agentsclimarketplace

Ccs experiments

Skill brycewang-stanford/Awesome-Journal-Skills/ACM-CCS-Skills/skills/ccs-experiments

Journal-specific Claude Code/Codex skill packs covering mainstream journals — AER, QJE, Nature, Cell, 管理世界, 经济研究 & 200+ more — your fast track to getting published. | 覆盖主流期刊的 Claude Code/Codex 期刊技能包,从选题、识别策略到表格规范与审稿回复全流程,助你快速发论文。

Install
npx -y skills add brycewang-stanford/Awesome-Journal-Skills --skill ccs-experiments

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Use when designing or auditing ACM CCS experiments, attack demonstrations, adaptive-attack defense evaluations, security measurements, baselines, overhead and cost reporting, ablations, and claim-to-evidence fit, with emphasis on evidence that survives an adversarial program committee rather than leaderboard wins.

SKILL.md

3.7 KB, as published. Nobody here has run it

CCS Experiments

Use this before submission when the attack demonstration, defense evaluation, or measurement story is not yet locked.

Experiment audit

  • Map each security claim to a specific artifact: an exploit run, an overhead measurement, a coverage number, a false-positive/false-negative table, or a measurement dataset.
  • For attacks, demonstrate the exploit against a realistic, named target (software version, platform, configuration) and report the resource cost to the attacker.
  • For defenses, evaluate against an adaptive attacker built with knowledge of the defense, and report performance overhead, memory cost, and any compatibility breakage.
  • For measurements, validate sampling: document the population, the vantage point, coverage and blind spots, and ground-truth checks against known cases.
  • Include baselines that represent the state of the art in attack or defense, not strawmen.
  • Report variance for stochastic results and audit for leakage, selection bias, and any mismatch between the threat model and the tested configuration.

What experiments are for at this venue

  • CCS experiments exist to make a security claim undeniable to a skeptic, not to top a benchmark. One clean end-to-end exploit against a real target outweighs a table of micro-benchmarks.
  • The strongest defense design triad: the attack it stops, an adaptive attack that knows the defense, and a deployment-cost measurement. Missing the middle element is the classic CCS defense reject.
  • Reviewers, often practitioners, check whether the evaluation environment matches the threat model. A defense claimed for production but tested only on a toy in a lab invites the relevance question.

Attack-and-defense evaluation table

Security claimMatching evidenceReject pattern avoided
Exploit is practicalEnd-to-end run on named target with attacker cost"Works only in a lab against a strawman"
Defense stops the attackDetection/prevention rate on the original attack"No numbers, only a design argument"
Defense resists adaptationAdaptive attacker with defense knowledge, degraded results"Only the non-adaptive attack was tried"
Deployment is feasibleOverhead, memory, compatibility on a realistic workload"Security claimed, cost never measured"

Vignette: evaluating a control-flow-integrity defense

Suppose the paper proposes a fine-grained CFI scheme. The matching plan: reproduce a known code-reuse attack and show it blocked; construct an adaptive attacker that respects the CFI policy and search for surviving gadget chains; then measure runtime overhead and binary-size growth on a standard benchmark suite. Every claim ties to a numbered table, and the adaptive result is reported even when it dents the headline.

Reporting floor

  • Name every target's exact version and configuration; "a popular browser" is not a target.
  • Report the attacker's resource budget (queries, time, samples) and the defense's measured overhead rather than vague "negligible cost" language.

Output format

[Experiment readiness] strong / adequate / weak
[Claim -> evidence map] <claim: exploit run / overhead table / measurement>
[Missing security evidence] <adaptive attack / baseline / cost / validation>
[Threat-model mismatch] <where the setup breaks the stated model>
[Decision-critical next run] <one experiment>

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.