USENIX Security2026Top-tier venue
"Oh, what people would do with my knife?'' Navigating the Dual-Use Dilemma in PoC Exploit Development, Disclosure, and Community Dynamics
Arwa Al Alsadi, Lorenz Kustosch, Lamya Alowain, Michel Van Eeten, Carlos H. Gañán
Abstract
The cybersecurity landscape faces an escalating challenge as proof-of-concept (PoC) exploits transition from demonstrations to weaponized attacks within minutes of disclosure. While research has documented temporal dynamics and malicious deployment, a critical gap remains in understanding the human factors underlying PoC creation. Through semi-structured interviews with 16 PoC developers across diverse regions, we apply Expectancy-Value Theory to reveal PoC development as a complex motivational ecosystem where technical confidence, value assessments, and risk calculations intersect within dual-use tensions. We demonstrate that PoC development spans a continuum from crash demonstrations to weaponized exploits, shaped by multifaceted calculus rather than binary ethics. We identify three theoretical extensions: dual-use moral reasoning enabling responsibility externalization, dynamic value assessment where vendor behavior reshapes disclosure decisions, and identity navigation between ethical research and technical mastery. Vendor responsiveness, community dynamics, and legal constraints significantly influence disclosure strategies. PoC developers adopt risk-mitigation approaches when navigating tensions between security improvement and potential misuse, challenging binary conceptualizations of "responsible" versus "irresponsible" disclosure.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on6
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu et al.S&P 2018 · 151 citations
- Economic Factors of Vulnerability Trade and ExploitationLuca AllodiCCS 2017 · 82 citations
- Smart Contract and DeFi Security Tools: Do They Meet the Needs of Practitioners?Stefanos Chaliasos, Marcos Antonios Charalambous, Liyi Zhou, Rafaila Galanopoulou et al.ICSE 2024 · 49 citations
- The Benefits of Vulnerability Discovery and Bug Bounty Programs: Case Studies of Chromium and FirefoxSoodeh Atefi, Amutheezan Sivagnanam, Afiya Ayman, Jens Grossklags et al.WWW 2023 · 13 citations
- Bug Hunters' Perspectives on the Challenges and Benefits of the Bug Bounty EcosystemOmer Akgul, Taha Eghtesad, Amit Elazari, Omprakash Gnawali et al.USENIX Security 2023
Related papers
- Actively Understanding the Dynamics and Risks of the Threat Intelligence EcosystemTillson Galloway, Omar Alrawi, Allen Chang, Athanasios Avgetidis et al.NDSS 2026 · 2 citations
- "Abuse Risks are Often Inherent to Product Features": Exploring AI Vendors' Bug Bounty and Responsible Disclosure PoliciesYangheran Piao, Jingjie Li, Daniel W. WoodsUSENIX Security 2026 · 1 citation
- PoCE: Automated Proof-of-Concept Synthesis using Large Language Models for Robust ValidationTanusree Das Tithy, Lamia Hasan Rodoshi, Ayman Rafid Azahar, Amlan Abhidarshi et al.ISSTA 2026
- Beyond Clinical Risk: An Experimental Study of Cybersecurity Informed Consent and Patient Choice for Connected Medical DevicesRonald E. Thompson III, R. Harrison Sweet, Christian J. Dameff, Jeffrey L. Tully et al.CHI 2026 · 1 citation
- PoCGen: Generating Proof-of-Concept Exploits for Vulnerabilities in Npm PackagesDeniz Simsek, Aryaz Eghbali, Michael PradelFSE 2026 · 4 citations
