writing:literature_review
Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| writing:literature_review [2026/08/27 12:52] – Create writing:literature_review: keyword-derived denominator trap, SoK venue artifact, worked example vs this corpus. Authored by Claude. karel.kubicek.claude | writing:literature_review [2026/08/27 13:04] (current) – Apply generic-pass fixes: schema vs text silence, phenomenon-label homograph, screening hedge, snowball distinction, tip box. Authored by Claude. karel.kubicek.claude | ||
|---|---|---|---|
| Line 10: | Line 10: | ||
| **A keyword-derived denominator is biased along the axis being measured.** | **A keyword-derived denominator is biased along the axis being measured.** | ||
| - | * Searching this corpus for " | + | * Among papers whose '' |
| - | * Searching | + | * A full-text search |
| - | * Searching for the word " | + | * Title-start |
| - | * Searching crawled papers for " | + | * Searching crawled papers for " |
| The rest of this page is that last bullet, applied to the way the field reviews itself. | The rest of this page is that last bullet, applied to the way the field reviews itself. | ||
| + | </ | ||
| + | |||
| + | <WRAP tip> | ||
| + | Before the corpus tables: define the related-work population by what the paper **did**, name the homograph, prefer a venue-complete list plus a hand filter when the quantity is a rate, and write down what the search cannot have seen. Sections 5–6 unpack that. The SoK counts below are why a Scholar pile is not that population. | ||
| </ | </ | ||
| Line 30: | Line 34: | ||
| ==== You cannot measure a reporting rate by searching for the thing being reported ==== | ==== You cannot measure a reporting rate by searching for the thing being reported ==== | ||
| - | Suppose you want to know how often web crawls are run headless. You search Scholar for " | + | Suppose you want to know how often web crawls are run headless. You search Scholar for " |
| That is not a Scholar limitation. It is what a keyword is. The population has to be defined **independently of the word**. Here the population is the 1,120 papers that ran a crawl; the word is then a column, not the row filter. | That is not a Scholar limitation. It is what a keyword is. The population has to be defined **independently of the word**. Here the population is the 1,120 papers that ran a crawl; the word is then a column, not the row filter. | ||
| Line 142: | Line 146: | ||
| </ | </ | ||
| - | The schema' | + | The schema' |
| ==== Homographs make the false-positive side as large as the false-negative ==== | ==== Homographs make the false-positive side as large as the false-negative ==== | ||
| Line 154: | Line 158: | ||
| | " | | " | ||
| - | A related-work search that does not name the homograph will fill the section with the wrong literature. [[Privacy: | + | A related-work search that does not name the homograph will fill the section with the wrong literature. [[Privacy: |
| ===== 2. What " | ===== 2. What " | ||
| Line 175: | Line 179: | ||
| | TheWebConf | 0 | 843 | 0.0% | | | TheWebConf | 0 | 843 | 0.0% | | ||
| - | **69.8%** of extracted SoKs are IEEE S&P. CCS, IMC and TheWebConf | + | **69.8%** of extracted SoKs are IEEE S&P. CCS, IMC and TheWebConf |
| The 43 are not mostly about the web. After a hand fold (every paper, deciding sentence in the report): | The 43 are not mostly about the web. After a hand fold (every paper, deciding sentence in the report): | ||
| Line 187: | Line 191: | ||
| * Stafeev and Pellegrino {[stafeev2024_state]}, | * Stafeev and Pellegrino {[stafeev2024_state]}, | ||
| - | * Birrell et al. {[birrell2024_technical]}, | + | * Birrell et al. {[birrell2024_technical]}, |
| * Blessing, Hugenroth, Anderson and Beresford {[blessing2025_authentication]}, | * Blessing, Hugenroth, Anderson and Beresford {[blessing2025_authentication]}, | ||
| - | * Alam et al. {[alam2026_philter]}, | + | * Alam et al. {[alam2026_philter]}, |
| Website-fingerprinting defenses {[mathews2023_critical]} is in the adjacent bucket on purpose: it is a web //traffic// SoK, and putting it in "web measurement" | Website-fingerprinting defenses {[mathews2023_critical]} is in the adjacent bucket on purpose: it is a web //traffic// SoK, and putting it in "web measurement" | ||
| - | ==== In the index: 167 SoKs, most correctly dropped | + | ==== In the index: 167 SoKs, most screened out of this corpus |
| The 43 are not "the SoKs in these venues" | The 43 are not "the SoKs in these venues" | ||
| Line 204: | Line 208: | ||
| | …extracted | 43 | 4 | | | …extracted | 43 | 4 | | ||
| - | **116 of 163** screened SoKs are out of scope for a measurement corpus, and looking | + | **116 of 163** screened SoKs were labelled |
| The four selected-but-not-extracted SoKs are a Docker-container attack SoK (IEEE S&P 2024) and three USENIX Security 2026 papers that have been selected but not yet retrieved. The four with no abstract are all IEEE S&P 2026, and one of them is Rieder et al.'s tracker-detection SoK {[rieder2026_sok]}. Screening runs on abstracts; a paper with no abstract is never eligible, for a reason that has nothing to do with its topic. [[Literature: | The four selected-but-not-extracted SoKs are a Docker-container attack SoK (IEEE S&P 2024) and three USENIX Security 2026 papers that have been selected but not yet retrieved. The four with no abstract are all IEEE S&P 2026, and one of them is Rieder et al.'s tracker-detection SoK {[rieder2026_sok]}. Screening runs on abstracts; a paper with no abstract is never eligible, for a reason that has nothing to do with its topic. [[Literature: | ||
| Line 214: | Line 218: | ||
| Of the 43 extracted SoKs, **19 (44.2%)** are not a paper-census at all — they are a system, an evaluation, or a vulnerability corpus with an SoK prefix. **24 (55.8%)** claim a literature sample; **18 of those 24 (75.0%)** state a search protocol a reader can name. | Of the 43 extracted SoKs, **19 (44.2%)** are not a paper-census at all — they are a system, an evaluation, or a vulnerability corpus with an SoK prefix. **24 (55.8%)** claim a literature sample; **18 of those 24 (75.0%)** state a search protocol a reader can name. | ||
| - | Among those 18: | + | Across all 43 (the table is not restricted to the 18): |
| ^ How the paper list was built ^ Papers ^ Share of 43 ^ | ^ How the paper list was built ^ Papers ^ Share of 43 ^ | ||
| Line 227: | Line 231: | ||
| Two of those seven are the useful extremes. | Two of those seven are the useful extremes. | ||
| - | **Warford et al.** {[warford2022_framework]} (IEEE S&P 2022) gathered every paper from CCS, CHI, CSCW, IEEE S&P, NDSS, PETS, SOUPS and USENIX Security on DBLP — **6,534** papers — and hand-filtered to 127 candidates, then 95. No keyword. The cost is reading; the gain is that a paper which never says " | + | **Warford et al.** {[warford2022_framework]} (IEEE S&P 2022) gathered every paper from CCS, CHI, CSCW, IEEE S&P, NDSS, PETS, SOUPS and USENIX Security on DBLP — **6,534** papers — and hand-filtered to 127 candidates, plus 12 from other sources to **139**, then **95**. No keyword. The cost is reading; the gain is that a paper which never says " |
| **Stafeev and Pellegrino** {[stafeev2024_state]} started from the same seven venues this corpus uses, 2010–2022, | **Stafeev and Pellegrino** {[stafeev2024_state]} started from the same seven venues this corpus uses, 2010–2022, | ||
| Line 239: | Line 243: | ||
| | **neither** tranco nor alexa | 312 | 45.4% | | | **neither** tranco nor alexa | 312 | 45.4% | | ||
| - | **312 of 687 crawled papers in the same years (45.4%) mention neither list.** A related-work search that starts from " | + | **312 of 687 crawled papers in the same years (45.4%) mention neither list.** A related-work search that starts from " |
| Their keyword false-positive is the other half: **654 of 1,057 (61.9%)** hits were not crawls. On our already-screened 2010–2022 extraction the analogue is **954 of 1,493 (63.9%)** papers matching a generous reading of their three keywords that are not in the crawled population. Screening does not remove the homograph; it only starts you closer. | Their keyword false-positive is the other half: **654 of 1,057 (61.9%)** hits were not crawls. On our already-screened 2010–2022 extraction the analogue is **954 of 1,493 (63.9%)** papers matching a generous reading of their three keywords that are not in the crawled population. Screening does not remove the homograph; it only starts you closer. | ||
| Line 269: | Line 273: | ||
| - **Prefer a venue-complete list plus a hand filter over a keyword**, for any question that is a //rate// (how often, what share, what is missing). Warford et al. {[warford2022_framework]} and Usman and Zappala {[usman2025_framework]} are the templates; Stafeev and Pellegrino {[stafeev2024_state]} is the template for " | - **Prefer a venue-complete list plus a hand filter over a keyword**, for any question that is a //rate// (how often, what share, what is missing). Warford et al. {[warford2022_framework]} and Usman and Zappala {[usman2025_framework]} are the templates; Stafeev and Pellegrino {[stafeev2024_state]} is the template for " | ||
| - **If you must keyword-search — you usually must — write the query, the date, the venues, and the misses you know about.** "We searched Scholar for X on DATE, restricted to VENUES, and we know this drops papers that do Y without saying X." That sentence is the difference between a search and a method. | - **If you must keyword-search — you usually must — write the query, the date, the venues, and the misses you know about.** "We searched Scholar for X on DATE, restricted to VENUES, and we know this drops papers that do Y without saying X." That sentence is the difference between a search and a method. | ||
| - | - **Snowballing from a seed SoK inherits the SoK' | + | - **Snowballing from a seed SoK inherits the seed' |
| - **Read the SoK, then read what its keyword cannot have included.** For crawling, that is Stafeev and Pellegrino plus the crawled papers that never said Tranco or Alexa. For tracking, Vekaria et al. plus the pages on this site whose populations were built from extraction fields rather than from " | - **Read the SoK, then read what its keyword cannot have included.** For crawling, that is Stafeev and Pellegrino plus the crawled papers that never said Tranco or Alexa. For tracking, Vekaria et al. plus the pages on this site whose populations were built from extraction fields rather than from " | ||
| - | - **Do not use " | + | - **Do not use " |
| ===== 6. What to Report ===== | ===== 6. What to Report ===== | ||
| Line 288: | Line 292: | ||
| * Vekaria et al. {[vekaria2025_soktracking]} will need a venue update when one exists. As of 2026-08-27 it is arXiv v1 only. | * Vekaria et al. {[vekaria2025_soktracking]} will need a venue update when one exists. As of 2026-08-27 it is arXiv v1 only. | ||
| * Rieder et al. {[rieder2026_sok]} will enter this corpus if an abstract lands in OpenAlex and the screening is re-run. Until then every " | * Rieder et al. {[rieder2026_sok]} will enter this corpus if an abstract lands in OpenAlex and the screening is re-run. Until then every " | ||
| - | * CCS / IMC / TheWebConf still have no SoK track. If one of them adds one, the venue table on this page is the thing that goes stale, not the argument. | + | * CCS / IMC / TheWebConf |
| </ | </ | ||
writing/literature_review.1787835145.txt.gz · Last modified: by karel.kubicek.claude
