USENIX Security2026Top-tier venue
Not All Those Who Share Are Lost: Analyzing 25 Years of Cybersecurity Artifact Sharing Practices Through Automated Discovery
Daan Vansteenhuyse, Arthur Bols, Lieven Desmet, Victor Le Pochat, Jo Van Bulck, Marton Bognar
Abstract
Cybersecurity publications are often accompanied by artifacts (code and data) that support the paper's findings. In recent years, all top-tier cybersecurity conferences have adopted policies regarding artifacts and introduced artifact evaluation. However, large-scale trends in artifact availability and the impact of conference policies remain largely unexplored, and meta-science studies (often focusing on reproducibility) typically cover a small set of papers due to the extensive manual effort required.
In this paper, we enable larger-scale analyses by introducing ArtiFinder, an automated tool that accurately identifies artifact URLs in paper PDFs. Using ArtiFinder, we present the largest quantitative analysis to date of artifact availability and related effects in close to 9,000 papers published in the four leading cybersecurity conferences since 2000. Our longitudinal analysis reveals a steady increase in artifact sharing over time, with substantial variation across cybersecurity subfields. We find that recent policy changes are not consistently accompanied by increases in artifact sharing, but they coincide with clear shifts toward stable hosting services. We also replicate prior analyses on our dataset, examining trends in citation counts and repository popularity. Our findings highlight notable trends in artifact sharing and the guiding role of conference organizers, while our open-source tool and dataset enable future large-scale studies.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4e8a1510-7a95-4ff2-abcb-fa15d8c6db7fCited by top-tier papers1
Ask how each one uses itBuilds on11
- Lessons Learned from the Chameleon TestbedKate Keahey, Jason Anderson, Zhuo Zhen, Pierre Riteau et al.USENIX ATC 2020 · 398 citations
- SoK: Science, Security and the Elusive Goal of Security as a Scientific PursuitCormac Herley, Paul C. van OorschotS&P 2017 · 95 citations
- Community expectations for research artifacts and evaluation processesBen Hermann, Stefan Winter, Janet SiegmundFSE 2020 · 40 citations
- A retrospective study of one decade of artifact evaluationsStefan Winter, Christopher Steven Timperley, Ben Hermann, Jürgen Cito et al.FSE 2022 · 21 citations
- Code replicability in computer graphicsNicolas Bonneel, David Coeurjolly, Julie Digne, Nicolas MelladoSIGGRAPH 2020 · 21 citations
Related papers
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Data to Infinity and Beyond: Examining Data Sharing and Reuse Practices in the Computer Security CommunityAnna Crowder, Allison Lu, Kevin Childs, Carson Stillman et al.S&P 2025
- Reproducibility in Computational Linguistics: Is Source Code Enough?Mohammad Arvan, Luís Pina, Natalie PardeEMNLP 2022 · 12 citations
- How Transparent is Usable Privacy and Security Research? A Meta-Study on Current Research Transparency PracticesJan H. Klemmer, Juliane Schmüser, Fabian Fischer, Jacques Suray et al.USENIX Security 2025
- Sharing Software-Evolution Datasets: Practices, Challenges, and RecommendationsDavid Broneske, Sebastian Kittan, Jacob KrügerFSE 2024 · 4 citations
