Skip to content
Review

Not In My Git Yard: Catching Backdoors at Commit and Release Time

Jul 2026 · arXiv.org · Vol abs/2607.26719 · 0 citations · 44 references
Computer Science

TL;DR

Lily is presented, an automated approach that strengthens open-source development and release processes against backdoor injection and achieves high detection accuracy with low false alarm rates, reliably identifies malicious code, resists adversarial attempts, and would have prevented real-world backdoor incidents.

Abstract

Code-level backdoors-stealthy code changes that grant hidden privileges via secret triggers-pose a persistent threat to opensource software. Known attempts to inject such backdoors into widely used projects through malicious commits, tampered release packages, or compromised third-party dependencies, were stopped only by luck and manual review. Existing Continuous Integration (CI) pipelines cannot detect these attacks, and downstream binary analysis tools require substantial manual effort. In this work, we present Lily, an automated approach that strengthens open-source development and release processes against backdoor injection. Lily integrates a backdoor detection mechanism into (1) CI pipelines to block malicious commits, and (2) release vetting workflows to prevent tampered releases or compromised dependencies from entering large ecosystems, such as Linux distributions. Lily offers two key contributions. First, it enhances CI-compatible fuzzing with the capability to detect triggers of suspicious behavior based on historical and current software executions. This enables fast, precise backdoor detection suitable for both CI and update validation workflows. Second, it combines code change analysis with fuzzing data to precisely point maintainers to backdoor-revealing code regions, even when release updates modify millions of lines of code. We also outline five strategies attackers could use to evade Lily, and evaluate corresponding defenses. Our experiments across hundreds of benign and backdoored commits and releases show that Lily achieves high detection accuracy with low false alarm rates, reliably identifies malicious code, resists adversarial attempts, and would have prevented real-world backdoor incidents.

View source

Similar papers

Review Open access 2026

Security Analysis of LLM-Generated Web API Backends

The adoption of Large Language Models (LLMs) is changing how code is written, but the security implications of using LLMs to generate complete web API backends remain insufficiently characterized. Prior studies have assessed the security of LLM-generated code by detecting vulnerabilities in isolated code snippets; howe...

Abdul Ali Khan, S. Rauti, T. Mäkilä · 0 citations
Preprint Sep 2026

CASHEWS: Source Preprocessor for LLM-based Malicious Package Detection

Malicious npm package detection tools now leverage LLMs'semantic understanding of source code to detect malicious intent at scale. This capability has proven invaluable in identifying packages involved in recent supply-chain attacks such as Shai-Hulud. However, threat actors exploit the limited context windows of LLMs...

Jean-Charles Noirot Ferrand, David Adei, Anders Møller et al. · 0 citations
#natural language process... Preprint Sep 2026

SpecGuard: Inference-Time Backdoor Detection For Free

Large language models are often fine-tuned, shared, or downloaded from third parties, so a deployed model may carry a hidden backdoor that behaves normally on benign inputs but switches to attacker-controlled behavior when a secret trigger appears. While backdoors can be audited before deployment, runtime monitoring re...

Wen Rui, Ahmed Salem, Andrew Paverd et al. · 0 citations
Review Jul 2026

ZKP Security Tools and Verification: Coverage, Effectiveness, Adoption, and Challenges

Zero-knowledge proofs (ZKPs) have become a core technology for privacy and verifiable computing. They are used to secure blockchains that handle billions of dollars and identity applications dealing with sensitive personal data. However, ZKP systems are complex, and subtle implementation errors can completely break the...

Arman Kolozyan, Tom Sorger, A. Hicks et al. · 1 citation
#machine learning Preprint Sep 2026

ALIBI: Adversarial Legitimacy Injection in Binary Input against LLM Malware Analyzers

Large language models are being integrated into malware triage workflows as reasoning components that summarize static evidence and produce analyst-facing verdicts. This paper shows that the same reasoning capability introduces a new attack surface. We present ALIBI, a semantic cover story attack against frontier LLM-b...

H. Choi, Wonyoung Jung, Haehoon Seo et al. · 0 citations
Aug 2026

A Post-Compilation Side-Channel Attack Countermeasure Framework for STM32

The prolific deployment of embedded systems across critical infrastructure has made hardware security a pressing concern. For example, inexpensive microcontrollers, such as the STM32 series, are frequently deployed with cryptographic firmware that is vulnerable to Side-Channel Attack (SCA), such as Correlation Power An...

Sartaj Jamal Chowdhury, Ahmed Nabil Hammad, John Dragos et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.