PatchWeaver: Risk-Bounded Autonomous Vulnerability Remediation Under Change-Management Policies
Description
This archive contains the Artifact Evaluation package for the USENIX Security 2026 paper "PatchWeaver: Risk-Bounded Autonomous Vulnerability Remediation Under Change-Management Policies."
PatchWeaver is a Kubernetes vulnerability-remediation system that provides policy-bounded autonomy under explicit change-management constraints. The artifact contains the PatchWeaver control-plane implementation, the ChangeSpec policy interface, the typed Kubernetes state-graph model, rollout simulation and scoring logic, benchmark workloads, security stress-test scenarios, ablation/sensitivity/overhead evaluators, scripts for regenerating figures, and reference output JSON/PDF figures.
The artifact does not require a Kubernetes cluster or GPT access. It runs a deterministic discrete-event simulation that drives the real PatchWeaver state graph, ChangeSpec policy engine, rollout scorer, action vocabulary, and transition model. Exact paper numbers were measured on a 12-node cluster and are therefore not expected to match this standalone artifact bit-for-bit; the artifact is intended to reproduce the qualitative mechanisms and ordering reported in the paper.
Quick start:
bash scripts/setup.sh
NUM_EPISODES=2 ATTACK_EPISODES=2 bash scripts/run_experiments.sh
Full default run:
SEED=42 bash scripts/run_experiments.sh
Files
PatchWeaver_usenix_security26_ae_v0.1.0.zip
Files
(305.3 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:3d5633b3788f33f3cfe6c77fa5ccbf59
|
305.3 kB | Preview Download |