跳到主要内容
知仓学习社ZHICANG

ccs-reproducibility

Use when strengthening ACM CCS reproducibility evidence, including the artifact-availability posture, threat-model-to-evidence mapping, attack repro…

不碰外部(只输出文字)无严重或高危命中brycewang-stanford/Awesome-Journal-Skills

它会碰到什么

扫了多少1 个文本文件,4 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

CCS Reproducibility

Use this before submission and again before the artifact-evaluation deadline. Reopen the

current CFP and call for artifacts to confirm what availability statement and packaging CCS

expects this cycle.

Evidence map

  • Map each security claim — every attack, defense guarantee, and measurement result — to a

verifiable location: a script, a config, a dataset, a proof, or a logged run.

  • For attacks, record the target's exact version and configuration, the attacker's resource

budget, and the sequence of steps that reproduce the exploit.

  • For defenses, record the workload, the overhead-measurement method, the hardware, and the

adaptive attacker used, so the cost-versus-security tradeoff can be rechecked.

  • For measurements, document the vantage point, the collection window, the sampling frame,

known blind spots, and the ground-truth validation.

  • When artifacts cannot be shared — licensing, responsible disclosure, subject safety, or

premature-release risk — say so explicitly and offer partial, synthetic, or redacted

artifacts that still let a reader assess the methodology.

Availability-posture table

| Claim type | What full sharing looks like | Honest fallback when sharing is blocked |

|---|---|---|

| Exploit against deployed software | Runnable PoC plus target build | Redacted PoC, disclosed-and-patched note, synthetic target |

| Defense with overhead numbers | Instrumented build and benchmark scripts | Binaries plus measurement scripts if source is proprietary |

| Internet-scale measurement | Dataset plus collection tooling | Aggregated data with subject-privacy justification for the rest |

| Cryptographic protocol | Reference implementation and test vectors | Spec plus test vectors if the implementation is embargoed |

Claiming an artifact is unavailable without a reason CCS accepts (a license, a disclosure

embargo, subject safety) reads as evasion; state the specific reason and offer the closest

shareable substitute.

Vignette: a measurement paper on vulnerable hosts

Consider a study scanning the Internet for a misconfiguration. Its reproducibility spine: the

scan methodology and rate-limiting, the classification rule for "vulnerable," the ground-truth

sample validated by hand, the ethics of scanning and notification, and an aggregated dataset

that preserves the finding without exposing individual vulnerable hosts to opportunistic

attackers.

Degrees of reproducibility

  • Turnkey: one command reproduces the attack or the overhead measurement from pinned configs.
  • Scripted: scripts exist but need documented manual steps or gated data access.
  • Descriptive: prose detailed enough that a competent security researcher could rebuild it.

For CCS, aim turnkey for anything you submit to artifact evaluation, and state the achieved

level honestly rather than overpromising a one-command reproduction that fails on a clean host.

Output format

[Claim inventory] <claim -> evidence location>
[Availability posture] full / partial / justified-withheld
[Reproducibility gaps] <versions / configs / budgets / provenance / ethics>
[Paper fixes] <must appear in main PDF or appendix>
[Artifact fixes] <packaging additions before the AE deadline>

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。