User Tools

Site Tools


artifacts

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
artifacts [2026/08/27 13:30] – Apply focused-review fixes: pin_artifact DOI/shortener, Demir/CCS/USENIX/PETS wording, verbatim quotes. Authored by Claude. karel.kubicek.claudeartifacts [2026/08/27 13:37] (current) – Generic-review fixes: host_fold DOI-prefix, pin_artifact record paths, regenerated Zenodo 431/617, causal wording. Authored by Claude. karel.kubicek.claude
Line 6: Line 6:
 **A GitHub URL is not an archival artifact.** USENIX Security 2026's Artifacts Available badge — mandatory for every accepted paper — refuses GitHub, GitLab and personal pages. The archived copy has to be reachable via a long-term stable reference or DOI. IEEE S&P 2026 and TheWebConf 2026 say the same for Available. Zenodo is the host those calls name first.((USENIX Security 2026 badges, [[https://secartifacts.github.io/usenixsec2026/badges|secartifacts.github.io/usenixsec2026/badges]], read 2026-08-27: //"software development repositories such as GitHub, GitLab, or personal web pages are not acceptable for this badge"//; Zenodo recommended, FigShare, Dryad and Software Heritage named. IEEE S&P 2026 [[https://sp2026.ieee-security.org/cfartifacts.html|cfartifacts.html]], same day: Available requires a DOI-backed deposit. TheWebConf 2026 [[https://www2026.thewebconf.org/calls/artifact-badging.html|artifact-badging.html]], same day: DOI required; GitHub is allowed //alongside// the DOI, not instead of it.)) **A GitHub URL is not an archival artifact.** USENIX Security 2026's Artifacts Available badge — mandatory for every accepted paper — refuses GitHub, GitLab and personal pages. The archived copy has to be reachable via a long-term stable reference or DOI. IEEE S&P 2026 and TheWebConf 2026 say the same for Available. Zenodo is the host those calls name first.((USENIX Security 2026 badges, [[https://secartifacts.github.io/usenixsec2026/badges|secartifacts.github.io/usenixsec2026/badges]], read 2026-08-27: //"software development repositories such as GitHub, GitLab, or personal web pages are not acceptable for this badge"//; Zenodo recommended, FigShare, Dryad and Software Heritage named. IEEE S&P 2026 [[https://sp2026.ieee-security.org/cfartifacts.html|cfartifacts.html]], same day: Available requires a DOI-backed deposit. TheWebConf 2026 [[https://www2026.thewebconf.org/calls/artifact-badging.html|artifact-badging.html]], same day: DOI required; GitHub is allowed //alongside// the DOI, not instead of it.))
  
-Of 5,859 papers in this corpus (seven venues, 2010–2026), **3,321 (56.7%) release at least one authors'-own artifact URL.** That rate rose **23.7% (2010–2013) → 65.0% (2022–2024)**; 2024 itself is 457 of 690 (66.2%). Among those 3,321, **GitHub still hosts 1,896 (57.1%)** and **a named archival host or a DOI resolver hosts 622 (18.7%)** — Zenodo, OSF, Figshare, Dryad, Dataverse, 4TU, Software Heritage, plus 34 other-DOI URLs whose prefix was not one of those (a resolver, not a verified archive). Zenodo among own-link papers was 42 of 457 in 2024 (9.2%) and **228 of 592 in 2025 (38.5%)** — the jump is USENIX's 2025–2026 open-science policy, under which 219 of 293 USENIX papers in 2025–2026 have a Zenodo link (74.7%). 2025–2026 are provisional venue-years; do not read the last column as a completed year.+Of 5,859 papers in this corpus (seven venues, 2010–2026), **3,321 (56.7%) release at least one authors'-own artifact URL.** That rate rose **23.7% (2010–2013) → 65.0% (2022–2024)**; 2024 itself is 457 of 690 (66.2%). Among those 3,321, **GitHub still hosts 1,896 (57.1%)** and **a named archival host or a DOI resolver hosts 617 (18.6%)** — Zenodo, OSF, Figshare, Dryad, Dataverse, 4TU, Software Heritage, plus 34 other-DOI URLs whose prefix was not one of those (a resolver, not a verified archive). Zenodo among own-link papers was 41 of 457 in 2024 (9.0%) and **224 of 592 in 2025 (37.8%)** — that jump **coincides with** USENIX's 2025–2026 open-science policy, under which 217 of 293 USENIX papers in 2025–2026 have a Zenodo link (74.1%). 2025–2026 are provisional venue-years; do not read the last column as a completed year.
 </WRAP> </WRAP>
  
Line 30: Line 30:
  
 ^ Piece ^ Why it is not optional ^ ^ Piece ^ Why it is not optional ^
-| **The URL list, as fetched.** Rank, domain, fetch date. A Tranco id if you used one ([[Programming:Tranco]]); the exact rows if you filtered. "The top 10k" is not a sample. | [[Design:Website selection]], [[Design:Sampling]] +| **The URL list, as fetched.** Rank, domain, fetch date. A Tranco id if you used one ([[Programming:Tranco]]); the exact rows if you filtered. "The top 10k" is not a sample. | Without it nobody can reconstruct the population. 
-| **The crawler pin.** Library version, browser build (not "Chrome"), headless/headful, statefulness, interaction depth, consent action. | [[Programming:Crawler]], [[Programming:Stateful stateless]], [[Privacy:Consent]] | +| **The crawler pin.** Library version, browser build (not "Chrome"), headless/headful, statefulness, interaction depth, consent action. | The number moves when these move ([[Programming:Crawler]], [[Programming:Stateful stateless]], [[Privacy:Consent]]). 
-| **The vantage point.** Provider, city, ASN if you know it. | [[Design:Crawling location]] | +| **The vantage point.** Provider, city, ASN if you know it. | Geo and CDN splits are vantage-dependent ([[Design:Crawling location]]). 
-| **The classifier, with its version.** EasyList commit, Disconnect snapshot, your model weights, the threshold. | [[Privacy:Requests]], [[Design:Website classification]] | +| **The classifier, with its version.** EasyList commit, Disconnect snapshot, your model weights, the threshold. | A later EasyList is a different experiment ([[Privacy:Requests]], [[Design:Website classification]]). 
-| **Per-site outcomes**, not only aggregates. One row per site: loaded or not, the labels, the counts. This is what makes a cluster-aware re-analysis possible. | [[Statistics:Hypothesis testing]], [[Statistics:Regression]] | +| **Per-site outcomes**, not only aggregates. One row per site: loaded or not, the labels, the counts. | Makes a cluster-aware re-analysis possible ([[Statistics:Hypothesis testing]], [[Statistics:Regression]]). Does not by itself reproduce the paper's aggregation. | 
-| **What you deleted, and why.** Raw cookies, request bodies, identifiers. A README that says "we stripped PII" is not a schema. | this page, [[Practices:Ethics]] | +| **The analysis scripts and the environment pin.** The command that produced the table; a lockfile or image digest. | Per-site outcomes without the reducer are a dataset, not a regenerated headline ([[Programming:Docker]]). 
-| **A licence, and a DOI.** GitHub's default branch has neither. | venue table below |+| **What you deleted, and why.** Raw cookies, request bodies, identifiers. A README that says "we stripped PII" is not a schema. | Otherwise a re-run cannot tell missingness from redaction ([[Practices:Ethics]]). 
 +| **A licence, and a DOI.** GitHub's default branch is not a frozen snapshot and has no DOI. A LICENSE file on the repo is not an archive. | Venue table below |
  
 A system paper that evaluated a defence on a testbed has a different minimum (the implementation, the configs, the test vectors). This page is for the student who crawled. A system paper that evaluated a defence on a testbed has a different minimum (the implementation, the configs, the test vectors). This page is for the student who crawled.
Line 87: Line 88:
 ^ Family ^ Permanence ^ Papers ^ Share of 3321 ^ ^ Family ^ Permanence ^ Papers ^ Share of 3321 ^
 | GitHub | mutable-repo | 1896 | 57.1% | | GitHub | mutable-repo | 1896 | 57.1% |
-| Zenodo | archival | 436 | 13.1% |+| Zenodo | archival | 431 | 13.0% |
 | Google Sites (project page) | project-page | 157 | 4.7% | | Google Sites (project page) | project-page | 157 | 4.7% |
 | OSF | archival | 112 | 3.4% | | OSF | archival | 112 | 3.4% |
Line 100: Line 101:
 | GitLab | mutable-repo | 25 | 0.8% | | GitLab | mutable-repo | 25 | 0.8% |
  
-Union of archival families: **622 / 3,321 = 18.7%**. **59 papers (1.8%) give a shortener as the artifact URL** (bit.ly, tinyurl, goo.gl). That URL is not an artifact; it is a redirect the owner can retarget. 667 distinct hosts did not match a family — almost all lab and university project pages. GitHub remains the default; the archival hosts are the minority, and they are new.+Union of archival families: **617 / 3,321 = 18.6%**. **59 papers (1.8%) give a shortener as the artifact URL** (bit.ly, tinyurl, goo.gl). That URL is not an artifact; it is a redirect the owner can retarget. 669 distinct hosts did not match a family. High-count residue hosts are mostly lab and university project pages; the tail also includes pastebins, form hosts, and registries (full list on the provenance page). GitHub remains the default; the archival hosts are the minority, and they are new.
  
 ==== Over time ==== ==== Over time ====
Line 121: Line 122:
 | 2022 | 546 | 338 | 61.9% | 234 | 69.2% | 5 | 1.5% | | 2022 | 546 | 338 | 61.9% | 234 | 69.2% | 5 | 1.5% |
 | 2023 | 719 | 475 | 66.1% | 321 | 67.6% | 21 | 4.4% | | 2023 | 719 | 475 | 66.1% | 321 | 67.6% | 21 | 4.4% |
-| 2024 | 690 | 457 | 66.2% | 307 | 67.2% | 42 | 9.2% | +| 2024 | 690 | 457 | 66.2% | 307 | 67.2% | 41 | 9.0% | 
-| 2025* | 770 | 592 | 76.9% | 318 | 53.7% | 228 38.5% |+| 2025* | 770 | 592 | 76.9% | 318 | 53.7% | 224 37.8% |
 | 2026* | 415 | 315 | 75.9% | 202 | 64.1% | 132 | 41.9% | | 2026* | 415 | 315 | 75.9% | 202 | 64.1% | 132 | 41.9% |
  
Line 132: Line 133:
 | 2025–2026* | 1185 | 907 | 76.5% | | 2025–2026* | 1185 | 907 | 76.5% |
  
-GitHub's share of own-link papers peaked in 2022 (69.2%) and dropped in 2025 (53.7%) as Zenodo rose. That is a venue-policy effect, not a GitHub decline in absolute terms: 2025 still has 318 GitHub papers, more than 2022's 234.+GitHub's share of own-link papers peaked in 2022 (69.2%) and dropped in 2025 (53.7%) as Zenodo rose. That **coincides with** the USENIX 2025–2026 policy change; it is not a GitHub decline in absolute terms: 2025 still has 318 GitHub papers, more than 2022's 234.
  
 ==== By venue ==== ==== By venue ====
Line 138: Line 139:
 ^ Venue ^ Papers ^ Own-link ^ Share ^ GitHub of own-link ^ Zenodo of own-link ^ ^ Venue ^ Papers ^ Own-link ^ Share ^ GitHub of own-link ^ Zenodo of own-link ^
 | CCS | 990 | 467 | 47.2% | 252 | 25 | | CCS | 990 | 467 | 47.2% | 252 | 25 |
-| IEEE-SP | 767 | 423 | 55.1% | 270 | 12 |+| IEEE-SP | 767 | 423 | 55.1% | 270 | 11 |
 | IMC | 638 | 313 | 49.1% | 163 | 12 | | IMC | 638 | 313 | 49.1% | 163 | 12 |
-| NDSS | 701 | 443 | 63.2% | 310 | 102 |+| NDSS | 701 | 443 | 63.2% | 310 | 100 |
 | PETS | 510 | 258 | 50.6% | 158 | 5 | | PETS | 510 | 258 | 50.6% | 158 | 5 |
-| USENIX | 1410 | 980 | 69.5% | 460 | 233 |+| USENIX | 1410 | 980 | 69.5% | 460 | 231 |
 | WWW | 843 | 437 | 51.8% | 283 | 47 | | WWW | 843 | 437 | 51.8% | 283 | 47 |
  
-USENIX is the venue that currently **requires** an open-science appendix, and it is the venue with the highest own-link rate (69.5%) and more than half of the Zenodo mass (233 of 436). PETS, which has run optional artifact evaluation for years, has **5** Zenodo papers. Optional AE does not produce archival deposits; a mandatory Available badge does.+USENIX is the venue that currently **requires** an open-science appendix, and it is the venue with the highest own-link rate (69.5%) and more than half of the Zenodo mass (231 of 431). PETS, which has run optional artifact evaluation for years, has **5** Zenodo papers. Optional AE is not the same mechanism as a mandatory Available badge; the rates should not be read as "optional AE does not work."
  
 ===== Venue artifact evaluation, today ===== ===== Venue artifact evaluation, today =====
Line 164: Line 165:
 ===== GitHub vs a DOI ===== ===== GitHub vs a DOI =====
  
-GitHub is the right place to **develop**. It is the wrong place to **cite**. The default branch moves; a force-push rewrites history; a renamed account 404s the camera-ready URL. The 2026 Available calls noticed.+GitHub is the right place to **develop**. It is the wrong place to **satisfy an Available badge**. The default branch moves; a force-push rewrites history; a renamed account 404s the camera-ready URL. A commit or tag permalink is a citable pointer at source; it is still not the archival deposit the 2026 Available calls ask for.
  
 The pattern that satisfies every row of the table above: The pattern that satisfies every row of the table above:
Line 173: Line 174:
   - Leave the GitHub URL in the README so people can file issues. It is a pointer, not the archive.   - Leave the GitHub URL in the README so people can file issues. It is a pointer, not the archive.
  
-OSF, Figshare, Dryad, institutional Dataverse, 4TU.ResearchData and Software Heritage also issue DOIs. Zenodo is the one the security AE pages name first, and it is the one 436 papers in this corpus already use.+OSF, Figshare, Dryad, institutional Dataverse, 4TU.ResearchData and Software Heritage also issue DOIs. Zenodo is the one the security AE pages name first, and it is the one 431 papers in this corpus already use.
  
 ''anonymous.4open.science'' (36 papers) is a double-blind stand-in for GitHub during review. It is not the camera-ready archive. Swap it for a DOI before the Available check. ''anonymous.4open.science'' (36 papers) is a double-blind stand-in for GitHub during review. It is not the camera-ready archive. Swap it for a DOI before the Available check.
Line 200: Line 201:
 **Restricted access is a release.** Pastrana et al.'s CrimeBB is available to academic researchers from the Cambridge Cybercrime Centre, not on a public URL {[pastrana2018_crimebb]}. Beverly et al. published seeds and targets and held the complete IPv6 traces under restricted distribution {[beverly2018_beholder]}. Both count as an artifact in the schema (''restricted'' / a dataset URL). A reviewer can still get the data. A bit.ly link to a Google Drive folder that you might delete is worse than a named restricted archive. **Restricted access is a release.** Pastrana et al.'s CrimeBB is available to academic researchers from the Cambridge Cybercrime Centre, not on a public URL {[pastrana2018_crimebb]}. Beverly et al. published seeds and targets and held the complete IPv6 traces under restricted distribution {[beverly2018_beholder]}. Both count as an artifact in the schema (''restricted'' / a dataset URL). A reviewer can still get the data. A bit.ly link to a Google Drive folder that you might delete is worse than a named restricted archive.
  
-**What you can always release**, even when the raw crawl cannot go out:+**What you can often still release**, even when the raw crawl cannot go out. Dual-use, an NDA, or copyright can still block the crawler or the classifier — Kim et al. withheld LTEFuzz itself {[kim2019_touching]}. For each withheld piece, say so.
  
   * The URL list (or the Tranco id plus the filter), unless the URLs themselves are the sensitive object (delisting requests, victim sites, the high-school Facebook study).   * The URL list (or the Tranco id plus the filter), unless the URLs themselves are the sensitive object (delisting requests, victim sites, the high-school Facebook study).
-  * The crawler, the pins, the classifier, the analysis scripts.+  * The crawler, the pins, the classifier, the analysis scripts — unless the capability is the harm.
   * Aggregates and per-bin counts that do not identify a site or a person.   * Aggregates and per-bin counts that do not identify a site or a person.
   * A data dictionary of what you deleted.   * A data dictionary of what you deleted.
Line 215: Line 216:
 ===== A check you can run ===== ===== A check you can run =====
  
-''pin_artifact.py'' classifies a URL the way the 2026 Available calls do, and for a Zenodo record prints the version DOI, the concept DOI, the files and the licence. ''%%--require-doi%%'' exits 1 unless every URL is on a **named archival host** (Zenodo, OSF, Figshare, Dryad, Dataverse, 4TU, Software Heritage). A publisher DOI is not enough; a GitHub path that happens to contain ''10.5281'' is not Zenodo.+''pin_artifact.py'' classifies a URL the way the 2026 Available calls do, and for a Zenodo record prints the version DOI, the concept DOI, the files and the licence. ''%%--require-doi%%'' exits 1 unless every URL is on a **named archival host with a record path** (Zenodo, OSF, Figshare, Dryad, Dataverse, 4TU, Software Heritage). A publisher DOI is not enough; ''osf.io/'' with no record id is not enough; a GitHub path that happens to contain ''10.5281'' is not Zenodo.
  
 <file python pin_artifact.py> <file python pin_artifact.py>
Line 310: Line 311:
     if m:     if m:
         return "doi.org", "/" + m.group(1), raw         return "doi.org", "/" + m.group(1), raw
 +    if ' ' in raw or '\t' in raw:
 +        raise ValueError(f"whitespace in URL: {raw!r}")
     with_scheme = raw if re.match(r"^[a-z][a-z0-9+.-]*://", raw, re.I) else "https://" + raw     with_scheme = raw if re.match(r"^[a-z][a-z0-9+.-]*://", raw, re.I) else "https://" + raw
-    parts = urllib.parse.urlparse(with_scheme.replace(" ", ""))+    parts = urllib.parse.urlparse(with_scheme)
     host = parts.hostname     host = parts.hostname
     if host is None or host == "":     if host is None or host == "":
Line 349: Line 352:
         if family == "Zenodo" and zenodo_id(raw) is None:         if family == "Zenodo" and zenodo_id(raw) is None:
             return "Zenodo (no record id)", "unknown"             return "Zenodo (no record id)", "unknown"
 +        path_l = path.lower().rstrip("/") or "/"
 +        if path_l in ("/", "/account", "/login", "/signin") or path.lower().startswith("/account"):
 +            return f"{family} (no record path)", "unknown"
         return family, "archival"         return family, "archival"
     if host.endswith(".osf.io"):     if host.endswith(".osf.io"):
Line 495: Line 501:
   * **Seven venues only.** CHI, SOUPS, ACSAC, EuroS&P, RAID, AsiaCCS are absent. Artifact-evaluation culture at those venues is not in these rates.   * **Seven venues only.** CHI, SOUPS, ACSAC, EuroS&P, RAID, AsiaCCS are absent. Artifact-evaluation culture at those venues is not in these rates.
   * **"Own-link" is a URL the extractor stored as the authors'.** A paper that says "code available on request" with no URL is not in the 3,321. A paper that prints someone else's GitHub is not either (''belongsToAuthors === false'').   * **"Own-link" is a URL the extractor stored as the authors'.** A paper that says "code available on request" with no URL is not in the 3,321. A paper that prints someone else's GitHub is not either (''belongsToAuthors === false'').
-  * **Hosts are folded.** GitHub includes gist, raw.githubusercontent.com and ''%%*.github.io%%''. Zenodo includes ''doi.org/10.5281'' and the unschemed ''doi:10.5281/zenodo.N''. The residue (667 hosts) is on the provenance page. Exact-string "github.com" undercounts.+  * **Hosts are folded.** GitHub includes gist, raw.githubusercontent.com and ''%%*.github.io%%''. Zenodo includes ''doi.org/10.5281'' and the unschemed ''doi:10.5281/zenodo.N'', not a GitHub path that happens to contain those digits. The residue (669 hosts) is on the provenance page. Exact-string "github.com" undercounts.
   * **''artifacts.badge'' is not a badge-award rate.** 15 papers. Use the venue AE results.   * **''artifacts.badge'' is not a badge-award rate.** 15 papers. Use the venue AE results.
   * **2025–2026 are provisional.** Own-link 76.9% / 75.9% in those years will move when the missing venue-years land.   * **2025–2026 are provisional.** Own-link 76.9% / 75.9% in those years will move when the missing venue-years land.
artifacts.1787837457.txt.gz · Last modified: by karel.kubicek.claude

Except where otherwise noted, content on this wiki is licensed under the following license: CC BY-NC-SA 4.0
CC BY-NC-SA 4.0 Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki