fix: correct AVE-2026-00070 researcher attribution - #182
Merged
Merged
Conversation
researcher was "Saray Chak" / researcher_url bawbel.io despite the record's own references already citing the actual external source: Zhu, Li, Lyu, Sun, Su, Shao, "Collaborative Shadows: Distributed Backdoor Attacks in LLM-Based Multi-Agent Systems" (arXiv:2510.11246). This is the exact misattribution pattern docs/specs/researcher-process.md documents as previously caught and fixed on two other records (the AVE-2026-00060 worked example) -- recurring here, uncaught until now. Verified the paper's real author list against the actual arXiv abstract page (not inferred from the reference text alone): Pengyu Zhu, Lijun Li, Yaxing Lyu, Li Sun, Sen Su, Jing Shao. researcher now credits them by name, researcher_url points at the real arXiv page. No score, severity, mechanism description, or any other field change. Republished via scripts/build-records.js. Revalidated: scripts/validate_records.py (77/77), pytest tests/ (309 passed).
# Conflicts: # dist/ave-records-latest.manifest.json
4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
AVE-2026-00070(Distributed Cross-Agent Backdoor Fragments) listedresearcher: "Saray Chak"/researcher_url: "https://bawbel.io"despite the record's own
referencesarray already citing the actualexternal source it's based on: Zhu, Li, Lyu, Sun, Su, Shao,
"Collaborative Shadows: Distributed Backdoor Attacks in LLM-Based
Multi-Agent Systems" (arXiv:2510.11246).
This is the exact misattribution pattern
docs/specs/researcher-process.md's worked example(
AVE-2026-00060) documents as previously caught and fixed on twoother records — recurring here, uncaught until now. Flagged during an
unrelated review pass, fixed as its own PR rather than folded into
that pass's changes.
Fix
Verified the paper's real author list against the actual arXiv
abstract page (not inferred from the reference text alone):
researcher: "Saray Chak" → "Pengyu Zhu, Lijun Li, Yaxing Lyu, LiSun, Sen Su, Jing Shao"
researcher_url:https://bawbel.io→https://arxiv.org/abs/2510.11246No score, severity, mechanism description, or any other field change.
Checklist
python3 scripts/validate_records.py— 77/77 validpytest tests/ -x -q— 309 passednode scripts/build-records.js