[Paper Review] An LLM-based Quantitative Framework for Evaluating High-Stealthy Backdoor Risks in OSS Supply Chains
VenueAAAI 2026 TitleAn LLM-based Quantitative Framework for Evaluating High-Stealthy Backdoor Risks in OSS Supply Chains AuthorsZihe Yan, Kai Luo, et al. (SJTU / Tsinghua / Tencent Xuanwu Lab) PaperarXiv:2511.13341 DOI10.1609/aaai.v40i2.37116 Codegithub.com/XuanwuLab/HSBRiskEvaluator ForReaders working on supply chain security, Linux distribution dependency governance, or red-team target selection SummaryThe paper breaks a high-stealth backdoor campaign into four stages from an attacker's perspective, then scores repositories with APT dependency data, GitHub community activity, and LLM-assisted semantic analysis. It evaluates 66 high-priority Debian packages with public GitHub repositories and uses xz as a case study. ...