arXiv:2511.13341cs.SEcs.AI2025-11AAAI被引 2

用大模型评估开源供应链后门风险,发现多个高隐蔽性威胁

An LLM-based Quantitative Framework for Evaluating High-Stealthy Backdoor Risks in OSS Supply Chains

  • 从攻击者视角建模后门各阶段,定义细粒度风险指标
  • 在66个Debian高优先级包中检测到多种隐蔽后门风险
  • 依赖LLM进行语义分析,突破传统静态分析局限

在现代软件开发流程中,开源软件供应链极大提升了工程效率。随着系统复杂度上升,使用开源组件作为第三方依赖已成为普遍做法。然而,底层依赖缺乏维护、社区审计不足,导致源码安全与仓库维护者合法性难以保障,尤其在高隐蔽性后门攻击(如XZ-Util事件)背景下风险凸显。为此,本文提出一种细粒度的开源软件项目后门风险评估框架,从攻击者视角建模隐蔽后门攻击过程,并为每个攻击阶段定义针对性指标。针对静态分析在评估仓库维护行为可靠性(如提交者权限异常提升、评审参与度低)方面的局限,该框架采用大语言模型(LLMs)对代码仓库进行语义评估,无需依赖人工设计的规则模式。框架在Debian生态中66个高优先级包上进行了验证,实验结果表明当前开源软件供应链普遍存在多种安全风险。

原文摘要 · Abstract (English)

In modern software development workflows, the open-source software supply chain contributes significantly to efficient and convenient engineering practices. With increasing system complexity, using open-source software as third-party dependencies has become a common practice. However, the lack of maintenance for underlying dependencies and insufficient community auditing create challenges in ensuring source code security and the legitimacy of repository maintainers, especially under high-stealthy backdoor attacks exemplified by the XZ-Util incident. To address these problems, we propose a fine-grained project evaluation framework for backdoor risk assessment in open-source software. The framework models stealthy backdoor attacks from the viewpoint of the attacker and defines targeted metrics for each attack stage. In addition, to overcome the limitations of static analysis in assessing the reliability of repository maintenance activities such as irregular committer privilege escalation and limited participation in reviews, the framework uses large language models (LLMs) to conduct semantic evaluation of code repositories without relying on manually crafted patterns. The framework is evaluated on sixty six high-priority packages in the Debian ecosystem. The experimental results indicate that the current open-source software supply chain is exposed to various security risks.

开源安全后门检测LLM应用供应链风险

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。