{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T12:03:35Z","timestamp":1784289815071,"version":"3.55.0"},"reference-count":42,"publisher":"Association for Computing Machinery (ACM)","issue":"2","funder":[{"name":"UK EPSRC","award":["EP\/S035362\/1"],"award-info":[{"award-number":["EP\/S035362\/1"]}]},{"DOI":"10.13039\/100000865","name":"Bill and Melinda Gates Foundation","doi-asserted-by":"crossref","award":["INV-057591"],"award-info":[{"award-number":["INV-057591"]}],"id":[{"id":"10.13039\/100000865","id-type":"DOI","asserted-by":"crossref"}]},{"name":"SPRITE+","award":["EPSRC (EP\/W020408\/1)"],"award-info":[{"award-number":["EPSRC (EP\/W020408\/1)"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Software supply-chain security requires provenance mechanisms that support reproducibility and vulnerability assessment under dynamic execution conditions. Conventional Software Bills of Materials (SBOMs) provide static dependency inventories but cannot capture runtime behaviour, environment drift or exploitability context. This article introduces agentic AI Bills of Materials (AIBOMs), extending SBOMs into active provenance artefacts through autonomous, policy-constrained reasoning. We present an agentic AIBOM framework based on a multi-agent architecture comprising (i) a baseline environment reconstruction agent (MCP), (ii) a runtime dependency and drift-monitoring agent (A2A) and (iii) a policy-aware vulnerability and VEX reasoning agent (AGNTCY). These agents generate contextual exploitability assertions by combining runtime execution evidence, dependency usage and environmental mitigations with ISO\/IEC 20153:2025 Common Security Advisory Framework (CSAF) v2.0 semantics. Exploitability is expressed via structured VEX assertions rather than enforcement actions. The framework introduces minimal, standards-aligned schema extensions to CycloneDX and SPDX, capturing execution context, dependency evolution and agent decision provenance while preserving interoperability. Evaluation across heterogeneous analytical workloads demonstrates improved runtime dependency capture, reproducibility fidelity and stability of vulnerability interpretation compared with established provenance systems, with low computational overhead. Ablation studies confirm that each agent contributes distinct capabilities unavailable through deterministic automation.<\/jats:p>","DOI":"10.1145\/3798285","type":"journal-article","created":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T14:46:52Z","timestamp":1773067612000},"page":"1-35","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["SBOMs into Agentic AIBOMs: Schema Extensions, Agentic Orchestration and Reproducibility Evaluation"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5629-6857","authenticated-orcid":false,"given":"Petar","family":"Radanliev","sequence":"first","affiliation":[{"name":"Department of Computer Sciences, University of Oxford, Oxford, United Kingdom and The Alan Turing Institute, British Library, London, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4715-212X","authenticated-orcid":false,"given":"Carsten","family":"Maple","sequence":"additional","affiliation":[{"name":"The Alan Turing Institute, British Library, London and University of Warwick \u2013 WMG, Coventry, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3989-7436","authenticated-orcid":false,"given":"Omar","family":"Santos","sequence":"additional","affiliation":[{"name":"Cisco Systems, RTP, Durham, North Carolina, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-6252-5134","authenticated-orcid":false,"given":"Kayvan","family":"Atefi","sequence":"additional","affiliation":[{"name":"Computer Science, School of Digital and Physical Sciences, Faculty of Science and Engineering, University of Hull, Hull, United Kingdom of Great Britain and Northern Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,7]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","unstructured":"Tong Qiu Jiaxin Zhu Wei Chen and Jun Wei. 2025. LiPSBOMaker: A prototype of multi-stage Linux distribution package SBOM generator. In Proceedings of the 34th ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA Companion '25). Association for Computing Machinery New York NY USA 56\u201360. Retrieved from 10.1145\/3713081.3731738 and https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3713081.3731738","DOI":"10.1145\/3713081.3731738"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3714464"},{"key":"e_1_3_2_4_2","unstructured":"GitHub SBOM. 2023. Exporting a Software Bill of Materials for Your Repository\u2014GitHub Docs. Retrieved July 07 2025 from https:\/\/docs.github.com\/en\/code-security\/supply-chain-security\/understanding-your-software-supply-chain\/exporting-a-software-bill-of-materials-for-your-repository"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","unstructured":"Himanshu V. Vairagade Angel Mercado Adolfo Ruiz Padron Abhro Buniya Shannon Eggers and Fan Zhang. 2025. Evaluating methods of software bill of materials generation to enhance nuclear power plant cybersecurity. Nuclear Technology 211 6 (June 2025) 1144\u20131152. DOI: 10.1080\/00295450.2024.2382015","DOI":"10.1080\/00295450.2024.2382015"},{"key":"e_1_3_2_6_2","unstructured":"Deloitte. 2018. Managing the risks and realising the opportunities of using third party Software Asset Management (SAM) providers. Retrieved March 13 2026 from https:\/\/www.deloitte.com\/uk\/en\/services\/audit-assurance\/research\/sam-blogs-and-bulletins.html"},{"key":"e_1_3_2_7_2","unstructured":"Jens Wiesner. 2022. CSAF Not SBOM Is the Solution. S4x22\u2014BSI. Retrieved January 03 2023 from https:\/\/www.youtube.com\/watch?v=fKlW9vOs7X4&t=504s"},{"key":"e_1_3_2_8_2","unstructured":"NIST. 2022. NVD\u2014CVSS v3 Calculator. CVSS Version 3.1. Retrieved January 03 2023 from https:\/\/nvd.nist.gov\/vuln-metrics\/cvss\/v3-calculator"},{"key":"e_1_3_2_9_2","unstructured":"Art Manion. 2020. SSVC: Stakeholder-Specific Vulnerability Categorization. Carnegie Mellon University. Retrieved January 02 2023 from https:\/\/bit.ly\/3ambIP4"},{"key":"e_1_3_2_10_2","unstructured":"Thomas Schmidt. 2022. Vulnerability Management with CSAF\u2014Why SBOM is Not Enough. Frankfurt."},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","unstructured":"Takeshi Takahashi and Youki Kadobayashi. 2015. Reference ontology for cybersecurity operational information. The Computer Journal 58 10 (Oct. 2015) 2297\u20132312. DOI: 10.1093\/COMJNL\/BXU101","DOI":"10.1093\/COMJNL\/BXU101"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/1880153.1880163"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1038\/s41746-021-00403-w"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/RWS52686.2021.9611807"},{"key":"e_1_3_2_15_2","unstructured":"Wayne Jackson. 2014. Code Cars and Congress: A Time for Cyber Supply Chain Management (1 of 3). Sonatype. Retrieved January 03 2023 from https:\/\/blog.sonatype.com\/2014\/12\/cyber-supply-chain-management-part1\/"},{"key":"e_1_3_2_16_2","unstructured":"Edward R. Royce. 2014. H.R.5793\u2014113th Congress (2013\u20132014): Cyber Supply Chain Management and Transparency Act of 2014. Congress.Gov. Retrieved January 03 2023 from http:\/\/www.congress.gov\/"},{"key":"e_1_3_2_17_2","unstructured":"Matt Howard. 2017. Cybersecurity Improvement Act of 2017: The Ghost of Congress Past\u2014DevOps.com. DevOps.com. Retrieved January 03 2023 from https:\/\/devops.com\/cybersecurity-improvement-act-2017-ghost-congress-past\/"},{"key":"e_1_3_2_18_2","unstructured":"Joseph Biden.12-M. Executive Order on Improving the Nation\u2019s Cybersecurity | The White House. The White House. Retrieved January 03 2023 from https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/"},{"key":"e_1_3_2_19_2","unstructured":"CISA. 2018. Software Bill of Materials. Cybersecurity & Infrastructure Security Agency. Retrieved December 24 2022 from https:\/\/www.cisa.gov\/sbom"},{"key":"e_1_3_2_20_2","unstructured":"NTIA. 2021. National Telecommunications and Information Administration. Software Bill of Materials (SBOM) | National Telecommunications and Information Administration. The National Telecommunications and Information Administration (NTIA) Washington D.C. Retrieved from https:\/\/ntia.gov\/page\/software-bill-materials"},{"key":"e_1_3_2_21_2","unstructured":"NTIA. 2021. SBOM at a Glance. NTIA Multistakeholder Process on Software Component Transparency | ntia.gov\/sbom. Retrieved January 03 2023 from https:\/\/tiny.cc\/SPDX"},{"key":"e_1_3_2_22_2","unstructured":"MITRE. 2022. CVE\u2014Common Vulnerabilities and Exposures. The MITRE Corporation. Retrieved January 03 2023 from https:\/\/cve.mitre.org\/"},{"key":"e_1_3_2_23_2","unstructured":"CVE. 2022. CVE Security Vulnerability Database. Security Vulnerabilities Exploits References and More. Retrieved January 03 2023 from https:\/\/www.cvedetails.com\/"},{"key":"e_1_3_2_24_2","unstructured":"Ronen Shustin. 2020. Remote Cloud Execution\u2014Critical Vulnerabilities in Azure Cloud Infrastructure (Part II)\u2014Check Point Research. Check Point Research. Retrieved January 03 2023 from https:\/\/research.checkpoint.com\/2020\/remote-cloud-execution-critical-vulnerabilities-in-azure-cloud-infrastructure-part-ii\/"},{"key":"e_1_3_2_25_2","unstructured":"CheckPoint. 2021. Cyber Security Report. Retrieved March 17 2026 from https:\/\/www.checkpoint.com\/downloads\/resources\/cyber-security-report-2021.pdf"},{"key":"e_1_3_2_26_2","unstructured":"Tom Alrich. 2022. \u2019Minimum Elements\u2019 Bigfoot and Other Myths. Blog. Retrieved January 03 2023 from https:\/\/tomalrichblog.blogspot.com\/2022\/"},{"key":"e_1_3_2_27_2","unstructured":"Dependency-Track. 2022. Software Bill of Materials (SBOM) Analysis | OWASP. Dependency-Track. Retrieved January 03 2023 from https:\/\/dependencytrack.org\/"},{"key":"e_1_3_2_28_2","unstructured":"Tom Alrich. 2022. Rethinking VEX (Dec. 2022). Retrieved March 17 2026 from https:\/\/tomalrichblog.blogspot.com\/2022\/"},{"key":"e_1_3_2_29_2","unstructured":"OSS. 2022. Sonatype OSS Inde. Retrieved January 03 2023 from https:\/\/ossindex.sonatype.org\/"},{"key":"e_1_3_2_30_2","unstructured":"Tom Alrich. 2022. Hmm\u2026It Seems SBOMs Might Become Big One of These Days\u2026 Blog. Retrieved January 03 2023 from https:\/\/tomalrichblog.blogspot.com\/2022\/04\/hmmit-seems-sboms-might-become-big-one.html"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/SVM66695.2025.00010"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/SYSCON64521.2025.11014830"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-COMPANION66252.2025.00013"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3672608.3707940"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","unstructured":"Rio Kishimoto Tetsuya Kanda Yuki Manabe Katsuro Inoue Shi Qiu and Yoshiki Higo. 2025. A dataset of software bill of materials for evaluating SBOM consumption tools. 576\u2013580. DOI: 10.1109\/MSR66628.2025.00090","DOI":"10.1109\/MSR66628.2025.00090"},{"key":"e_1_3_2_36_2","unstructured":"CSAF. 2025. ISO\/IEC 20153:2025 | IEC. ISO\/IEC. Retrieved from https:\/\/webstore.iec.ch\/en\/publication\/105858"},{"key":"e_1_3_2_37_2","unstructured":"CSAF. 2025. ISO\/IEC 20153:2025\u2014Information Technology\u2014OASIS Common Security Advisory Framework (CSAF) v2.0 Specification. ISO\/IEC. Retrieved from https:\/\/www.iso.org\/standard\/89986.html"},{"key":"e_1_3_2_38_2","unstructured":"Grype. 2025. anchore\/grype: A Vulnerability Scanner For Container Images and Filesystems. Retrieved from https:\/\/github.com\/anchore\/grype"},{"key":"e_1_3_2_39_2","unstructured":"Syft. 2024. Syft: CLI Tool and Library for Generating SBOMs. Anchore GitHub Repository. Retrieved from https:\/\/github.com\/anchore\/syft"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/2882903.2899401"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/2591062.2591129"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","unstructured":"Trung Dong Huynh and Luc Moreau. 2015. ProvStore: A public provenance repository. In Provenance and Annotation of Data and Processes (IPAW 2014). B. Lud\u00e4scher and B. Plale B. (Eds.) Lecture Notes in Computer Science Vol. 8628. Springer Cham. DOI: 10.1007\/978-3-319-16462-5_32","DOI":"10.1007\/978-3-319-16462-5_32"},{"key":"e_1_3_2_43_2","unstructured":"John Speed Meyers. 2022. Are SBOMs Any Good? Preliminary Measurement of the Quality of Open Source Project SBOMs. Chainguard. Retrieved January 03 2023 from https:\/\/www.chainguard.dev\/unchained\/are-sboms-any-good-preliminary-measurement-of-the-quality-of-open-source-project-sboms"}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3798285","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,7]],"date-time":"2026-04-07T14:17:20Z","timestamp":1775571440000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3798285"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,7]]},"references-count":42,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3798285"],"URL":"https:\/\/doi.org\/10.1145\/3798285","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,7]]},"assertion":[{"value":"2025-09-10","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-02-02","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-07","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}