遇见数据集

Artifact for SOHO Supply-chain Analysis (USENIX Security 2026)

收藏
Zenodo2026-08-09 更新2026-08-13 收录
官方服务:

资源简介:

This record contains the research artifact for the paper "Anchors that Don't Lift: Understanding Supply-Chain Driven Kernel Lock-In and Governance-Mediated Mitigation Strategies in SOHO Devices," accepted at the 35th USENIX Security Symposium (USENIX Security 2026, cycle 2, paper #2241). This is an extended version of the artifact. It contains everything that was submitted for artifact evaluation, plus a fourth component: the analysis scripts used to collect the firmware and GPL sources and to produce the supply-chain data. The artifact has four components: 1. Analysis Scripts (pipeline/) Helper scripts support firmware/source collection, kernel extraction, CVE analysis, and SoC/SDK attribution, with each folder containing a README describing how to run them. An OpenWrt example firmware is included to test the scripts. 2. Reddit Comments Classifier (RedditCommentsClassification/)A fine-tuned DeBERTa-base model that classifies Reddit comments as either "Related to security/privacy" or "Not Related to security/privacy." The folder includes the model weights, tokenizer files, an inference script (Inference_RedditCommentsClassifier_Deberta.py), and a sample input file. 3. Supply Chain Data (Dataset/Supplychain-data/)A device-metadata table compiled from our own analysis combined with multiple publicly available sources. This dataset is included directly in the repository. The scripts in pipeline/ are the ones used to derive its firmware, kernel, SDK and SoC fields. 4. Forum Data (Dataset/Forum-data/) — gated accessA dataset of posts and comments collected from publicly available forum discussion threads. While the underlying content is technically public, aggregating and redistributing it on a permanent platform raises privacy concerns, particularly if the data were used outside of academic research. For this reason, the dataset is not included directly in this repository. It will be shared with researchers upon receipt ofa signed data sharing agreement, which restricts use to academic research purposes, prohibits redistribution, and requires institutional ethics approval. The agreement template and instructions for requesting access are located in Dataset/Forum-data/data_sharing_agreement.txt. CitationIf you use this artifact, please cite: Badola, R., Ghosh, R., Gupta, A., Rebeiro, C. & Mondal, M. (2026). Anchors that Don't Lift: Understanding Supply-Chain Driven Kernel Lock-In and Governance-Mediated Mitigation Strategies in SOHO Devices. In Proceedings of the 35th USENIX Security Symposium (USENIX Security'26).

提供机构:
Zenodo
创建时间:
2026-08-09
二维码
社区交流群
二维码
科研交流群
商业服务