There is a newer version of the record available.

Published May 31, 2026 | Version v0.1.0

PatchWeaver: Risk-Bounded Autonomous Vulnerability Remediation Under Change-Management Policies

Authors/Creators

  • 1. Dawn Computing

Description

This archive contains the Artifact Evaluation package for the USENIX Security 2026 paper "PatchWeaver: Risk-Bounded Autonomous Vulnerability Remediation Under Change-Management Policies."

PatchWeaver is a Kubernetes vulnerability-remediation system that provides policy-bounded autonomy under explicit change-management constraints. The artifact contains the PatchWeaver control-plane implementation, the ChangeSpec policy interface, the typed Kubernetes state-graph model, rollout simulation and scoring logic, benchmark workloads, security stress-test scenarios, ablation/sensitivity/overhead evaluators, scripts for regenerating figures, and reference output JSON/PDF figures.

The artifact does not require a Kubernetes cluster or GPT access. It runs a deterministic discrete-event simulation that drives the real PatchWeaver state graph, ChangeSpec policy engine, rollout scorer, action vocabulary, and transition model. Exact paper numbers were measured on a 12-node cluster and are therefore not expected to match this standalone artifact bit-for-bit; the artifact is intended to reproduce the qualitative mechanisms and ordering reported in the paper.

Quick start:

  bash scripts/setup.sh
  NUM_EPISODES=2 ATTACK_EPISODES=2 bash scripts/run_experiments.sh

Full default run:

  SEED=42 bash scripts/run_experiments.sh

Files

PatchWeaver_usenix_security26_ae_v0.1.0.zip

Files (305.3 kB)

Name Size Download all
md5:3d5633b3788f33f3cfe6c77fa5ccbf59
305.3 kB Preview Download