Pith. sign in

REVIEW 3 major objections 4 minor 40 references

Qubes OS Security in the Public Record

T0 review · 3 major / 4 minor · reviewed 2026-08-02 · deepseek-v4-flash

Pith's one-line read This paper claims that roughly 80% of fourteen years of public Qubes advisories are attributable to upstream Xen, CPU, and integration components rather than Qubes-core logic, with statistically flat disclosure since 2018.

desk verdict A careful, reproducible study of the Qubes advisory record whose central claims hold up; main caveat is the post hoc attribution codebook, which shifts the headline numbers a bit but not the qualitative picture. read the letter →

arxiv 2607.14587 v1 pith:CQ7V3BBZ submitted 2026-07-16 cs.CR cs.CL

classification cs.CRcs.CL
keywords QubesOSXensecurityadvisoriesupstreamdependencevulnerabilitydiscoverymodelschange-pointanalysisPoissonregressionmicroarchitecturalvulnerabilities
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper tries to establish that Qubes OS's public security advisory record is dominated by upstream components—Xen, CPU/microarchitecture, and integrations—rather than by Qubes' own core logic. Across 109 Qubes Security Bulletins from 2011 to 2025, 79.8% are attributed upstream, a share that survives all four weighting schemes. It also claims the quarterly disclosure series broke around 2015Q1 and that post-2018 annual rates are statistically flat, meaning the record is stable but not quiet. A careful reader cares because this is a rare longitudinal case where component boundaries are security-relevant and the advisory record is clean enough to test whether upstream dependence is visible in public data.

What carries the argument

The load-bearing mechanism is a deterministic, title-driven attribution codebook: a fixed precedence order (CPU/microarchitecture > Xen/hypervisor > Qubes-core > upstream integration) maps each bulletin's title tokens to one primary and multiple incidence labels, turning free-text QSB titles into a reproducible four-category ledger. This ledger produces the 79.8% upstream figure and feeds the change-point and count-model tests. Supporting machinery includes Bayesian single-change-point and BIC piecewise Poisson segmentation to locate regime breaks, overdispersion diagnostics (Pearson dispersion, negative-binomial profile-likelihood bounds) to validate Poisson assumptions, and rolling one-ste

What would settle it

Have two independent coders read the full text of all 109 QSBs and assign primary components without seeing the codebook; if the resulting upstream share falls below 50%, or if a codebook-precedence reversal drops the share below a majority, the central claim is a measurement artifact. Separately, the stable-regime claim is falsified if complete 2025-2026 data produce a significantly positive post-2018 slope rather than the flat slope estimated here.

Watch

Extended reading notes

Core claim

On its own terms, the paper's central discovery is that the public Qubes advisory stream is shaped far more by the hypervisor, processor, and upstream integration layers than by Qubes-maintained control logic. Using a deterministic, title-driven attribution codebook, 87 of 109 QSBs (79.8%) receive an upstream primary label; the share stays at 80.9% under weighted multi-label attribution and 82.5% under identifier weighting, while Qubes-core never exceeds 20.2%. Regime analysis consistently locates a single dominant break at 2015Q1, after which advisory volume enters a higher plateau; a piecewise Poisson model with an architecture-informed 2018 break yields a net post-2018 slope statistically

Load-bearing premise

The headline upstream share rests on the premise that the hand-written, title-only attribution codebook with fixed precedence (CPU > Xen > Qubes-core > upstream) correctly identifies each bulletin's true primary component, and that the 30-bulletin post hoc audit—drawn from the same corpus the rules were designed on—proves the codebook right.

Editorial extensions

If this is right

  • Monitoring the Qubes-maintained Xen Security Advisory (XSA) tracker and the Xen advisory stream should be a first-class input to operational security planning, since upstream issues account for the large majority of public bulletins.
  • The documented security-testing-to-stable cadence of roughly two weeks is the operative exposure window; update staging decisions should be made against it.
  • Post-2018 advisory volume is statistically flat, so near-term jumps in QSB count are more likely to come from exogenous microcode or transient-execution waves (31.5% of post-2018 bulletins) than from Qubes-core code changes.
  • S-shaped vulnerability discovery models fit the cumulative record descriptively but do not beat a rolling three-year mean in short-horizon forecasts, so simple baselines should be favored for annual planning.
  • Qubes-core advisories remain a minority under every attribution scheme, so the public record is not evidence of a Qubes-core quality problem.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the upstream share is as stable as the paper finds, Qubes' real assurance bottleneck sits outside its own codebase; a natural next step is to test whether future QSB rates track Xen advisory rates or microcode release waves, which the paper measures only at the aggregate level.
  • The same protocol could be applied to other isolation-heavy systems with explicit trust anchors—other Xen-based desktops, microkernel or unikernel systems—to test whether upstream dominance is a general property of compressed-TCB architectures rather than a Qubes quirk.
  • The negative VDM forecast result suggests operational teams should budget advisory-response effort using rolling historical averages rather than fitted growth curves; the paper states the statistical result but leaves the budgeting consequence implicit.
  • One testable extension is to correlate the quarterly series against external indicators such as Xen advisory volume or new microcode releases, to check whether the 2015Q1 break and the post-2018 plateau are driven by upstream disclosure waves rather than Qubes' own release process.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 4 minor

Summary. The paper presents a protocol-driven longitudinal analysis of the public Qubes OS advisory record: all 109 Qubes Security Bulletins (QSBs, 2011–2025), the official Qubes-maintained Xen Security Advisory (XSA) tracker, and a secondary annualized vulnerability-event series. It makes four main claims: (1) under the paper's primary component-attribution codebook, 79.8% of QSBs are attributable to upstream components (Xen, CPU/microarchitecture, or other upstream integration) rather than Qubes-core logic; (2) the quarterly advisory series exhibits a dominant change-point around 2015Q1, with a statistically flat annual rate after 2018; (3) the attribution and stable-regime conclusions survive multiple sensitivity checks (weighted/incidence views, overdispersion diagnostics, endpoint exclusion); and (4) S-shaped vulnerability discovery models fit descriptively but do not significantly outperform simple rolling baselines in short-horizon forecasts. The paper positions itself as measuring the public record, not latent vulnerability incidence, and repeatedly cautions against over-interpretation.

Significance. If the headline claims hold, the paper makes a useful empirical contribution: it provides a fully reproducible QSB ledger and XSA-tracker snapshot, along with a transparent multi-scheme attribution protocol, and it reports a genuinely useful negative result on VDM forecasting. The overdispersion and censoring sensitivity checks are methodologically sound, and the change-point analysis converges on a consistent break across four methods. The XSA-tracker statistic (113/464, using Qubes' official relevance labels) is an independent, less codebook-dependent corroboration of upstream dependence. The paper is carefully scoped and its stated limitations are generally conservative; this is the kind of self-aware measurement study that the security community needs. The main risk is that the 79.8% headline and the 'stable post-2018' wording are stronger than the evidence from the post hoc, single-coder attribution validation and the low-power slope tests, respectively.

major comments (3)
  1. [Section 3.2, Table 2] The validation of the deterministic attribution codebook is post hoc and single-coder: the 30-QSB audit subset is drawn from the same corpus used to author the token rules, and the manual pass was performed by the same researcher who designed the codebook. High agreement (96.7% primary-label accuracy, macro-F1 0.969) documents internal consistency, not out-of-sample accuracy. This matters because the primary-label scheme with fixed precedence (CPU > Xen > Qubes-core > Upstream integration) is the basis for the headline 79.8% upstream share. The paper acknowledges this limitation in Sec. 6 but does not provide a mitigating analysis. Please add an independent full-corpus audit by a second coder blind to the codebook, or a formal development/test split with the codebook frozen before validation. At minimum, report a sensitivity analysis that varies the precedence order (e.g., Qubes-core fir
  2. [Section 4.2, Tables 1 and 4] The 'Upstream integration' category conflates genuinely upstream code with Qubes-specific integration and packaging work (Salt, RPM, Linux netback, kernel driver, template packaging, domU integration issue). Since the paper's central interpretive claim is that the public-record burden is concentrated in 'upstream trust anchors' (Abstract, Sec. 5), this category can inflate the upstream share if a QSB concerns Qubes-maintained packaging/integration logic rather than an upstream component. Report the upstream share with 'Upstream integration' excluded (i.e., Xen/hypervisor + CPU/microarchitecture only) under each of the four attribution views, and discuss how the conclusion changes. The XSA-tracker statistic (113/464) is a useful independent check but covers only Xen, not the full 'upstream' grouping used in the headline.
  3. [Section 4.1, Eq. (1)] The 'stable post-2018 regime' conclusion is supported by failing to reject the null that the net post-2018 slope β1+β2 is zero (p=0.208 with the partial 2025 endpoint; p=0.989 without it). In a series of only 14–15 annual observations this test has low power, so non-significance is weak evidence of a zero slope. To support the wording 'statistically flat,' report a 95% confidence interval for β1+β2 (or an equivalence test with a pre-specified bound). The same concern applies to the secondary-series trend test (z=-0.92, p=0.356). The change-point analysis around 2015Q1 is more convincing, but the post-2018 'stability' claim needs stronger statistical support.
minor comments (4)
  1. [Section 3.3] 'Distribution-light' appears to be a typo for 'distribution-free' in the description of the Mann–Kendall test.
  2. [Data Availability / Appendix A] The full attribution codebook is only in the external artifact. Since the codebook is a central piece of the methodology, consider including the complete token list and precedence rules as an appendix rather than representative triggers only.
  3. [Table 1] For the incidence view, make explicit that percentages sum to more than 100% because one bulletin can contribute to multiple categories; the footnote says 'incidence mass,' but a parenthetical in the table header would improve clarity.
  4. [Section 4.1] 'Collapses essentially to zero' is stronger than the reported estimates justify. The NB2 overdispersion parameter is near zero, but the one-sided profile-likelihood upper bounds (α < 0.15 annually, α < 0.21 quarterly) are not negligible; consider phrasing such as 'small' or 'consistent with negligible overdispersion.'

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: headline findings are direct reproducible measurements with independent external anchors; the post hoc codebook validation is a disclosed limitation, not a circular derivation.

full rationale

Walking the derivation chain, the headline upstream-dependence claim (87/109 QSBs, 79.8%) is a direct deterministic count from an explicit, publicly reproducible codebook, not the output of a fitted parameter that is then re-presented as a prediction. The 113/464 XSA-tracker statistic is an externally maintained Qubes relevance count and is cited as an independent point of agreement. The change-point, overdispersion, and piecewise-Poisson results are standard statistical procedures applied to the public count series; the 2018 breakpoint is fixed a priori from the Qubes 4.x architectural transition, and the flat post-2018 slope is a tested conclusion rather than a consequence of fitting that breakpoint. The VDM evaluation is genuinely rolling and out-of-sample, and its main finding is a negative result against simple baselines. The only notable weakness touching attribution is the acknowledged post hoc 30-QSB validation (Section 3.2 and Limitations): the validation subset is drawn from the same corpus used to author the codebook, so the reported 96.7% accuracy is an in-sample consistency check rather than independent confirmation. However, this is a limitation on evidentiary strength, not circularity: no equation or fitted value is reused as its own prediction, and the paper explicitly discloses the post hoc nature of the audit. The central claims therefore do not reduce to their own inputs by construction.

Assumptions & free parameters 5 free parameters · 6 assumptions · 0 invented entities

The central claims rest less on invented entities than on hand-authored classification rules and model choices. The attribution codebook, the 2018 breakpoint, and the VDM parameter fits are the main inputs the reader must accept on the authors' terms.

free parameters (5)
  • 2018 piecewise breakpoint τ = 2018 (hand-set, not data-mined)
    Used in Eq. (1) to define the post-2018 stable-regime slope test. Chosen from the Qubes 4.x architectural transition; if the true policy/architecture break differs, the 'flat after 2018' conclusion could be an artifact.
  • Attribution precedence order (CPU > Xen > Qubes-core > Upstream) = Hand-authored precedence
    Primary-label assignment in Section 3.2 follows a fixed precedence; it determines the headline 79.8% upstream share. No independent justification is given for this ordering.
  • Yamada model parameters (primary series) = a=240.8, b=0.102
    Fitted to annual QSB counts (Section 4.5) and used to claim S-shaped descriptive fit; bootstrap intervals are wide ([159.7, 729.0] for a).
  • AML model parameters (secondary series) = B=155.8, κ=0.463, C=62.1
    Fitted to the annualized vulnerability-event series; used for the descriptive 'late-stage, slowing growth' claim.
  • NB2 overdispersion parameter α = α ≈ 8e-8 (annual), 8e-5 (quarterly)
    Estimated in the negative-binomial robustness models (Section 3.3) to justify Poisson inference; sits near the boundary, with profile-likelihood upper bounds α < 0.15 and α < 0.21.
assumptions (6)
  • domain assumption The public QSB/XSA advisory record is a meaningful, non-randomly-missing sample of security-relevant vulnerability activity for Qubes.
    Entire study is about the public record; the authors explicitly disclaim latent incidence, but the policy relevance of the findings depends on this record being informative.
  • ad hoc to paper The deterministic title-driven codebook tokens and precedence rules adequately capture true component attribution for all 109 QSBs.
    Section 3.2 introduces hand-authored token rules; accuracy is checked on a 30-QSB post hoc subset, not a pre-registered holdout.
  • domain assumption Qubes' official XSA tracker relevance filter (e.g., excluding pure host DoS cases) is accepted as the correct mapping of Xen advisories to Qubes.
    Section 2 notes the filter; the 113/464 tracker upstream-dependence statistic inherits that policy, whose historical drift is acknowledged in Limitations.
  • standard math Counts of QSBs follow a Poisson or NB2 process with piecewise-constant or piecewise-linear log-rate.
    Modeling assumption for change-point and trend tests (Section 3.3); overdispersion checks support it for these data.
  • domain assumption S-shaped VDM families are a priori plausible discovery models for the Qubes advisory record.
    Used in Section 3.5; the paper itself finds they do not beat baselines in forecasting, so this axiom mainly affects the descriptive narrative.
  • ad hoc to paper The 2018 breakpoint tied to the Qubes 4.x transition is a meaningful architectural/policy boundary.
    Used in Eq. (1); justified by release notes and core-stack announcements, but the exact year is a modeling choice.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Qubes OS Security in the Public Record." pith.science (2026). https://pith.science/paper/CQ7V3BBZ

@misc{pith2026260714587,
  author       = {Pith},
  title        = {Pith review of: Qubes OS Security in the Public Record},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/CQ7V3BBZ}},
  note         = {Machine review of arXiv:2607.14587}
}
read the original abstract

Qubes OS is a revealing case for security measurement because its architecture makes component boundaries security-relevant. We present a protocol-driven longitudinal analysis of 109 public Qubes Security Bulletins (QSBs, 2011--2025), the official Qubes-maintained Xen Security Advisory (XSA) tracker, and a secondary vulnerability-event sensitivity series. The study measures the public advisory record rather than latent vulnerability incidence or realized compromise. The methodology combines audited deterministic component attribution, change-point analysis, overdispersion checks, severity-proxy weighting, censoring sensitivity, documentary latency lower bounds, and baseline-aware evaluation of vulnerability discovery models (VDMs). The results show persistent upstream dependence in that public record. On the official tracker, 113 of 464 XSAs affect Qubes; under primary labeling, 87 of 109 QSBs (79.8\%) are attributable to Xen, CPU/microarchitectural, or other upstream components rather than Qubes-core logic, with similar results under weighted views. Change-point analyses identify 2015Q1 as the dominant break in the quarterly advisory series, while post-2018 annual disclosure rates are statistically flat. Poisson inferences are stable under dispersion diagnostics and negative-binomial sensitivity checks. The attribution codebook performs well in a stratified 30-QSB audit, and S-shaped VDMs fit descriptively but do not significantly outperform a rolling-mean baseline in short-horizon forecasts. Overall, the Qubes public advisory record appears stable, but not quiet: disclosure activity plateaus at a higher level than in the earliest years, while the observed burden remains concentrated in upstream trust anchors.

Figures

Figures reproduced from arXiv: 2607.14587 by the authors.

Figure 1
Figure 1. Exact annual counts reconstructed from the canonical advisory tables. The [PITH_FULL_IMAGE:figures/full_fig_p008_1.png] view at source ↗
Figure 2
Figure 2. Quarterly QSB counts with the dominant 2015Q1 break and the architecture [PITH_FULL_IMAGE:figures/full_fig_p009_2.png] view at source ↗
Figure 3
Figure 3. Component shares under four attribution views. The conclusion that upstream [PITH_FULL_IMAGE:figures/full_fig_p011_3.png] view at source ↗
Figures from the paper (1 more)
Figure 4
Figure 4. Figure 4: Rolling one-step-ahead annual MAE. Simple rolling baselines remain hard to [PITH_FULL_IMAGE:figures/full_fig_p012_4.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

40 extracted references · 2 canonical work pages

  1. [1]

    Qubes OS Project: Qubes security bulletins (QSBs).https://www.qubes-os.org/ security/qsb/(accessed 2026-03-17)

  2. [2]

    org/security/xsa/(accessed 2026-03-17)

    Qubes OS Project: Xen security advisory (XSA) tracker.https://www.qubes-os. org/security/xsa/(accessed 2026-03-17)

  3. [3]

    Xen Project: Xen security advisories.https://xenbits.xen.org/xsa/(accessed 2026-03-17)

  4. [4]

    org/en/latest/introduction/faq.html(accessed 2026-03-17)

    Qubes OS Project: Frequently asked questions (F AQ).https://doc.qubes-os. org/en/latest/introduction/faq.html(accessed 2026-03-17)

  5. [5]

    Qubes OS Project: Testing new releases and updates.https://doc.qubes-os.org/ en/latest/user/downloading-installing-upgrading/testing.html(accessed 2026-03-17)

  6. [6]

    org/en/latest/introduction/intro.htmlandhttps://doc.qubes-os.org/en/ latest/developer/system/architecture.html(accessed 2026-03-17)

    Qubes OS Project: Introduction and architecture.https://doc.qubes-os. org/en/latest/introduction/intro.htmlandhttps://doc.qubes-os.org/en/ latest/developer/system/architecture.html(accessed 2026-03-17)

  7. [7]

    Qubes OS Project: QSB-055 — Issues with PV type change and handling IOMMU on AMD (XSA-310, XSA-311).https://www.qubes-os.org/news/2019/12/11/ qsb-055/(accessed 2026-03-17)

  8. [8]

    Qubes OS Project: QSB-083 — Retbleed: arbitrary speculative code execution with return instructions (XSA-407).https://www.qubes-os.org/news/2022/07/ 13/qsb-083/(accessed 2026-03-17)

Show all 40 references
  1. [9]

    Qubes OS Project: QSB-089 — Qrexec: memory corruption in service request han- dling.https://www.qubes-os.org/news/2023/05/11/qsb-089/(accessed 2026- 03-17)

  2. [10]

    Qubes OS Project: QSB-102 — Multiple speculative-execution vulnerabilities: Spectre-BHB, BTC/SRSO (XSA-455, XSA-456).https://www.qubes-os.org/ news/2024/04/10/qsb-102/(accessed 2026-03-17)

  3. [11]

    org/news/2025/08/14/qsb-109/(accessed 2026-03-17)

    Qubes OS Project: QSB-109 — Intel microcode updates.https://www.qubes-os. org/news/2025/08/14/qsb-109/(accessed 2026-03-17)

  4. [12]

    Qubes OS Project: Qubes R4.0 release notes.https://doc.qubes-os.org/en/ latest/developer/releases/4_0/release-notes.html(accessed 2026-03-17)

  5. [13]

    qubes-os.org/news/2017/10/03/core3/(accessed 2026-03-17)

    Rutkowska, J.: Introducing the next generation Qubes core stack.https://www. qubes-os.org/news/2017/10/03/core3/(accessed 2026-03-17)

  6. [14]

    Journal of the American Statistical Association22(158), 209–212 (1927)

    Wilson, E.B.: Probable inference, the law of succession, and statistical inference. Journal of the American Statistical Association22(158), 209–212 (1927)

  7. [15]

    Mann, H.B.: Nonparametric tests against trend.Econometrica13(3), 245–259 (1945)

  8. [16]

    Sen, P.K.: Estimates of the regression coefficient based on Kendall’s tau.Journal of the American Statistical Association63(324), 1379–1389 (1968)

  9. [17]

    Griffin, London (1975) Qubes OS Security in the Public Record 17

    Kendall, M.G.:Rank Correlation Methods, 4th edn. Griffin, London (1975) Qubes OS Security in the Public Record 17

  10. [18]

    Goel, A.L., Okumoto, K.: Time-dependent error-detection rate model for soft- ware reliability and other performance measures.IEEE Transactions on Reliability 28(3), 206–211 (1979)

  11. [19]

    Yamada, S., Ohba, M., Osaki, S.: S-shaped reliability growth modeling for software error detection.IEEE Transactions on Reliability32(5), 475–484 (1983)

  12. [20]

    In:Proceedings of the 7th International Conference on Software Engineering, pp

    Musa, J.D., Okumoto, K.: A logarithmic Poisson execution time model for software reliability measurement. In:Proceedings of the 7th International Conference on Software Engineering, pp. 230–238 (1984)

  13. [21]

    Diebold, F.X., Mariano, R.S.: Comparing predictive accuracy.Journal of Business & Economic Statistics13(3), 253–263 (1995)

  14. [22]

    Harvey, D., Leybourne, S., Newbold, P.: Testing the equality of prediction mean squared errors.International Journal of Forecasting13(2), 281–291 (1997)

  15. [23]

    In: 16th IEEE International Symposium on Software Reliability Engineering (IS- SRE’05), (2005)

    Alhazmi, O.H., Malaiya, Y.K.: Modeling the vulnerability discovery process. In: 16th IEEE International Symposium on Software Reliability Engineering (IS- SRE’05), (2005)

  16. [24]

    Rescorla, E.: Is finding security holes a good idea?IEEE Security & Privacy3(1), 14–19 (2005)

  17. [25]

    org/10.2139/ssrn.786128(2006)

    Arora, A., Krishnan, R., Telang, R., Yang, Y.: An empirical analysis of software vendors’ patching behavior: Impact of vulnerability disclosure.https://dx.doi. org/10.2139/ssrn.786128(2006)

  18. [26]

    Ozment, A., Schechter, S.E.: Milk or wine: Does software security improve with age? In:Proceedings of USENIX Security Symposium 2006(2006)

  19. [27]

    Alhazmi, O.H., Malaiya, Y.K., Ray, I.: Measuring, analyzing and predicting se- curity vulnerabilities in software systems.Computers & Security26(3), 219–228 (2007)

  20. [28]

    Cambridge University Press, Cambridge (2011)

    Hilbe, J.M.:Negative Binomial Regression, 2nd edn. Cambridge University Press, Cambridge (2011)

  21. [29]

    arXiv:1103.0759 (2011)

    Zhou, F., Goel, M., Desnoyers, P., Sundaram, R.: Scheduler vulnerabilities and attacks in cloud computing. arXiv:1103.0759 (2011)

  22. [30]

    In:Proceedings of the 7th ACM Symposium on Information, Computer and Communications Security, (2012)

    Nguyen, V.H., Massacci, F.: An independent validation of vulnerability discovery models. In:Proceedings of the 7th ACM Symposium on Information, Computer and Communications Security, (2012)

  23. [31]

    Massacci, F., Nguyen, V.H.: An empirical methodology to evaluate vulnerability discovery models.IEEE Transactions on Software Engineering40(12), 1147–1162 (2014)

  24. [32]

    arXiv:1802.03802 (2018)

    Trippel, C., Lustig, D., Martonosi, M.: MeltdownPrime and SpectrePrime: Automatically-synthesized attacks exploiting invalidation-based coherence proto- cols. arXiv:1802.03802 (2018)

  25. [33]

    In:USENIX Security Symposium 2019, 249–266 (2019)

    Canella, C., Van Bulck, J., Schwarz, M., Lipp, M., von Berg, B., Ortner, P., Piessens, F., Evtyushkin, D., Gruss, D.: A systematic evaluation of transient execu- tion attacks and defenses. In:USENIX Security Symposium 2019, 249–266 (2019)

  26. [34]

    In:Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, pp

    Jones, K.R., Yen, T.-F., Sundaramurthy, S.C., Bardas, A.G.: Deploying Android security updates: An extensive study involving manufacturers, carriers, and end users. In:Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, pp. 551–567 (2020)

  27. [35]

    arXiv:2006.01442 (2020)

    Ahmad, B.A.: Real-time detection of Spectre and Meltdown attacks using machine learning. arXiv:2006.01442 (2020)

  28. [36]

    Kosasih, W., Farias, P., Chiappetta, M., Yilmaz, C., Yarom, Y.: SoK: Can we really detect cache side-channel attacks by monitoring performance counters? In: Proceedings of the 19th ACM Asia Conference on Computer and Communications Security, 172–185 (2024) 18 Alfonso De Gregorio

  29. [37]

    arXiv:2511.17726 (2025)

    Sethumurugan, S., Cherupalli, H., Lu, K., Sartori, J.: Pre-cache: A microarchitec- tural solution to prevent Meltdown and Spectre. arXiv:2511.17726 (2025)

  30. [38]

    arXiv:2501.04580 (2025)

    Moore, M., Zenla, A.: Goldilocks Isolation: High performance VMs with Edera. arXiv:2501.04580 (2025)

  31. [39]

    River Publishers (2025)

    Anand, A., Bhatt, N., Alhazmi, O.H.: Software Vulnerability Discovery Process: Concepts and Applications. River Publishers (2025)

  32. [40]

    Zenodo (2026)

    De Gregorio, A.:Qubes OS Security Analysis Dataset Bundle. Zenodo (2026). doi:10.5281/zenodo.21360032

Pith tools

Reviewed August 2, 2026 · model on record in the stance chip above.