-bound advisory automation for agentic AI: a reproducible AIBOM-driven CSAF-VEX framework

    Jun 16, 2026Petar Radanliev, Omar Santos, Carsten Maple +1CybersecuritySoftware Security

  10. GitInject: Real-World Prompt Injection Attacks in AI-Powered CI/CD Pipelines

    Jun 7, 2026Jafar Isbarov, Umid Suleymanov, Ilia Shumailov +1AI Agent SecurityAI Agent Security Benchmarks

  11. Benchmarking Security Risk Detection and Verification in Open Agentic Skill Ecosystems

    May 30, 2026Ismail Hossain, Sai Puppala, Zhuoran Lu +2AI Agent SecurityAI Agent Security Benchmarks

  12. Harmless Yet Harmful: Neutral Prompting Attacks for Stealthy Hallucination Steering in Agent Skills

    May 28, 2026Chia-Yi Hsu, Chia-Mu Yu, Chun-Ying Huang +1Adversarial Prompt GenerationAI Coding Agents

  13. Correct Code, Vulnerable Dependencies: A Large Scale Measurement Study of LLM-Specified Library Versions

    May 7, 2026Chengjie Wang, Jingzheng Wu, Xiang Ling +2Software EngineeringLLM Security

  14. Test Before You Deploy: Governing Updates in the LLM Supply Chain

    Apr 30, 2026Mohd Sameen Chishti, Damilare Peter Oyinloye, Jingyue LiLLM EvaluationLLM Auditing

  15. eDySec: A Deep Learning-based Explainable Dynamic Analysis Framework for Detecting Malicious Packages in PyPI Ecosystem

    Apr 29, 2026Sk Tanzir Mehedi, Raja Jurdak, Chadni Islam +2Malware ClassificationSoftware Supply Chain Security

  16. Fox in the Henhouse: Supply-Chain Backdoor Attacks Against Reinforcement Learning

    May 26, 2025Shijie Liu, Andrew C. Cullen, Paul Montague +2Adversarial AttacksBackdoor Attacks