PulseAugur
实时 09:44:18
English(EN) Stylometric Defenses Against Author Impersonation in Software Repositories

新的风格计量分析可检测代码提交中的作者冒充行为

研究人员开发了一种新的方法,通过对代码差异和提交消息进行风格计量分析来检测软件仓库中的作者冒充行为。通过在大量的Linux内核提交历史记录上微调跨模态Transformer,他们创建了可以识别伪造提交的嵌入。该方法在开放世界作者身份验证方面达到了0.93的ROC AUC,并在PHP后门和ForceMemo/GlassWorm活动等回顾性供应链事件中得到了成功验证,展示了其在持续集成和部署管道中的潜力。 AI

影响 通过实现对恶意代码提交的自动化检测,增强了软件供应链的安全性。

排序理由 该集群包含一篇详细介绍软件安全新方法的学术论文。[lever_c_demoted from research: ic=1 ai=1.0]

在 arXiv cs.LG 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

新的风格计量分析可检测代码提交中的作者冒充行为

报道来源 [1]

  1. arXiv cs.LG TIER_1 English(EN) · Leonid Ravich, Michael Fire ·

    Stylometric Defenses Against Author Impersonation in Software Repositories

    arXiv:2608.02695v1 Announce Type: cross Abstract: Software supply-chain attacks increasingly exploit an identity gap where compromised maintainer accounts authorize malicious changes. This work evaluates patch-level authorship verification as a behavioral defense layer, showing t…