Lune

USENIX Security2026Top-tier venue

PatchWeaver: Risk-Bounded Autonomous Vulnerability Remediation Under Change-Management Policies

Rui Li, Shuang Cao

2026Year

Abstract

Security teams increasingly rely on automation to keep pace with vulnerability disclosure and patch deployment, yet real remediation workflows are constrained by change-management policies: maintenance windows, staged rollout rules, blastradius limits, approval gates, and least-privilege requirements. Today, "autonomous" remediation is brittle. Scripted playbooks are safe but rigid, while LLM-driven agents are flexible but frequently violate operational policies (e.g., patching outside windows, taking too many replicas offline, or skipping mandatory validation), creating outages and compliance risk.

We present PATCHWEAVER, a remediation system that provides policy-bounded autonomy. PATCHWEAVER combines (i) an explicit, continuously refreshed graph of Kubernetes assets, dependencies, identities, vulnerabilities, approvals, and evidence; (ii) a typed policy interface (CHANGESPEC) that encodes organization-specific change rules as executable predicates; and (iii) a rollout-based decision layer that scores candidate remediation plans by predicting both progress and policy-violation risk before any action is executed. The core insight is that myopic enforcement cannot avoid constraint traps-states where locally admissible actions lead to dead ends that force later violations. PATCHWEAVER detects traps via short-horizon simulation and replans when reality diverges from prediction.

We evaluate PATCHWEAVER on four Kubernetes remediation workloads under explicit governance constraints. Compared to a strong toolchain baseline (Gatekeeper + Argo Rollouts + Cosign), PATCHWEAVER reduces step-level policy violations by 52.5% (4.73% vs. 9.95%, p < 0.01) and episodelevel violations by 52.2% (5.82% vs. 12.18%). Compared to an LLM-agent baseline, PATCHWEAVER reduces step violations by 79.1% and worst-case (p99) episode violations by 3.1× (16.8% vs. 51.3%). In security stress tests across 10 attack categories, PATCHWEAVER achieves 0.33% aggregate miss rate with mean dwell time 0.84 s, separating 88.7% immediate blocks from 11.0% escalations, versus 28.5% miss rate and 96.4 s for the toolchain. Control-plane overhead remains practical: p99 admission latency is 31 ms at 32 policy predicates, and total resource usage is under 1 CPU core and 1 GB memory.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

Builds on14

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines