Lune

USENIX Security2026Top-tier venue

"Oh, what people would do with my knife?'' Navigating the Dual-Use Dilemma in PoC Exploit Development, Disclosure, and Community Dynamics

Arwa Al Alsadi, Lorenz Kustosch, Lamya Alowain, Michel Van Eeten, Carlos H. Gañán

2026Year

Abstract

The cybersecurity landscape faces an escalating challenge as proof-of-concept (PoC) exploits transition from demonstrations to weaponized attacks within minutes of disclosure. While research has documented temporal dynamics and malicious deployment, a critical gap remains in understanding the human factors underlying PoC creation. Through semi-structured interviews with 16 PoC developers across diverse regions, we apply Expectancy-Value Theory to reveal PoC development as a complex motivational ecosystem where technical confidence, value assessments, and risk calculations intersect within dual-use tensions. We demonstrate that PoC development spans a continuum from crash demonstrations to weaponized exploits, shaped by multifaceted calculus rather than binary ethics. We identify three theoretical extensions: dual-use moral reasoning enabling responsibility externalization, dynamic value assessment where vendor behavior reshapes disclosure decisions, and identity navigation between ethical research and technical mastery. Vendor responsiveness, community dynamics, and legal constraints significantly influence disclosure strategies. PoC developers adopt risk-mitigation approaches when navigating tensions between security improvement and potential misuse, challenging binary conceptualizations of "responsible" versus "irresponsible" disclosure.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

Builds on6

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines