fix: researcher-attribution audit across the corpus (49 of 50) - #205
Merged
Merged
Conversation
Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: chaksaray <15962335+chaksaray@users.noreply.github.com>
# Conflicts: # records/AVE-2026-00048.json
Follow-up to #202, which flagged that AVE-2026-00048 was one of many records still carrying the deprecated 'Bawbel Security Research Team' convention -- 50 of 80 records, not the single miss its own premise assumed. Applied the same standard used on #202 and #48: a cited reference only justifies crediting its author as researcher if it genuinely, specifically describes THIS record's particular mechanism, not merely the broader category it sits in. Several papers (Greshake 2023, Perez 2022, Cohen 2024) repeat across many structurally distinct records as foundational/ background citations -- a single indirect-prompt-injection paper cannot be the specific origin of a dozen different narrow behavioral variants it never names. Verified each of the 50 individually against its actual cited references and behavioral_fingerprint: - 44 records: no reference specific enough to support external credit (either generic framework citations only -- CWE/OWASP/MITRE/RFC/MCP spec -- or a cited paper whose confirmed scope doesn't match this record's specific mechanism). AVE's own synthesis; researcher corrected to Saray Chak. - 5 records: verified, specific external source confirmed -- AVE-2026-00007 and AVE-2026-00015 to Perez & Ribeiro (arXiv 2211.09527, whose own named contributions are literally 'goal hijacking' and 'prompt leaking'); AVE-2026-00016 to Zou et al. (PoisonedRAG, arXiv 2402.07867, confirmed to describe injecting malicious text into a RAG knowledge base that gets retrieved as trusted context -- a direct match); AVE-2026-00059 to Liu et al. (ShareLock, arXiv 2606.27027, confirmed real, exact attack-success-rate match to the record's own reference text); AVE-2026-00065 to Kumar Aditya (Keysight ATI, confirmed real via the researcher's own published blog post naming him as lead). - 1 record left unchanged: AVE-2026-00020 (cross-agent A2A injection). Cohen et al.'s worm-propagation mechanism is a plausible but not clean match -- flagged as genuinely ambiguous rather than decided unilaterally. All 80 records still validate, fixtures intact, full suite passes.
This was referenced Aug 26, 2026
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #202, which flagged that
AVE-2026-00048was one of many records still carrying the deprecatedBawbel Security Research Teamconvention — 50 of 80 records, not the single miss its own premise assumed.Standard applied: same as #202/#48 — a cited reference only justifies crediting its author as
researcherif it genuinely, specifically describes this record's particular mechanism, not merely the broader category it sits in. Several papers (Greshake 2023, Perez 2022, Cohen 2024) repeat across many structurally distinct records as foundational/background citations — a single indirect-prompt-injection paper can't be the specific origin of a dozen different narrow behavioral variants it never names.Results, all 50 checked individually:
Saray Chak.AVE-2026-00007,AVE-2026-00015→ Perez & Ribeiro (arXiv 2211.09527), whose own named contributions are literally "goal hijacking" and "prompt leaking"AVE-2026-00016→ Zou et al. (PoisonedRAG, arXiv 2402.07867), confirmed to describe injecting malicious text into a RAG knowledge base retrieved as trusted context — a direct matchAVE-2026-00059→ Liu et al. (ShareLock, arXiv 2606.27027), confirmed real, with an exact attack-success-rate match to the record's own reference textAVE-2026-00065→ Kumar Aditya (Keysight ATI), confirmed real via his own published blog post naming him as lead researcherAVE-2026-00020(cross-agent A2A injection). Cohen et al.'s worm-propagation mechanism is a plausible but not clean match — flagged as genuinely ambiguous rather than decided unilaterally.All 80 records still validate, fixtures intact, full suite passes.