Page 117 - 《软件学报》2026年第7期
P. 117

2802                                                       软件学报  2026  年第  37  卷第  7  期


                      poisoning. arXiv:2410.08811, 2024.
                 [100]   Hu Q, Xie XF, Chen S, Quan LL, Ma L. Large language model supply chain: Open problems from the security perspective. In: Proc. of
                      the 34th ACM SIGSOFT Int’l Symp. on Software Testing and Analysis. Clarion Hotel Trondheim Trondheim: ACM, 2025. 169–173.
                      [doi: 10.1145/3713081.3731747]
                 [101]   Carlini N, Jagielski M, Choquette-Choo CA, Paleka D, Pearce W, Anderson H, Terzis A, Thomas K, Tramèr F. Poisoning Web-scale
                      training datasets is practical. In: Proc. of the 2024 IEEE Symp. on Security and Privacy. San Francisco: IEEE, 2024. 407–425. [doi: 10.
                      1109/SP54263.2024.00179]
                 [102]   Cotroneo D, Improta C, Liguori P, Natella R. Vulnerabilities in AI code generators: Exploring targeted data poisoning attacks. In: Proc.
                      of the 32nd IEEE/ACM Int’l Conf. on Program Comprehension. Lisbon: IEEE, 2024. 280–292.
                 [103]   Xu YC, Yao JR, Shu ML, Sun YC, Wu ZC, Yu N, Goldstein T, Huang FR. Shadowcast: Stealthy data poisoning attacks against vision-
                      language models. In: Proc. of the 38th Int’l Conf. on Neural Information Processing Systems. Vancouver: Curran Associates Inc., 2024.
                      1841.
                 [104]   VassilevA, OpreaA, Fordyce A, Anderson H. Adversarial machine learning: A taxonomy and terminology of attacks and mitigations.
                      2024. https://www.nist.gov/publications/adversarial-machine-learning-taxonomy-and-terminology-attacks-and-mitigations
                 [105]   Amini MH, Moore E. How poisoned data can trick AI, and how to stop it. 2025. https://theconversation.com/how-poisoned-data-can-
                      trick-ai-and-how-to-stop-it-256423
                 [106]   Liu H, Zhou GG, Fu PH, Mao GH. Research of transferring attack based on supply chain network. Computer Science, 2013, 40(7):
                      98–101 (in Chinese with English abstract). [doi: 10.3969/j.issn.1002-137X.2013.07.022]
                 [107]   Torres-Arias  S,  Ammula  AK,  Curtmola  R,  Cappos  J.  On  omitting  commits  and  committing  omissions:  Preventing  git  metadata
                      tampering  that  (re)introduces  software  vulnerabilities.  In:  Proc.  of  the  25th  USENIX  Conf.  on  Security  Symp.  Austin:  USENIX
                      Association, 2016. 379–395.
                 [108]   Boughton L, Miller C, Acar Y, Wermke D, Käastner C. Decomposing and measuring trust in open-source software supply chains. In:
                      Proc. of the 44th ACM/IEEE Int’l Conf. on Software Engineering: New Ideas and Emerging Results (ICSE-NIER 2024). Lisbon: ACM,
                      2024. 57–61. [doi: 10.1145/3639476.3639775]
                 [109]   Federrath IH. Typosquatting in programming language package managers [MS. Thesis]. Hamburg: University of Hamburg, 2016.
                 [110]   Meyers  JS,  Tozer  B.  Bewear!  Python  typosquatting  is  about  more  than  typos.  2020.  https://www.iqt.org/library/bewear-python-
                      typosquatting-is-about-more-than-typos
                 [111]   Birsan  A.  Dependency  confusion:  How  I  hacked  into  Apple,  Microsoft  and  dozens  of  other  companies.  2021.  https://medium.com/
                      @alex.birsan/dependency-confusion-how-i-hacked-into-apple-microsoft-and-dozens-of-other-companies-4a5d60fec610
                 [112]   Ohm M, Plate H, Sykosch A, Meier M. Backstabber‘s knife collection: A review of open source software supply chain attacks. In: Proc.
                      of the 17th Int’l Conf. Detection of Intrusions and Malware, and Vulnerability Assessment. Lisbon: Springer, 2020. 23–43. [doi: 10.
                      1007/978-3-030-52683-2_2]
                 [113]   Truong MT. Typosquatting attacks and mitigations [MS. Thesis]. Sankt Augustin: University of Applied Science, 2023.
                 [114]   GitHub. Cache action. 2025. https://github.com/actions/cache
                 [115]   Khan A. The monsters in your build cache—GitHub actions cache poisoning. 2025. https://adnanthekhan.com/2024/05/06/the-monsters-
                      in-your-build-cache-github-actions-cache-poisoning
                 [116]   Unit42. GitHub actions supply chain attack: A targeted attack on coinbase expanded to the widespread tj-actions/changed-files incident:
                      Threat assessment. 2025. https://unit42.paloaltonetworks.com/github-actions-supply-chain-attack/
                 [117]   CISA.  Russian  foreign  intelligence  service  (SVR)  exploiting  JetBrains  TeamCity  CVE  globally.  2023.  https://www.cisa.gov/news-
                      events/cybersecurity-advisories/aa23-347a
                 [118]   Brian C, Fredrick DL, Jacob W. Attacking the build through cross-build injection. 2007. https://img2.helpnetsecurity.com/dl/articles/
                      fortify_attacking_the_build.pdf
                 [119]   Adobe  Systems  Incorporated.  Security  advisory:  Revocation  of  adobe  code  signing  certificate.  2012.  https://www.adobe.com/
                      support/security/advisories/apsa12-01.html
                 [120]   Mounesan M, Siadati H, Jafarikhah S. Exploring the threat of software supply chain attacks on containerized applications. In: Proc. of
                      the 16th Int’l Conf. on Security of Information and Networks. Jaipur: IEEE, 2023. 1–8. [doi: 10.1109/SIN60469.2023.10474901]
                 [121]   Wang SN, Zhao YJ, Hou XY, Wang HY. Large language model supply chain: A research agenda. ACM Trans. on Software Engineering
                      and Methodology, 2025, 34(5): 147. [doi: 10.1145/3708531]
                 [122]   Huang KF, Chen BH, Lu Y, Wu SS, Wang DJ, Huang YH, Jiang HW, Zhou ZT, Cao JM, Peng X. Lifting the veil on the large language
                      model supply chain: Composition, risks, and mitigations. arXiv:2410.21218v1, 2024.
   112   113   114   115   116   117   118   119   120   121   122