USENIX Security2026Top-tier venue
PatchWeaver: Risk-Bounded Autonomous Vulnerability Remediation Under Change-Management Policies
Rui Li, Shuang Cao
Abstract
Security teams increasingly rely on automation to keep pace with vulnerability disclosure and patch deployment, yet real remediation workflows are constrained by change-management policies: maintenance windows, staged rollout rules, blastradius limits, approval gates, and least-privilege requirements. Today, "autonomous" remediation is brittle. Scripted playbooks are safe but rigid, while LLM-driven agents are flexible but frequently violate operational policies (e.g., patching outside windows, taking too many replicas offline, or skipping mandatory validation), creating outages and compliance risk.
We present PATCHWEAVER, a remediation system that provides policy-bounded autonomy. PATCHWEAVER combines (i) an explicit, continuously refreshed graph of Kubernetes assets, dependencies, identities, vulnerabilities, approvals, and evidence; (ii) a typed policy interface (CHANGESPEC) that encodes organization-specific change rules as executable predicates; and (iii) a rollout-based decision layer that scores candidate remediation plans by predicting both progress and policy-violation risk before any action is executed. The core insight is that myopic enforcement cannot avoid constraint traps-states where locally admissible actions lead to dead ends that force later violations. PATCHWEAVER detects traps via short-horizon simulation and replans when reality diverges from prediction.
We evaluate PATCHWEAVER on four Kubernetes remediation workloads under explicit governance constraints. Compared to a strong toolchain baseline (Gatekeeper + Argo Rollouts + Cosign), PATCHWEAVER reduces step-level policy violations by 52.5% (4.73% vs. 9.95%, p < 0.01) and episodelevel violations by 52.2% (5.82% vs. 12.18%). Compared to an LLM-agent baseline, PATCHWEAVER reduces step violations by 79.1% and worst-case (p99) episode violations by 3.1× (16.8% vs. 51.3%). In security stress tests across 10 attack categories, PATCHWEAVER achieves 0.33% aggregate miss rate with mean dwell time 0.84 s, separating 88.7% immediate blocks from 11.0% escalations, versus 28.5% miss rate and 96.4 s for the toolchain. Control-plane overhead remains practical: p99 admission latency is 31 ms at 32 policy predicates, and total resource usage is under 1 CPU core and 1 GB memory.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on14
- Kairos: Practical Intrusion Detection and Investigation using Whole-system ProvenanceZijun Cheng, Qiujian Lv, Jinyuan Liang, Yan Wang et al.S&P 2024 · 125 citations
- in-toto: Providing farm-to-table guarantees for bits and bytesSantiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola et al.USENIX Security 2019 · 98 citations
- An Empirical Study on Software Bill of Materials: Where We Stand and the Road AheadBoming Xia, Tingting Bi, Zhenchang Xing, Qinghua Lu et al.ICSE 2023 · 82 citations
- An Empirical Study of Malicious Code In PyPI EcosystemWenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang et al.ASE 2023 · 31 citations
- Resource Usage and Optimization Opportunities in Workflows of GitHub ActionsIslem Bouzenia, Michael PradelICSE 2024 · 15 citations
Related papers
- Agent-Based Automated Remediation for Vulnerabilities in Maven ProjectsLyuye Zhang, He Ye, Federica Sarro, Yuqiang Sun et al.OOPSLA 2026
- An Empirical Study and Benchmark of Kubernetes Misconfiguration ScannersHaeun Eom, Bohyun Suk, Sungjae HwangISSTA 2026
- Welder: Compositional Liveness Verification of Cluster Control PlanesZhizhen Cathy Cai, Nikhil Date, Jiawei Tyler Gu, Cody Rivera et al.SOSP 2026
- Breaking the Bulkhead: Demystifying Cross-Namespace Reference Vulnerabilities in Kubernetes OperatorsAndong Chen, Ziyi Guo, Zhaoxuan Jin, Zhenyuan Li et al.NDSS 2026 · 2 citations
- KUBETEUS: An Intelligent Network Policy Generation Framework for ContainersBom Kim, Hyeonjun Park, Seungsoo LeeINFOCOM 2025 · 4 citations
