Athena: Vulnerability-Affected Library Identification via Knowledge Graph Completion
Quick summary
arXiv:2609.01187v1 Announce Type: cross Abstract: A single vulnerability in a widely used library can cascade through millions of dependent applications, yet more than half of vulnerability database entries contain missing or incorrect affected-library information. Existing automated approaches neglect the relational structure of vulnerability databases, treating identification as an isolated text retrieval problem. In this paper, we propose Athena, the first graph-based approach for vulnerability affected library identification. Athena models vulnerability databases as a knowledge graph and r
Key takeaways
- arXiv:2609.01187v1 Announce Type: cross Abstract: A single vulnerability in a widely used library can cascade through millions of dependent applications, yet more than half of vulnerability database entries contain missing or incorrect affected-library information.
- Existing automated approaches neglect the relational structure of vulnerability databases, treating identification as an isolated text retrieval problem.
- In this paper, we propose Athena, the first graph-based approach for vulnerability affected library identification.
Why it matters
“Athena: Vulnerability-Affected Library Identification via Knowledge Graph Completion” shows why AI risk cannot be reduced to answer accuracy. Access controls, logging, human approval and incident response need to be designed into the workflow from the start.

Member comments