Pith. sign in

REVIEW 2 major objections 67 references

A compact four-pole Purcell filter on a 3D flip-chip platform gives a flat 1 GHz readout passband while suppressing qubit-frequency leakage by more than 45 dB, so resonators can be strongly coupled without paying a Purcell decay penalty.

Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →

T0 review · grok-4.5

2026-07-13 23:34 UTC pith:3CFRUIYJ

load-bearing objection We only have the abstract for the Purcell-filter paper; the attached full text is a different manuscript, so the device claims cannot be checked. the 2 major comments →

arxiv 2603.16693 v2 pith:3CFRUIYJ submitted 2026-03-17 quant-ph

A Compact Broadband Purcell Filter for Superconducting Quantum Circuits in a 3D Flip-Chip Architecture

classification quant-ph
keywords Purcell filtersuperconducting qubitsqubit readout3D flip-chipmultiplexed readoutniobium thin filmexternal quality factorcircuit QED
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

Fast, high-fidelity qubit readout needs strong resonator–feedline coupling, but that same coupling opens a decay path for the qubit through the Purcell effect. This paper presents a four-pole broadband Purcell filter built in a 3D flip-chip architecture that separates those demands: it passes a flat 1 GHz band centered at 7.68 GHz for readout while providing more than 45 dB suppression at typical qubit frequencies. A test chip with six floating readout resonators shows the filter still supports strong multiplexed coupling inside the passband. The devices are made in a 150 nm niobium process and measured at 20 mK. An analytical model maps filter response and each floating resonator’s frequency and external quality factor straight from geometry, so designs can be synthesized and optimized without heavy simulation. The authors argue the layout is compact and fabrication-tolerant enough for large-scale superconducting processors.

Core claim

A four-pole broadband Purcell filter implemented on a 3D flip-chip platform delivers a flat 1 GHz passband at 7.68 GHz with more than 45 dB stopband suppression at qubit frequencies, remains compatible with strong multiplexed coupling of six floating readout resonators, and is accurately described by a geometry-based analytical model of filter response and resonator resonance frequency and external quality factor.

What carries the argument

The four-pole broadband Purcell filter in 3D flip-chip form, plus the analytical model that predicts filter S-parameters and floating-resonator f_r and Q_ext directly from physical geometry, enabling rapid circuit synthesis without full-wave redesign at every step.

Load-bearing premise

That the measured passband flatness, stopband suppression, and strong multiplexed coupling on this single niobium test chip at 20 mK will still hold under real multi-qubit loading, packaging parasitics, and fabrication spread without reopening Purcell-limited decay or readout crosstalk.

What would settle it

Fabricate and cool a multi-qubit flip-chip processor that uses this filter with several strongly coupled readout resonators, measure qubit T1 versus filter-predicted Purcell rate and multiplexed readout fidelity/crosstalk across the 1 GHz band, and check whether suppression stays above 45 dB and T1 is not Purcell-limited once packaging and full loading are present.

Watch this falsifier. Get emailed when new claim-graph text bears on it.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, simulated authors' rebuttal, and a circularity audit.

Referee Report

2 major / 0 minor

Summary. The manuscript claims a four-pole broadband Purcell filter in a 3D flip-chip architecture that delivers a flat ~1 GHz passband centered at 7.68 GHz with >45 dB stopband suppression at typical qubit frequencies, while remaining compatible with strong multiplexed coupling of six floating readout resonators on a 150 nm Nb test chip measured at 20 mK. An analytical geometry-based model is said to predict filter response and the resonators’ resonance frequencies and external quality factors, enabling rapid synthesis. The design is presented as compact and fabrication-tolerant for large-scale superconducting processors. The supplied full-text body, however, is an unrelated cs.CR paper (SynthChain) and contains none of the filter design, S-parameter data, model equations, or cryogenic results.

Significance. If the abstract claims hold under multi-qubit loading and realistic packaging, a compact, broadband, geometry-predictable Purcell filter that preserves strong resonator–feedline coupling would be a practically useful building block for multiplexed readout in 3D flip-chip quantum processors. The combination of a four-pole response, floating resonators, and an analytical model that maps geometry directly to f_r and Q_ext would be a genuine engineering contribution. Because the matching technical body is absent from the review package, these strengths cannot be verified or credited on the basis of measured data or derivations.

major comments (2)
  1. The review package supplies only the abstract of arXiv:2603.16693; the full manuscript text is the unrelated SynthChain paper (arXiv:2603.16694). Consequently there are no filter schematics, pole-placement equations, measured S-parameters, model-vs-data residuals, Q_ext values, or 20 mK characterization results against which the central claims (>45 dB suppression, 1 GHz flat passband, geometry-based prediction of resonator parameters) can be checked. Load-bearing technical assessment is impossible until the correct body is provided.
  2. Even taking the abstract at face value, the generalization claim—that the reported stopband suppression and strong multiplexed coupling remain valid under realistic multi-qubit loading, packaging parasitics, and fabrication spread—cannot be evaluated without the missing measurement and modeling sections. This is a load-bearing assumption for the “practical solution for large-scale processors” conclusion.

Circularity Check

0 steps flagged

No circularity identifiable: abstract claims are experimental/geometry-based, and the provided full text is the wrong paper.

full rationale

The target abstract (arXiv:2603.16693) presents a four-pole Purcell filter with measured passband/stopband performance and an analytical model that maps resonator geometry to f_r and Q_ext. Those claims are not self-definitional: filter S-parameters and resonator parameters are physical observables, and a geometry-to-response model is a standard independent mapping if checked against measurement. The CACHEABLE full manuscript text is an unrelated cs.CR paper (SynthChain), so no load-bearing equations, fits, or self-citation chains from the Purcell-filter derivation can be quoted or reduced. With no exhibit of Eq. X = Eq. Y by construction, fitted inputs renamed as predictions, or uniqueness imported from overlapping authors, circularity cannot be asserted. Score 0 is the correct honest non-finding under the hard rule that circularity requires a quotable specific reduction.

Axiom & Free-Parameter Ledger

2 free parameters · 3 axioms · 1 invented entities

Abstract-only review of a microwave quantum-hardware paper. Load-bearing background is standard circuit-QED and microwave filter physics; free parameters and invented entities cannot be exhaustively extracted without the real body. Listed items are those the abstract itself makes the claim rest on.

free parameters (2)
  • Filter center frequency / pole placement (7.68 GHz, 1 GHz passband)
    Design targets chosen for the readout band; abstract does not show whether they are fixed by first principles or tuned to hardware constraints.
  • External quality factors of floating resonators
    Strong coupling within the passband is a design choice; Q_ext values are set by geometry and coupling strength and would be fitted or targeted in synthesis.
axioms (3)
  • domain assumption Strong resonator–feedline coupling improves readout speed/fidelity but increases Purcell decay of the qubit unless filtered.
    Standard circuit-QED premise stated in the abstract as the trade-off the filter overcomes.
  • domain assumption A four-pole microwave filter response can provide a flat passband at readout frequencies and deep stopband at qubit frequencies in a flip-chip stack.
    Assumes filter theory and packaging parasitics allow the claimed isolation without spoiling resonators.
  • ad hoc to paper Resonance frequencies and external quality factors of floating resonators are determined accurately enough from physical geometry via the authors’ analytical model.
    Abstract claims this model enables rapid synthesis; validity is internal to the paper’s contribution.
invented entities (1)
  • Four-pole broadband Purcell filter in 3D flip-chip architecture (this design instance) no independent evidence
    purpose: Enable strong multiplexed readout coupling while suppressing Purcell decay
    The specific compact filter implementation is the paper’s engineered object; not a new fundamental particle or force, but a new device instance whose independent evidence would be measured S-parameters and qubit T1 with/without filter.

pith-pipeline@v1.1.0-grok45 · 25687 in / 2699 out tokens · 29839 ms · 2026-07-13T23:34:47.451905+00:00 · methodology

0 comments
read the original abstract

Fast and high-fidelity qubit readout requires strong coupling between the readout resonator and the feedline. However, such coupling unavoidably enhances qubit decay through the Purcell effect. We present a four-pole broadband Purcell filter implemented on a 3D flip-chip platform to overcome this trade-off. The filter provides a flat 1 GHz passband centered at 7.68 GHz and achieves more than 45 dB suppression at typical qubit frequencies. We demonstrate the filter's compatibility with multiplexed readout using a test chip that integrates six floating readout resonators strongly coupled within the passband. The chip is fabricated using a 150 nm Niobium (Nb) thin-film process and characterized at 20 mK in a cryogenic measurement setup. We also develop an analytical model that accurately captures the filter response and determines the resonance frequencies and external quality factors of the floating resonators directly from their physical geometry, enabling rapid circuit synthesis and design optimization. The proposed design is compact and fabrication-tolerant, making it a practical solution for large-scale superconducting quantum processors.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Reference graph

Works this paper leans on

67 extracted references · 15 canonical work pages · 1 internal anchor

  1. [1]

    shai-hulud

    Unit 42. "shai-hulud" worm compromises npm ecosys- tem in supply chain attack. Technical report, Palo Alto Networks, September 2025. Technical alert / threat re- search report. URL: https://unit42.paloaltonet works.com/npm-supply-chain-attack/

  2. [2]

    Secret-based cloud supply-chain attacks: Case study and lessons for security teams, Dec 2022

    Schindel Alon and Tamari Shir. Secret-based cloud supply-chain attacks: Case study and lessons for security teams, Dec 2022. URL: https://www.wiz.io/blog/ secret-based-cloud-supply-chain-attacks-c ase-study-and-lessons-for-security-teams

  3. [3]

    Collecting telemetry data on macos using ap- ple’s endpoint security, 2025

    Apriorit. Collecting telemetry data on macos using ap- ple’s endpoint security, 2025. Describes macOS teleme- try collection mechanisms and their usage challenges. URL: https://www.apriorit.com/dev-blog/coll ecting-telemetry-data-on-macos-using-endpo int-security

  4. [4]

    Operationally transparent cyber (optc), 2021

    Rody Arantes, Carl Weir, Henry Hannon, and Marisha Kulseng. Operationally transparent cyber (optc), 2021. doi:10.21227/edq8-nk52

  5. [5]

    Exorcist: Automated Differen- tial Analysis to Detect Compromises in Closed-Source Software Supply Chains

    Frederick Barr-Smith, Tim Blazytko, Richard Baker, and Ivan Martinovic. Exorcist: Automated Differen- tial Analysis to Detect Compromises in Closed-Source Software Supply Chains. InProceedings of the 2022 ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses, pages 51–61, Los Angeles CA USA, 2022. ACM

  6. [6]

    Kairos: Practical intrusion detection and investigation using whole-system provenance.2024 IEEE Symposium on Security and Privacy (SP), pages 3533–3551, 2023

    Zijun Cheng, Qiujian Lv, Jinyuan Liang, Yan Wang, De- gang Sun, Thomas Pasquier, and Xueyuan Han. Kairos: Practical intrusion detection and investigation using whole-system provenance.2024 IEEE Symposium on Security and Privacy (SP), pages 3533–3551, 2023

  7. [7]

    Crowdstrike threat hunting report

    CrowdStrike. Crowdstrike threat hunting report. https: //www.crowdstrike.com/en-gb/resources/repo rts/threat-hunting-report/, 2025. Annual threat intelligence and hunting report

  8. [8]

    Ghorbani

    Sajjad Dadkhah, Xichen Zhang, Alexander Gerald Weis- mann, Amir Firouzi, and Ali A. Ghorbani. The largest social media ground-truth dataset for real/fake con- tent: Truthseeker.IEEE Transactions on Computa- tional Social Systems, 11(3):3376–3390, 2024. doi: 10.1109/TCSS.2023.3322303

  9. [9]

    Information security continuous monitoring (iscm) for federal information systems and organizations (sp 800-137)

    Kelley Dempsey et al. Information security continuous monitoring (iscm) for federal information systems and organizations (sp 800-137). Technical report, National Institute of Standards and Technology, 2011. URL: ht tps://csrc.nist.gov/pubs/sp/800/137/final

  10. [10]

    A new method for detecting beaconing attacks in iot-based scada systems.Int

    Ferdi Do˘gan, Onur Polat, and Fahri Yardimci. A new method for detecting beaconing attacks in iot-based scada systems.Int. J. Inf. Secur., 24(6), November 2025. doi:10.1007/s10207-025-01161-6

  11. [11]

    Openssf malicious packages

    Open Source Security Foundation. Openssf malicious packages. https://github.com/ossf/maliciou s-packages/, 2024

  12. [12]

    Python packages leverage github to deploy fileless malware, Dec 2022

    Yehuda Gelb. Python packages leverage github to deploy fileless malware, Dec 2022. URL: https: //medium.com/checkmarx-security/python-p ackages-leverage-github-to-deploy-fileles s-malware-b6c281dea58f#:~:text=In%20early% 20December%2C%20a%20number,cleverness%20of %20their%20deployment%20strategy. 14

  13. [13]

    Attacker hidden in plain sight for nearly six months, targeting python developers, Nov 2023

    Yehuda Gelb. Attacker hidden in plain sight for nearly six months, targeting python developers, Nov 2023. URL: https://medium.com/checkmarx-securit y/attacker-hidden-in-plain-sight-for-nearl y-six-months-targeting-python-developers-3 712f0f107e0

  14. [14]

    Lazarus group launches first open source supply chain attacks targeting crypto sector, Aug 2023

    Yehuda Gelb. Lazarus group launches first open source supply chain attacks targeting crypto sector, Aug 2023. URL: https://medium.com/checkmarx-security/ lazarus-group-launches-first-open-source-s upply-chain-attacks-targeting-crypto-secto r-cabc626e404e

  15. [15]

    An ongoing open source attack reveals roots dating back to 2021, Aug 2023

    Yehuda Gelb. An ongoing open source attack reveals roots dating back to 2021, Aug 2023. URL: https: //medium.com/checkmarx-security/an-ongoing -open-source-attack-reveals-roots-dating-b ack-to-2021-4a511979fd98

  16. [16]

    An empirical study of ma- licious code in pypi ecosystem

    Wenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang, Yong Fang, and Yang Liu. An empirical study of ma- licious code in pypi ecosystem. InProceedings of the 38th IEEE/ACM International Conference on Automated Software Engineering, ASE ’23, page 166–177. IEEE Press, 2024.doi:10.1109/ASE56229.2023.00135

  17. [17]

    Donapi: malicious npm pack- ages detector using behavior sequence knowledge map- ping

    Cheng Huang, Nannan Wang, Ziyan Wang, Siqi Sun, Lingzi Li, Junren Chen, Qianchong Zhao, Jiaxuan Han, Zhen Yang, and Lei Shi. Donapi: malicious npm pack- ages detector using behavior sequence knowledge map- ping. InProceedings of the 33rd USENIX Conference on Security Symposium, SEC ’24, USA, 2024. USENIX Association

  18. [18]

    Sok: History is a vast early warning system: Auditing the provenance of sys- tem intrusions

    Muhammad Adil Inam, Yinfang Chen, Akul Goyal, Ja- son Liu, Jaron Mink, Noor Michael, Sneha Gaur, Adam Bates, and Wajih Ul Hassan. Sok: History is a vast early warning system: Auditing the provenance of sys- tem intrusions. In2023 IEEE Symposium on Secu- rity and Privacy (SP), pages 2620–2638, 2023. doi: 10.1109/SP46215.2023.10179405

  19. [19]

    Orthrus: achieving high quality of attribution in provenance-based intrusion de- tection systems

    Baoxiang Jiang, Tristan Bilot, Nour El Madhoun, Khal- doun Al Agha, Anis Zouaoui, Shahrear Iqbal, Xueyuan Han, and Thomas Pasquier. Orthrus: achieving high quality of attribution in provenance-based intrusion de- tection systems. InProceedings of the 34th USENIX Conference on Security Symposium, SEC ’25, USA,

  20. [20]

    3cx software supply chain com- promise initiated by a prior software supply chain com- promise; suspected north korean actor responsible, Apr

    Jeff Johnson, Fred Plan, Adrian Sanchez, Renato Fontana, Jake Nicastro, Dimiter Andonov, Marius Fodor- eanu, and Daniel Scott. 3cx software supply chain com- promise initiated by a prior software supply chain com- promise; suspected north korean actor responsible, Apr

  21. [21]

    URL: https://cloud.google.com/blog/to pics/threat-intelligence/3cx-software-sup ply-chain-compromise/

  22. [22]

    What is typosquatting? – definition and explanation

    Kaspersky. What is typosquatting? – definition and explanation. URL: https://www.kaspersky.com/re source-center/definitions/what-is-typosqu atting

  23. [23]

    Ladisa, H

    P. Ladisa, H. Plate, M. Martinez, and O. Barais. Sok: Taxonomy of attacks on open-source software supply chains. In2023 IEEE Symposium on Security and Pri- vacy (SP), pages 1509–1526, Los Alamitos, CA, USA, may 2023. IEEE Computer Society. doi:10.1109/SP 46215.2023.10179304

  24. [24]

    Maintainable Log Datasets for Evaluation of Intrusion Detection Systems

    Max Landauer, Florian Skopik, Maximilian Frank, Wolf- gang Hotwagner, Markus Wurzenberger, and Andreas Rauber. Maintainable Log Datasets for Evaluation of Intrusion Detection Systems.IEEE Transactions on Dependable and Secure Computing, 20(4):3466–3482, July 2023. arXiv:2203.08580 [cs]. doi:10.1109/TD SC.2022.3201582

  25. [25]

    Have it Your Way: Generating Customized Log Datasets With a Model-Driven Simulation Testbed.IEEE Transactions on Reliability, 70(1):402–415, March 2021

    Max Landauer, Florian Skopik, Markus Wurzenberger, Wolfgang Hotwagner, and Andreas Rauber. Have it Your Way: Generating Customized Log Datasets With a Model-Driven Simulation Testbed.IEEE Transactions on Reliability, 70(1):402–415, March 2021. doi:10.1 109/TR.2020.3031317

  26. [26]

    NODLINK: An Online System for Fine-Grained APT Attack Detection and Investigation

    Shaofei Li, Feng Dong, Xusheng Xiao, Haoyu Wang, Fei Shao, Jiedong Chen, Yao Guo, Xiangqun Chen, and Ding Li. NODLINK: An Online System for Fine-Grained APT Attack Detection and Investigation. InNetwork and Distributed System Security (NDSS) Symposium 2024. The Internet Society, 2024. doi: 10.14722/ndss.2024.23204

  27. [27]

    T-trace: Constructing the apts provenance graphs through multiple syslogs correlation

    Teng Li, Ximeng Liu, Wei Qiao, Xiongjie Zhu, Yulong Shen, and Jianfeng Ma. T-trace: Constructing the apts provenance graphs through multiple syslogs correlation. IEEE Transactions on Dependable and Secure Comput- ing, 21(3):1179–1195, 2024. doi:10.1109/TDSC.202 3.3273918

  28. [28]

    Deeppayload: Black-box backdoor at- tack on deep learning models through neural payload in- jection

    Yuanchun Li, Jiayi Hua, Haoyu Wang, Chunyang Chen, and Yunxin Liu. Deeppayload: Black-box backdoor at- tack on deep learning models through neural payload in- jection. InProceedings of the 43rd International Confer- ence on Software Engineering, ICSE ’21, page 263–274. IEEE Press, 2021. doi:10.1109/ICSE43902.2021.0 0035

  29. [29]

    On the critical path to implant backdoors and the effectiveness of potential mitigation techniques: Early learnings from xz, 2024

    Mario Lins, René Mayrhofer, Michael Roland, Daniel Hofer, and Martin Schwaighofer. On the critical path to implant backdoors and the effectiveness of potential mitigation techniques: Early learnings from xz, 2024. 15 URL: https://arxiv.org/abs/2404.08987 , arXi v:2404.08987

  30. [30]

    Carol Lo, Thu Yein Win, Zeinab Rezaeifar, Zaheer Khan, and Phil Legg. Lotl-hunter: Detecting multi-stage living-off-the-land attacks in cyber-physical systems us- ing decision fusion techniques with digital twins.Fu- ture Generation Computer Systems, page 108382, 2026. doi:10.1016/j.future.2026.108382

  31. [31]

    Apt-mcl: An adaptive apt de- tection system based on multi-view collaborative prove- nance graph learning, 2026

    Mingqi Lv, Shanshan Zhang, Haiwen Liu, Tieming Chen, and Tiantian Zhu. Apt-mcl: An adaptive apt de- tection system based on multi-view collaborative prove- nance graph learning, 2026. URL: https://arxiv.or g/abs/2601.08328,arXiv:2601.08328

  32. [32]

    Special report: Mandiant m-trends 2025,

    Mandiant. Special report: Mandiant m-trends 2025,

  33. [33]

    URL: https://services.google.com/fh/f iles/misc/m-trends-2025-en.pdf

  34. [34]

    Steganography, Seq

    Semilof Margiem and Clark Casey. Steganography, Seq

  35. [35]

    URL: https://www.techtarget.com/searc hsecurity/definition/steganography#:~:text =Steganography%20is%20the%20technique%20of ,for%20hiding%20or%20protecting%20data

  36. [36]

    Revisit sequential logic obfuscation: At- tacks and defenses

    Travis Meade, Zheng Zhao, Shaojie Zhang, David Pan, and Yier Jin. Revisit sequential logic obfuscation: At- tacks and defenses. In2017 IEEE International Sympo- sium on Circuits and Systems (ISCAS), pages 1–4, 2017. doi:10.1109/ISCAS.2017.8050606

  37. [37]

    QUT-DV25: A dataset for dynamic analysis of next-gen software supply chain attacks

    Sk Tanzir Mehedi, Raja Jurdak, Chadni Islam, and Gowri Sankar Ramachandran. QUT-DV25: A dataset for dynamic analysis of next-gen software supply chain attacks. InThe Thirty-ninth Annual Conference on Neu- ral Information Processing Systems Datasets and Bench- marks Track, 2025. URL: https://openreview.net /forum?id=GR3P9UXqCE

  38. [38]

    Unraveled — a semi-synthetic dataset for advanced persistent threats.Computer Networks, 227:109688, 2023

    Sowmya Myneni, Kritshekhar Jha, Abdulhakim Sabur, Garima Agrawal, Yuli Deng, Ankur Chowdhary, and Dijiang Huang. Unraveled — a semi-synthetic dataset for advanced persistent threats.Computer Networks, 227:109688, 2023. doi:10.1016/j.comnet.2023.10 9688

  39. [39]

    Ghorbani

    Euclides Carlos Pinto Neto, Sajjad Dadkhah, Raphael Ferreira, Alireza Zohourian, Rongxing Lu, and Ali A. Ghorbani. Ciciot2023: A real-time dataset and bench- mark for large-scale attacks in iot environment.Sensors, 23(13), 2023.doi:10.3390/s23135941

  40. [40]

    Empirical study of software composition analysis tools for c/c++ binary programs.IEEE Access, 12:50418–50430, 2024

    Yuqiao Ning, Yanan Zhang, Chao Ma, Zhen Guo, and Longhai Yu. Empirical study of software composition analysis tools for c/c++ binary programs.IEEE Access, 12:50418–50430, 2024. doi:10.1109/ACCESS.2023. 3341224

  41. [41]

    Backstabber’s Knife Collection: A Review of Open Source Software Supply Chain Attacks, 2020

    Marc Ohm, Henrik Plate, Arnold Sykosch, and Michael Meier. Backstabber’s Knife Collection: A Review of Open Source Software Supply Chain Attacks, 2020. ar Xiv:2005.09535

  42. [42]

    Springer International Publishing, Cham, 2022

    Marwan Omar.Malware Anomaly Detection Using Local Outlier Factor Technique, pages 37–48. Springer International Publishing, Cham, 2022. doi:10.1007/ 978-3-031-15893-3_3

  43. [43]

    Stokes, Jonathan Bar Or, Ke Tian, Farid Tajaddodianfar, Joshua Neil, Christian Seifert, Alina Oprea, and John C

    Talha Ongun, Jack W. Stokes, Jonathan Bar Or, Ke Tian, Farid Tajaddodianfar, Joshua Neil, Christian Seifert, Alina Oprea, and John C. Platt. Living-off-the-land command detection using active learning. InProceed- ings of the 24th International Symposium on Research in Attacks, Intrusions and Defenses, RAID ’21, page 442–455, New York, NY , USA, 2021. Asso...

  44. [44]

    package-analysis: Open source package anal- ysis

    OpenSSF. package-analysis: Open source package anal- ysis. https://github.com/ossf/package-analy sis, Feb 2024. Version rel-36 (tag dated 2024-02-21). Accessed: 2026-01-23

  45. [45]

    OWASP Top 10:2025, 2025

    OWASP Top 10 Team. OWASP Top 10:2025, 2025. URL:https://owasp.org/Top10/2025/

  46. [46]

    npm supply chain at- tack, 2025

    Palo Alto Networks, Unit 42. npm supply chain at- tack, 2025. Cloud Security Blog. Accessed: 2026-02-04. URL: https://www.paloaltonetworks.com/blog/ cloud-security/npm-supply-chain-attack/

  47. [47]

    Striking back at cobalt: Using network traffic metadata to detect cobalt strike masquerading command and control channels

    Clément Parssegny, Johan Mazel, Olivier Levillain, and Pierre Chifflier. Striking back at cobalt: Using network traffic metadata to detect cobalt strike masquerading command and control channels. In Mila Dalla Preda, Sebastian Schrittwieser, Vincent Naessens, and Bjorn De Sutter, editors,Availability, Reliability and Security, pages 163–185, Cham, 2025. S...

  48. [48]

    Hercule: attack story recon- struction via community discovery on correlated log graph

    Kexin Pei, Zhongshu Gu, Brendan Saltaformaggio, Shiqing Ma, Fei Wang, Zhiwei Zhang, Luo Si, Xiangyu Zhang, and Dongyan Xu. Hercule: attack story recon- struction via community discovery on correlated log graph. InProceedings of the 32nd Annual Conference on Computer Security Applications, ACSAC ’16, page 583–595, New York, NY , USA, 2016. Association for ...

  49. [49]

    Homomorphic encrypted yara rules evaluation.J

    Diana-Elena Petrean and Rodica Potolea. Homomorphic encrypted yara rules evaluation.J. Inf. Secur. Appl., 82(C), May 2024. doi:10.1016/j.jisa.2024.1037 38. 16

  50. [50]

    Reversinglabs software supply chain security report

    ReversingLabs. Reversinglabs software supply chain security report. https://www.reversinglabs.co m/sscs-report , 2025. Industry report on software supply chain security

  51. [51]

    Ghorbani

    Iman Sharafaldin, Arash Habibi Lashkari, and Ali A. Ghorbani. Toward generating a new intrusion detection dataset and intrusion traffic characterization. InInterna- tional Conference on Information Systems Security and Privacy, 2018

  52. [52]

    De- tecting Python Malware in the Software Supply Chain with Program Analysis

    Ridwan Shariffdeen, Behnaz Hassanshahi, Martin Mirchev, Ali El Husseini, and Abhik Roychoudhury. De- tecting Python Malware in the Software Supply Chain with Program Analysis . In2025 IEEE/ACM 47th Inter- national Conference on Software Engineering: Software Engineering in Practice (ICSE-SEIP), pages 203–214, Los Alamitos, CA, USA, May 2025. IEEE Computer...

  53. [53]

    Detecting Multi-Step IAM attacks in AWS environments via model checking

    Ilia Shevrin and Oded Margalit. Detecting Multi-Step IAM attacks in AWS environments via model checking. In32nd USENIX Security Symposium (USENIX Secu- rity 23), pages 6025–6042, Anaheim, CA, August 2023. USENIX Association

  54. [54]

    Le, and Byungchul Tak

    Somin Song, Sahil Suneja, Michael V . Le, and Byungchul Tak. On the value of sequence-based system call filtering for container security. In2023 IEEE 16th In- ternational Conference on Cloud Computing (CLOUD), pages 296–307, 2023. doi:10.1109/CLOUD60044.2 023.00043

  55. [55]

    A multi-source log semantic analysis-based attack investi- gation approach.Computers & Security, 150:104303, 2025.doi:10.1016/j.cose.2024.104303

    Yubo Song, Kanghui Wang, Xin Sun, Zhongyuan Qin, Hua Dai, Weiwei Chen, Bang Lv, and Jiaqi Chen. A multi-source log semantic analysis-based attack investi- gation approach.Computers & Security, 150:104303, 2025.doi:10.1016/j.cose.2024.104303

  56. [56]

    An emerging threat fileless malware: a survey and research challenges.Cybersecu- rity, 3, 2020

    Sudhakar and Sushil Kumar. An emerging threat fileless malware: a survey and research challenges.Cybersecu- rity, 3, 2020

  57. [57]

    Malware2att&ck: A sophisticated model for mapping malware to att&ck techniques.Computers & Security, 140:103772, 2024

    Huaqi Sun, Hui Shu, Fei Kang, Yuntian Zhao, and Yuyao Huang. Malware2att&ck: A sophisticated model for mapping malware to att&ck techniques.Computers & Security, 140:103772, 2024. doi:10.1016/j.cose.2 024.103772

  58. [58]

    Osptrack: A labeled dataset targeting sim- ulated execution of open-source software

    Zhuoran Tan, Christos Anagnostopoulos, and Jeremy Singer. Osptrack: A labeled dataset targeting sim- ulated execution of open-source software. In2025 IEEE/ACM 22nd International Conference on Mining Software Repositories (MSR), pages 659–663. IEEE, 2025.doi:10.1109/MSR66628.2025.00102

  59. [59]

    Marnerides

    Zhuoran Tan, Shameem Puthiya Parambath, Chris- tos Anagnostopoulos, Jeremy Singer, and Angelos K. Marnerides. Advanced persistent threats based on sup- ply chain vulnerabilities: Challenges, solutions, and future directions.IEEE Internet of Things Journal, 12(6):6371–6395, 2025. doi:10.1109/JIOT.2025. 3528744

  60. [60]

    harmless

    Lijin Wang, Jingjing Wang, Tianshuo Cong, Xinlei He, Zhan Qin, and Xinyi Huang.From purity to peril: back- dooring merged models from "harmless" benign compo- nents. USENIX Association, USA, 2025

  61. [61]

    Shad- owlogic: Backdoors in computational graphs

    Eoin Wickens, Kasimir Schulz, and Tom Bonner. Shad- owlogic: Backdoors in computational graphs. https: //hiddenlayer.com/innovation-hub/shadowlog ic/#Triggers, October 2024. Accessed: 2025-06-26

  62. [62]

    Research directions in software supply chain se- curity.ACM Trans

    Laurie Williams, Giacomo Benedetti, Sivana Hamer, Ranindya Paramitha, Imranur Rahman, Mahzabin Tamanna, Greg Tystahl, Nusrat Zahan, Patrick Morri- son, Yasemin Acar, Michel Cukier, Christian Kästner, Alexandros Kapravelos, Dominik Wermke, and William Enck. Research directions in software supply chain se- curity.ACM Trans. Softw. Eng. Methodol., 34(5), May...

  63. [63]

    Ai supply chain security, 2025

    Wiz. Ai supply chain security, 2025. Accessed: 2026- 02-04. URL: https://www.wiz.io/academy/ai-s ecurity/ai-supply-chain-security

  64. [64]

    More than meets the eye: On evaluating sbom tools in java.ACM Trans

    Menghan Wu, Yukai Zhao, Xing Hu, Xian Zhan, Shan- ping Li, and Xin Xia. More than meets the eye: On evaluating sbom tools in java.ACM Trans. Softw. Eng. Methodol., September 2025. Just Accepted. doi: 10.1145/3766073

  65. [65]

    Machine learning attack series: Back- dooring keras models and how to detect it, 2024

    wunderwuzzi. Machine learning attack series: Back- dooring keras models and how to detect it, 2024. Ac- cessed: 2025-07-28. URL: https://embracethered. com/blog/posts/2024/machine-learning-attac k-series-keras-backdoor-model/

  66. [66]

    PROGRAPHER: An anomaly detec- tion system based on provenance graph embedding

    Fan Yang, Jiacen Xu, Chunlin Xiong, Zhou Li, and Kehuan Zhang. PROGRAPHER: An anomaly detec- tion system based on provenance graph embedding. In32nd USENIX Security Symposium (USENIX Secu- rity 23), pages 4355–4372, Anaheim, CA, August 2023. USENIX Association

  67. [67]

    evidence supports this phase

    Ugur Yilmaz and Piers Harding. Securing the software supply chain for containers: practices and challenges in a cloud-native landscape for a global observatory. In Jorge Ibsen and Gianluca Chiozzi, editors,Software and Cyberinfrastructure for Astronomy VIII, volume 13101, page 1310114. International Society for Optics and Photonics, SPIE, 2024. doi:10.111...