Cryptographic Registry Provenance: Structural Defense Against Dependency Confusion in AI Package Ecosystems 事件

PRODUCT_LAUNCH2026-05-27影响: MEDIUM

Cryptographic Registry Provenance: Structural Defense Against Dependency Confusion in AI Package Ecosystems arXiv:2605.03309v2 Announce Type: replace-cross Abstract: Dependency confusion attacks exploit a structural gap in software distribution: once a package is installed, there is no cryptographic proof of which registry distributed it. Every existing defense is configuration-based and fails silently when misconfigured. We present a cryptographic distribution provenance system comprising thre

Cryptographic Registry Provenance: Structural Defense Against Dependency Confusion in AI Package Ecosystems · 相关公司

I
ISONONPROFIT
P
PHINONPROFIT
C
CATIRESEARCH_INSTITUTE
E
EATNONPROFIT
A
ACTNONPROFIT
E
EveryCOMPANY
I
IdentityNONPROFIT
E
EGINONPROFIT
R
RatioRESEARCH_INSTITUTE