Artifact for SOHO Supply-chain Analysis (USENIX Security 2026)
收藏资源简介:
This record contains the research artifact for the paper "Anchors that Don't Lift: Understanding Supply-Chain Driven Kernel Lock-In and Governance-Mediated Mitigation Strategies in SOHO Devices," accepted at the 35th USENIX Security Symposium (USENIX Security 2026, cycle 2, paper #2241). The artifact has three components: 1. Reddit Comments Classifier (RedditCommentsClassification/)A fine-tuned DeBERTa-base model that classifies Reddit comments as either "Related to security/privacy" or "Not Related to security/privacy." The folder includes the model weights, tokenizer files, an inference script (Inferance_RedditCommentsClassifier_Deberta.py), and a sample input file. 2. Supply Chain Data (Dataset/Supplychain-data/)A device-metadata table compiled from our own analysis combined with multiple publicly available sources. This dataset is included directly in the repository. 3. Reddit Data (Dataset/Reddit-data/) — gated accessA dataset of posts and comments collected from publicly available Reddit discussion threads. While the underlying content is technically public, aggregating and redistributing it on a permanent platform raises privacy concerns, particularly if the data were used outside of academic research. For this reason, the Reddit dataset is not included directly in this repository. It will be shared with researchers upon receipt of a signed data sharing agreement, which restricts use to academic research purposes, prohibits redistribution, and requires institutional ethics approval. The agreement template and instructions for requesting access are located in Dataset/Reddit-data/data_sharing_agreement.txt. CitationIf you use this artifact, please cite: Badola, R., Ghosh, R., Gupta, A., Rebeiro, C. & Mondal, M. (2026). Anchors that Don't Lift: Understanding Supply-Chain Driven Kernel Lock-In and Governance-Mediated Mitigation Strategies in SOHO Devices. In Proceedings of the 35th USENIX Security Symposium (USENIX Security'26).



