REVIEW 2 major objections 67 references
A compact four-pole Purcell filter on a 3D flip-chip platform gives a flat 1 GHz readout passband while suppressing qubit-frequency leakage by more than 45 dB, so resonators can be strongly coupled without paying a Purcell decay penalty.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · grok-4.5
2026-07-13 23:34 UTC pith:3CFRUIYJ
load-bearing objection We only have the abstract for the Purcell-filter paper; the attached full text is a different manuscript, so the device claims cannot be checked. the 2 major comments →
A Compact Broadband Purcell Filter for Superconducting Quantum Circuits in a 3D Flip-Chip Architecture
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
A four-pole broadband Purcell filter implemented on a 3D flip-chip platform delivers a flat 1 GHz passband at 7.68 GHz with more than 45 dB stopband suppression at qubit frequencies, remains compatible with strong multiplexed coupling of six floating readout resonators, and is accurately described by a geometry-based analytical model of filter response and resonator resonance frequency and external quality factor.
What carries the argument
The four-pole broadband Purcell filter in 3D flip-chip form, plus the analytical model that predicts filter S-parameters and floating-resonator f_r and Q_ext directly from physical geometry, enabling rapid circuit synthesis without full-wave redesign at every step.
Load-bearing premise
That the measured passband flatness, stopband suppression, and strong multiplexed coupling on this single niobium test chip at 20 mK will still hold under real multi-qubit loading, packaging parasitics, and fabrication spread without reopening Purcell-limited decay or readout crosstalk.
What would settle it
Fabricate and cool a multi-qubit flip-chip processor that uses this filter with several strongly coupled readout resonators, measure qubit T1 versus filter-predicted Purcell rate and multiplexed readout fidelity/crosstalk across the 1 GHz band, and check whether suppression stays above 45 dB and T1 is not Purcell-limited once packaging and full loading are present.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript claims a four-pole broadband Purcell filter in a 3D flip-chip architecture that delivers a flat ~1 GHz passband centered at 7.68 GHz with >45 dB stopband suppression at typical qubit frequencies, while remaining compatible with strong multiplexed coupling of six floating readout resonators on a 150 nm Nb test chip measured at 20 mK. An analytical geometry-based model is said to predict filter response and the resonators’ resonance frequencies and external quality factors, enabling rapid synthesis. The design is presented as compact and fabrication-tolerant for large-scale superconducting processors. The supplied full-text body, however, is an unrelated cs.CR paper (SynthChain) and contains none of the filter design, S-parameter data, model equations, or cryogenic results.
Significance. If the abstract claims hold under multi-qubit loading and realistic packaging, a compact, broadband, geometry-predictable Purcell filter that preserves strong resonator–feedline coupling would be a practically useful building block for multiplexed readout in 3D flip-chip quantum processors. The combination of a four-pole response, floating resonators, and an analytical model that maps geometry directly to f_r and Q_ext would be a genuine engineering contribution. Because the matching technical body is absent from the review package, these strengths cannot be verified or credited on the basis of measured data or derivations.
major comments (2)
- The review package supplies only the abstract of arXiv:2603.16693; the full manuscript text is the unrelated SynthChain paper (arXiv:2603.16694). Consequently there are no filter schematics, pole-placement equations, measured S-parameters, model-vs-data residuals, Q_ext values, or 20 mK characterization results against which the central claims (>45 dB suppression, 1 GHz flat passband, geometry-based prediction of resonator parameters) can be checked. Load-bearing technical assessment is impossible until the correct body is provided.
- Even taking the abstract at face value, the generalization claim—that the reported stopband suppression and strong multiplexed coupling remain valid under realistic multi-qubit loading, packaging parasitics, and fabrication spread—cannot be evaluated without the missing measurement and modeling sections. This is a load-bearing assumption for the “practical solution for large-scale processors” conclusion.
Circularity Check
No circularity identifiable: abstract claims are experimental/geometry-based, and the provided full text is the wrong paper.
full rationale
The target abstract (arXiv:2603.16693) presents a four-pole Purcell filter with measured passband/stopband performance and an analytical model that maps resonator geometry to f_r and Q_ext. Those claims are not self-definitional: filter S-parameters and resonator parameters are physical observables, and a geometry-to-response model is a standard independent mapping if checked against measurement. The CACHEABLE full manuscript text is an unrelated cs.CR paper (SynthChain), so no load-bearing equations, fits, or self-citation chains from the Purcell-filter derivation can be quoted or reduced. With no exhibit of Eq. X = Eq. Y by construction, fitted inputs renamed as predictions, or uniqueness imported from overlapping authors, circularity cannot be asserted. Score 0 is the correct honest non-finding under the hard rule that circularity requires a quotable specific reduction.
Axiom & Free-Parameter Ledger
free parameters (2)
- Filter center frequency / pole placement (7.68 GHz, 1 GHz passband)
- External quality factors of floating resonators
axioms (3)
- domain assumption Strong resonator–feedline coupling improves readout speed/fidelity but increases Purcell decay of the qubit unless filtered.
- domain assumption A four-pole microwave filter response can provide a flat passband at readout frequencies and deep stopband at qubit frequencies in a flip-chip stack.
- ad hoc to paper Resonance frequencies and external quality factors of floating resonators are determined accurately enough from physical geometry via the authors’ analytical model.
invented entities (1)
-
Four-pole broadband Purcell filter in 3D flip-chip architecture (this design instance)
no independent evidence
read the original abstract
Fast and high-fidelity qubit readout requires strong coupling between the readout resonator and the feedline. However, such coupling unavoidably enhances qubit decay through the Purcell effect. We present a four-pole broadband Purcell filter implemented on a 3D flip-chip platform to overcome this trade-off. The filter provides a flat 1 GHz passband centered at 7.68 GHz and achieves more than 45 dB suppression at typical qubit frequencies. We demonstrate the filter's compatibility with multiplexed readout using a test chip that integrates six floating readout resonators strongly coupled within the passband. The chip is fabricated using a 150 nm Niobium (Nb) thin-film process and characterized at 20 mK in a cryogenic measurement setup. We also develop an analytical model that accurately captures the filter response and determines the resonance frequencies and external quality factors of the floating resonators directly from their physical geometry, enabling rapid circuit synthesis and design optimization. The proposed design is compact and fabrication-tolerant, making it a practical solution for large-scale superconducting quantum processors.
Reference graph
Works this paper leans on
-
[1]
shai-hulud
Unit 42. "shai-hulud" worm compromises npm ecosys- tem in supply chain attack. Technical report, Palo Alto Networks, September 2025. Technical alert / threat re- search report. URL: https://unit42.paloaltonet works.com/npm-supply-chain-attack/
2025
-
[2]
Secret-based cloud supply-chain attacks: Case study and lessons for security teams, Dec 2022
Schindel Alon and Tamari Shir. Secret-based cloud supply-chain attacks: Case study and lessons for security teams, Dec 2022. URL: https://www.wiz.io/blog/ secret-based-cloud-supply-chain-attacks-c ase-study-and-lessons-for-security-teams
2022
-
[3]
Collecting telemetry data on macos using ap- ple’s endpoint security, 2025
Apriorit. Collecting telemetry data on macos using ap- ple’s endpoint security, 2025. Describes macOS teleme- try collection mechanisms and their usage challenges. URL: https://www.apriorit.com/dev-blog/coll ecting-telemetry-data-on-macos-using-endpo int-security
2025
-
[4]
Operationally transparent cyber (optc), 2021
Rody Arantes, Carl Weir, Henry Hannon, and Marisha Kulseng. Operationally transparent cyber (optc), 2021. doi:10.21227/edq8-nk52
-
[5]
Exorcist: Automated Differen- tial Analysis to Detect Compromises in Closed-Source Software Supply Chains
Frederick Barr-Smith, Tim Blazytko, Richard Baker, and Ivan Martinovic. Exorcist: Automated Differen- tial Analysis to Detect Compromises in Closed-Source Software Supply Chains. InProceedings of the 2022 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses, pages 51–61, Los Angeles CA USA, 2022. ACM
2022
-
[6]
Kairos: Practical intrusion detection and investigation using whole-system provenance.2024 IEEE Symposium on Security and Privacy (SP), pages 3533–3551, 2023
Zijun Cheng, Qiujian Lv, Jinyuan Liang, Yan Wang, De- gang Sun, Thomas Pasquier, and Xueyuan Han. Kairos: Practical intrusion detection and investigation using whole-system provenance.2024 IEEE Symposium on Security and Privacy (SP), pages 3533–3551, 2023
2024
-
[7]
Crowdstrike threat hunting report
CrowdStrike. Crowdstrike threat hunting report. https: //www.crowdstrike.com/en-gb/resources/repo rts/threat-hunting-report/, 2025. Annual threat intelligence and hunting report
2025
-
[8]
Sajjad Dadkhah, Xichen Zhang, Alexander Gerald Weis- mann, Amir Firouzi, and Ali A. Ghorbani. The largest social media ground-truth dataset for real/fake con- tent: Truthseeker.IEEE Transactions on Computa- tional Social Systems, 11(3):3376–3390, 2024. doi: 10.1109/TCSS.2023.3322303
-
[9]
Information security continuous monitoring (iscm) for federal information systems and organizations (sp 800-137)
Kelley Dempsey et al. Information security continuous monitoring (iscm) for federal information systems and organizations (sp 800-137). Technical report, National Institute of Standards and Technology, 2011. URL: ht tps://csrc.nist.gov/pubs/sp/800/137/final
2011
-
[10]
A new method for detecting beaconing attacks in iot-based scada systems.Int
Ferdi Do˘gan, Onur Polat, and Fahri Yardimci. A new method for detecting beaconing attacks in iot-based scada systems.Int. J. Inf. Secur., 24(6), November 2025. doi:10.1007/s10207-025-01161-6
-
[11]
Openssf malicious packages
Open Source Security Foundation. Openssf malicious packages. https://github.com/ossf/maliciou s-packages/, 2024
2024
-
[12]
Python packages leverage github to deploy fileless malware, Dec 2022
Yehuda Gelb. Python packages leverage github to deploy fileless malware, Dec 2022. URL: https: //medium.com/checkmarx-security/python-p ackages-leverage-github-to-deploy-fileles s-malware-b6c281dea58f#:~:text=In%20early% 20December%2C%20a%20number,cleverness%20of %20their%20deployment%20strategy. 14
2022
-
[13]
Attacker hidden in plain sight for nearly six months, targeting python developers, Nov 2023
Yehuda Gelb. Attacker hidden in plain sight for nearly six months, targeting python developers, Nov 2023. URL: https://medium.com/checkmarx-securit y/attacker-hidden-in-plain-sight-for-nearl y-six-months-targeting-python-developers-3 712f0f107e0
2023
-
[14]
Lazarus group launches first open source supply chain attacks targeting crypto sector, Aug 2023
Yehuda Gelb. Lazarus group launches first open source supply chain attacks targeting crypto sector, Aug 2023. URL: https://medium.com/checkmarx-security/ lazarus-group-launches-first-open-source-s upply-chain-attacks-targeting-crypto-secto r-cabc626e404e
2023
-
[15]
An ongoing open source attack reveals roots dating back to 2021, Aug 2023
Yehuda Gelb. An ongoing open source attack reveals roots dating back to 2021, Aug 2023. URL: https: //medium.com/checkmarx-security/an-ongoing -open-source-attack-reveals-roots-dating-b ack-to-2021-4a511979fd98
2021
-
[16]
An empirical study of ma- licious code in pypi ecosystem
Wenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang, Yong Fang, and Yang Liu. An empirical study of ma- licious code in pypi ecosystem. InProceedings of the 38th IEEE/ACM International Conference on Automated Software Engineering, ASE ’23, page 166–177. IEEE Press, 2024.doi:10.1109/ASE56229.2023.00135
-
[17]
Donapi: malicious npm pack- ages detector using behavior sequence knowledge map- ping
Cheng Huang, Nannan Wang, Ziyan Wang, Siqi Sun, Lingzi Li, Junren Chen, Qianchong Zhao, Jiaxuan Han, Zhen Yang, and Lei Shi. Donapi: malicious npm pack- ages detector using behavior sequence knowledge map- ping. InProceedings of the 33rd USENIX Conference on Security Symposium, SEC ’24, USA, 2024. USENIX Association
2024
-
[18]
Sok: History is a vast early warning system: Auditing the provenance of sys- tem intrusions
Muhammad Adil Inam, Yinfang Chen, Akul Goyal, Ja- son Liu, Jaron Mink, Noor Michael, Sneha Gaur, Adam Bates, and Wajih Ul Hassan. Sok: History is a vast early warning system: Auditing the provenance of sys- tem intrusions. In2023 IEEE Symposium on Secu- rity and Privacy (SP), pages 2620–2638, 2023. doi: 10.1109/SP46215.2023.10179405
-
[19]
Orthrus: achieving high quality of attribution in provenance-based intrusion de- tection systems
Baoxiang Jiang, Tristan Bilot, Nour El Madhoun, Khal- doun Al Agha, Anis Zouaoui, Shahrear Iqbal, Xueyuan Han, and Thomas Pasquier. Orthrus: achieving high quality of attribution in provenance-based intrusion de- tection systems. InProceedings of the 34th USENIX Conference on Security Symposium, SEC ’25, USA,
-
[20]
3cx software supply chain com- promise initiated by a prior software supply chain com- promise; suspected north korean actor responsible, Apr
Jeff Johnson, Fred Plan, Adrian Sanchez, Renato Fontana, Jake Nicastro, Dimiter Andonov, Marius Fodor- eanu, and Daniel Scott. 3cx software supply chain com- promise initiated by a prior software supply chain com- promise; suspected north korean actor responsible, Apr
-
[21]
URL: https://cloud.google.com/blog/to pics/threat-intelligence/3cx-software-sup ply-chain-compromise/
-
[22]
What is typosquatting? – definition and explanation
Kaspersky. What is typosquatting? – definition and explanation. URL: https://www.kaspersky.com/re source-center/definitions/what-is-typosqu atting
-
[23]
P. Ladisa, H. Plate, M. Martinez, and O. Barais. Sok: Taxonomy of attacks on open-source software supply chains. In2023 IEEE Symposium on Security and Pri- vacy (SP), pages 1509–1526, Los Alamitos, CA, USA, may 2023. IEEE Computer Society. doi:10.1109/SP 46215.2023.10179304
doi:10.1109/sp 2023
-
[24]
Maintainable Log Datasets for Evaluation of Intrusion Detection Systems
Max Landauer, Florian Skopik, Maximilian Frank, Wolf- gang Hotwagner, Markus Wurzenberger, and Andreas Rauber. Maintainable Log Datasets for Evaluation of Intrusion Detection Systems.IEEE Transactions on Dependable and Secure Computing, 20(4):3466–3482, July 2023. arXiv:2203.08580 [cs]. doi:10.1109/TD SC.2022.3201582
work page internal anchor Pith review Pith/arXiv arXiv doi:10.1109/td 2023
-
[25]
Max Landauer, Florian Skopik, Markus Wurzenberger, Wolfgang Hotwagner, and Andreas Rauber. Have it Your Way: Generating Customized Log Datasets With a Model-Driven Simulation Testbed.IEEE Transactions on Reliability, 70(1):402–415, March 2021. doi:10.1 109/TR.2020.3031317
arXiv 2021
-
[26]
NODLINK: An Online System for Fine-Grained APT Attack Detection and Investigation
Shaofei Li, Feng Dong, Xusheng Xiao, Haoyu Wang, Fei Shao, Jiedong Chen, Yao Guo, Xiangqun Chen, and Ding Li. NODLINK: An Online System for Fine-Grained APT Attack Detection and Investigation. InNetwork and Distributed System Security (NDSS) Symposium 2024. The Internet Society, 2024. doi: 10.14722/ndss.2024.23204
-
[27]
T-trace: Constructing the apts provenance graphs through multiple syslogs correlation
Teng Li, Ximeng Liu, Wei Qiao, Xiongjie Zhu, Yulong Shen, and Jianfeng Ma. T-trace: Constructing the apts provenance graphs through multiple syslogs correlation. IEEE Transactions on Dependable and Secure Comput- ing, 21(3):1179–1195, 2024. doi:10.1109/TDSC.202 3.3273918
-
[28]
Deeppayload: Black-box backdoor at- tack on deep learning models through neural payload in- jection
Yuanchun Li, Jiayi Hua, Haoyu Wang, Chunyang Chen, and Yunxin Liu. Deeppayload: Black-box backdoor at- tack on deep learning models through neural payload in- jection. InProceedings of the 43rd International Confer- ence on Software Engineering, ICSE ’21, page 263–274. IEEE Press, 2021. doi:10.1109/ICSE43902.2021.0 0035
-
[29]
Mario Lins, René Mayrhofer, Michael Roland, Daniel Hofer, and Martin Schwaighofer. On the critical path to implant backdoors and the effectiveness of potential mitigation techniques: Early learnings from xz, 2024. 15 URL: https://arxiv.org/abs/2404.08987 , arXi v:2404.08987
Pith/arXiv arXiv 2024
-
[30]
Carol Lo, Thu Yein Win, Zeinab Rezaeifar, Zaheer Khan, and Phil Legg. Lotl-hunter: Detecting multi-stage living-off-the-land attacks in cyber-physical systems us- ing decision fusion techniques with digital twins.Fu- ture Generation Computer Systems, page 108382, 2026. doi:10.1016/j.future.2026.108382
-
[31]
Mingqi Lv, Shanshan Zhang, Haiwen Liu, Tieming Chen, and Tiantian Zhu. Apt-mcl: An adaptive apt de- tection system based on multi-view collaborative prove- nance graph learning, 2026. URL: https://arxiv.or g/abs/2601.08328,arXiv:2601.08328
arXiv 2026
-
[32]
Special report: Mandiant m-trends 2025,
Mandiant. Special report: Mandiant m-trends 2025,
2025
-
[33]
URL: https://services.google.com/fh/f iles/misc/m-trends-2025-en.pdf
2025
-
[34]
Steganography, Seq
Semilof Margiem and Clark Casey. Steganography, Seq
-
[35]
URL: https://www.techtarget.com/searc hsecurity/definition/steganography#:~:text =Steganography%20is%20the%20technique%20of ,for%20hiding%20or%20protecting%20data
-
[36]
Revisit sequential logic obfuscation: At- tacks and defenses
Travis Meade, Zheng Zhao, Shaojie Zhang, David Pan, and Yier Jin. Revisit sequential logic obfuscation: At- tacks and defenses. In2017 IEEE International Sympo- sium on Circuits and Systems (ISCAS), pages 1–4, 2017. doi:10.1109/ISCAS.2017.8050606
-
[37]
QUT-DV25: A dataset for dynamic analysis of next-gen software supply chain attacks
Sk Tanzir Mehedi, Raja Jurdak, Chadni Islam, and Gowri Sankar Ramachandran. QUT-DV25: A dataset for dynamic analysis of next-gen software supply chain attacks. InThe Thirty-ninth Annual Conference on Neu- ral Information Processing Systems Datasets and Bench- marks Track, 2025. URL: https://openreview.net /forum?id=GR3P9UXqCE
2025
-
[38]
Sowmya Myneni, Kritshekhar Jha, Abdulhakim Sabur, Garima Agrawal, Yuli Deng, Ankur Chowdhary, and Dijiang Huang. Unraveled — a semi-synthetic dataset for advanced persistent threats.Computer Networks, 227:109688, 2023. doi:10.1016/j.comnet.2023.10 9688
-
[39]
Euclides Carlos Pinto Neto, Sajjad Dadkhah, Raphael Ferreira, Alireza Zohourian, Rongxing Lu, and Ali A. Ghorbani. Ciciot2023: A real-time dataset and bench- mark for large-scale attacks in iot environment.Sensors, 23(13), 2023.doi:10.3390/s23135941
-
[40]
Yuqiao Ning, Yanan Zhang, Chao Ma, Zhen Guo, and Longhai Yu. Empirical study of software composition analysis tools for c/c++ binary programs.IEEE Access, 12:50418–50430, 2024. doi:10.1109/ACCESS.2023. 3341224
-
[41]
Backstabber’s Knife Collection: A Review of Open Source Software Supply Chain Attacks, 2020
Marc Ohm, Henrik Plate, Arnold Sykosch, and Michael Meier. Backstabber’s Knife Collection: A Review of Open Source Software Supply Chain Attacks, 2020. ar Xiv:2005.09535
Pith/arXiv arXiv 2020
-
[42]
Springer International Publishing, Cham, 2022
Marwan Omar.Malware Anomaly Detection Using Local Outlier Factor Technique, pages 37–48. Springer International Publishing, Cham, 2022. doi:10.1007/ 978-3-031-15893-3_3
2022
-
[43]
Talha Ongun, Jack W. Stokes, Jonathan Bar Or, Ke Tian, Farid Tajaddodianfar, Joshua Neil, Christian Seifert, Alina Oprea, and John C. Platt. Living-off-the-land command detection using active learning. InProceed- ings of the 24th International Symposium on Research in Attacks, Intrusions and Defenses, RAID ’21, page 442–455, New York, NY , USA, 2021. Asso...
-
[44]
package-analysis: Open source package anal- ysis
OpenSSF. package-analysis: Open source package anal- ysis. https://github.com/ossf/package-analy sis, Feb 2024. Version rel-36 (tag dated 2024-02-21). Accessed: 2026-01-23
2024
-
[45]
OWASP Top 10:2025, 2025
OWASP Top 10 Team. OWASP Top 10:2025, 2025. URL:https://owasp.org/Top10/2025/
2025
-
[46]
npm supply chain at- tack, 2025
Palo Alto Networks, Unit 42. npm supply chain at- tack, 2025. Cloud Security Blog. Accessed: 2026-02-04. URL: https://www.paloaltonetworks.com/blog/ cloud-security/npm-supply-chain-attack/
2025
-
[47]
Striking back at cobalt: Using network traffic metadata to detect cobalt strike masquerading command and control channels
Clément Parssegny, Johan Mazel, Olivier Levillain, and Pierre Chifflier. Striking back at cobalt: Using network traffic metadata to detect cobalt strike masquerading command and control channels. In Mila Dalla Preda, Sebastian Schrittwieser, Vincent Naessens, and Bjorn De Sutter, editors,Availability, Reliability and Security, pages 163–185, Cham, 2025. S...
2025
-
[48]
Hercule: attack story recon- struction via community discovery on correlated log graph
Kexin Pei, Zhongshu Gu, Brendan Saltaformaggio, Shiqing Ma, Fei Wang, Zhiwei Zhang, Luo Si, Xiangyu Zhang, and Dongyan Xu. Hercule: attack story recon- struction via community discovery on correlated log graph. InProceedings of the 32nd Annual Conference on Computer Security Applications, ACSAC ’16, page 583–595, New York, NY , USA, 2016. Association for ...
-
[49]
Homomorphic encrypted yara rules evaluation.J
Diana-Elena Petrean and Rodica Potolea. Homomorphic encrypted yara rules evaluation.J. Inf. Secur. Appl., 82(C), May 2024. doi:10.1016/j.jisa.2024.1037 38. 16
-
[50]
Reversinglabs software supply chain security report
ReversingLabs. Reversinglabs software supply chain security report. https://www.reversinglabs.co m/sscs-report , 2025. Industry report on software supply chain security
2025
-
[51]
Ghorbani
Iman Sharafaldin, Arash Habibi Lashkari, and Ali A. Ghorbani. Toward generating a new intrusion detection dataset and intrusion traffic characterization. InInterna- tional Conference on Information Systems Security and Privacy, 2018
2018
-
[52]
De- tecting Python Malware in the Software Supply Chain with Program Analysis
Ridwan Shariffdeen, Behnaz Hassanshahi, Martin Mirchev, Ali El Husseini, and Abhik Roychoudhury. De- tecting Python Malware in the Software Supply Chain with Program Analysis . In2025 IEEE/ACM 47th Inter- national Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP), pages 203–214, Los Alamitos, CA, USA, May 2025. IEEE Computer...
-
[53]
Detecting Multi-Step IAM attacks in AWS environments via model checking
Ilia Shevrin and Oded Margalit. Detecting Multi-Step IAM attacks in AWS environments via model checking. In32nd USENIX Security Symposium (USENIX Secu- rity 23), pages 6025–6042, Anaheim, CA, August 2023. USENIX Association
2023
-
[54]
Somin Song, Sahil Suneja, Michael V . Le, and Byungchul Tak. On the value of sequence-based system call filtering for container security. In2023 IEEE 16th In- ternational Conference on Cloud Computing (CLOUD), pages 296–307, 2023. doi:10.1109/CLOUD60044.2 023.00043
-
[55]
Yubo Song, Kanghui Wang, Xin Sun, Zhongyuan Qin, Hua Dai, Weiwei Chen, Bang Lv, and Jiaqi Chen. A multi-source log semantic analysis-based attack investi- gation approach.Computers & Security, 150:104303, 2025.doi:10.1016/j.cose.2024.104303
-
[56]
An emerging threat fileless malware: a survey and research challenges.Cybersecu- rity, 3, 2020
Sudhakar and Sushil Kumar. An emerging threat fileless malware: a survey and research challenges.Cybersecu- rity, 3, 2020
2020
-
[57]
Huaqi Sun, Hui Shu, Fei Kang, Yuntian Zhao, and Yuyao Huang. Malware2att&ck: A sophisticated model for mapping malware to att&ck techniques.Computers & Security, 140:103772, 2024. doi:10.1016/j.cose.2 024.103772
-
[58]
Osptrack: A labeled dataset targeting sim- ulated execution of open-source software
Zhuoran Tan, Christos Anagnostopoulos, and Jeremy Singer. Osptrack: A labeled dataset targeting sim- ulated execution of open-source software. In2025 IEEE/ACM 22nd International Conference on Mining Software Repositories (MSR), pages 659–663. IEEE, 2025.doi:10.1109/MSR66628.2025.00102
-
[59]
Zhuoran Tan, Shameem Puthiya Parambath, Chris- tos Anagnostopoulos, Jeremy Singer, and Angelos K. Marnerides. Advanced persistent threats based on sup- ply chain vulnerabilities: Challenges, solutions, and future directions.IEEE Internet of Things Journal, 12(6):6371–6395, 2025. doi:10.1109/JIOT.2025. 3528744
-
[60]
harmless
Lijin Wang, Jingjing Wang, Tianshuo Cong, Xinlei He, Zhan Qin, and Xinyi Huang.From purity to peril: back- dooring merged models from "harmless" benign compo- nents. USENIX Association, USA, 2025
2025
-
[61]
Shad- owlogic: Backdoors in computational graphs
Eoin Wickens, Kasimir Schulz, and Tom Bonner. Shad- owlogic: Backdoors in computational graphs. https: //hiddenlayer.com/innovation-hub/shadowlog ic/#Triggers, October 2024. Accessed: 2025-06-26
2024
-
[62]
Research directions in software supply chain se- curity.ACM Trans
Laurie Williams, Giacomo Benedetti, Sivana Hamer, Ranindya Paramitha, Imranur Rahman, Mahzabin Tamanna, Greg Tystahl, Nusrat Zahan, Patrick Morri- son, Yasemin Acar, Michel Cukier, Christian Kästner, Alexandros Kapravelos, Dominik Wermke, and William Enck. Research directions in software supply chain se- curity.ACM Trans. Softw. Eng. Methodol., 34(5), May...
doi:10.1145/3714464 2025
-
[63]
Ai supply chain security, 2025
Wiz. Ai supply chain security, 2025. Accessed: 2026- 02-04. URL: https://www.wiz.io/academy/ai-s ecurity/ai-supply-chain-security
2025
-
[64]
More than meets the eye: On evaluating sbom tools in java.ACM Trans
Menghan Wu, Yukai Zhao, Xing Hu, Xian Zhan, Shan- ping Li, and Xin Xia. More than meets the eye: On evaluating sbom tools in java.ACM Trans. Softw. Eng. Methodol., September 2025. Just Accepted. doi: 10.1145/3766073
-
[65]
Machine learning attack series: Back- dooring keras models and how to detect it, 2024
wunderwuzzi. Machine learning attack series: Back- dooring keras models and how to detect it, 2024. Ac- cessed: 2025-07-28. URL: https://embracethered. com/blog/posts/2024/machine-learning-attac k-series-keras-backdoor-model/
2024
-
[66]
PROGRAPHER: An anomaly detec- tion system based on provenance graph embedding
Fan Yang, Jiacen Xu, Chunlin Xiong, Zhou Li, and Kehuan Zhang. PROGRAPHER: An anomaly detec- tion system based on provenance graph embedding. In32nd USENIX Security Symposium (USENIX Secu- rity 23), pages 4355–4372, Anaheim, CA, August 2023. USENIX Association
2023
-
[67]
Ugur Yilmaz and Piers Harding. Securing the software supply chain for containers: practices and challenges in a cloud-native landscape for a global observatory. In Jorge Ibsen and Gianluca Chiozzi, editors,Software and Cyberinfrastructure for Astronomy VIII, volume 13101, page 1310114. International Society for Optics and Photonics, SPIE, 2024. doi:10.111...
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.