Skip to content

fix: researcher-attribution audit across the corpus (49 of 50) - #205

Merged
chaksaray merged 4 commits into
developfrom
fix/researcher-attribution-audit
Aug 26, 2026
Merged

chaksaray merged 4 commits into
developfrom
fix/researcher-attribution-audit

Conversation

@chaksaray

Copy link
Copy Markdown
Contributor

Follow-up to #202, which flagged that AVE-2026-00048 was one of many records still carrying the deprecated Bawbel Security Research Team convention — 50 of 80 records, not the single miss its own premise assumed.

Standard applied: same as #202/#48 — a cited reference only justifies crediting its author as researcher if it genuinely, specifically describes this record's particular mechanism, not merely the broader category it sits in. Several papers (Greshake 2023, Perez 2022, Cohen 2024) repeat across many structurally distinct records as foundational/background citations — a single indirect-prompt-injection paper can't be the specific origin of a dozen different narrow behavioral variants it never names.

Results, all 50 checked individually:

  • 44 records: AVE's own synthesis — either only generic framework citations (CWE/OWASP/MITRE/RFC/MCP spec), or a cited paper whose confirmed scope doesn't match the record's specific mechanism. Corrected to Saray Chak.
  • 5 records: verified, specific external source confirmed —
    • AVE-2026-00007, AVE-2026-00015 → Perez & Ribeiro (arXiv 2211.09527), whose own named contributions are literally "goal hijacking" and "prompt leaking"
    • AVE-2026-00016 → Zou et al. (PoisonedRAG, arXiv 2402.07867), confirmed to describe injecting malicious text into a RAG knowledge base retrieved as trusted context — a direct match
    • AVE-2026-00059 → Liu et al. (ShareLock, arXiv 2606.27027), confirmed real, with an exact attack-success-rate match to the record's own reference text
    • AVE-2026-00065 → Kumar Aditya (Keysight ATI), confirmed real via his own published blog post naming him as lead researcher
  • 1 record left unchanged: AVE-2026-00020 (cross-agent A2A injection). Cohen et al.'s worm-propagation mechanism is a plausible but not clean match — flagged as genuinely ambiguous rather than decided unilaterally.

All 80 records still validate, fixtures intact, full suite passes.

chaksaray and others added 4 commits August 23, 2026 16:07
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: chaksaray <15962335+chaksaray@users.noreply.github.com>
# Conflicts:
#	records/AVE-2026-00048.json
Follow-up to #202, which flagged that AVE-2026-00048 was one of many
records still carrying the deprecated 'Bawbel Security Research Team'
convention -- 50 of 80 records, not the single miss its own premise
assumed.

Applied the same standard used on #202 and #48: a cited reference only
justifies crediting its author as researcher if it genuinely, specifically
describes THIS record's particular mechanism, not merely the broader
category it sits in. Several papers (Greshake 2023, Perez 2022, Cohen
2024) repeat across many structurally distinct records as foundational/
background citations -- a single indirect-prompt-injection paper cannot
be the specific origin of a dozen different narrow behavioral variants
it never names.

Verified each of the 50 individually against its actual cited references
and behavioral_fingerprint:

- 44 records: no reference specific enough to support external credit
  (either generic framework citations only -- CWE/OWASP/MITRE/RFC/MCP
  spec -- or a cited paper whose confirmed scope doesn't match this
  record's specific mechanism). AVE's own synthesis; researcher
  corrected to Saray Chak.
- 5 records: verified, specific external source confirmed --
  AVE-2026-00007 and AVE-2026-00015 to Perez & Ribeiro (arXiv 2211.09527,
  whose own named contributions are literally 'goal hijacking' and
  'prompt leaking'); AVE-2026-00016 to Zou et al. (PoisonedRAG, arXiv
  2402.07867, confirmed to describe injecting malicious text into a RAG
  knowledge base that gets retrieved as trusted context -- a direct
  match); AVE-2026-00059 to Liu et al. (ShareLock, arXiv 2606.27027,
  confirmed real, exact attack-success-rate match to the record's own
  reference text); AVE-2026-00065 to Kumar Aditya (Keysight ATI,
  confirmed real via the researcher's own published blog post naming
  him as lead).
- 1 record left unchanged: AVE-2026-00020 (cross-agent A2A injection).
  Cohen et al.'s worm-propagation mechanism is a plausible but not clean
  match -- flagged as genuinely ambiguous rather than decided
  unilaterally.

All 80 records still validate, fixtures intact, full suite passes.
@chaksaray
chaksaray merged commit 228d545 into develop Aug 26, 2026
6 checks passed
@chaksaray
chaksaray deleted the fix/researcher-attribution-audit branch August 26, 2026 00:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants