遇见数据集

Channel-Based Provenance Signals for 87 HPC and Quantum-Computing Open-Source Projects

收藏
Zenodo2026-07-19 更新2026-08-01 收录
官方服务:

资源简介:

Software trust is negotiated in communication channels such as the README, the registry listing, or the maintainer's account. AI agents now consume these channels directly, and attackers enter through them: the XZ Utils backdoor arrived through a mailing list, the Shai-Hulud worms phished maintainers to compromise 1,000+ npm packages, and in 2026, AI agents repeatedly installed a hallucinated package that never existed. Existing tools assess repositories, builds, and artifacts, but not this layer. We present channel-based provenance, to our knowledge, the first assessment framework for this layer: 18 signals spanning identity and access, communication channels, knowledge infrastructure, and distribution metadata, measured on 87 HPC and quantum-computing projects with a hand-verified 30-project panel. We find near-total provenance blindness; no missing signal requires new infrastructure, so the gap is adoption. The poster walks viewers from attack timeline to framework to per-project results, closing with concrete asks for maintainers, software stacks, and facilities. Conducted under the author's 2025-2026 Trusted CI Fellowship. Portions of the code and documentation were drafted with assistance from Claude (Anthropic); this assistance is recorded via Co-Authored-By trailers in the commit history. All content, code, and data were reviewed and verified by the maintainer, who is the sole author of this work.

提供机构:
Zenodo
创建时间:
2026-07-19
二维码
社区交流群
二维码
科研交流群
商业服务