Transferability of Athena across ecosystems and vulnerability databases

Determine whether the performance gains achieved by Athena for Java vulnerability-affected library identification transfer to other software ecosystems and vulnerability databases, including OSV and Snyk.

Background

The empirical evaluation uses only the VulLib-Java benchmark, although Athena’s knowledge-graph schema is based on language-independent entities and relations such as CVE, CPE, and CWE. The paper states that analogous metadata from PyPI, npm, or pkg.go.dev could be substituted without architectural changes, but the available evidence does not establish that the observed gains generalize beyond Java or beyond the evaluated vulnerability sources. The authors therefore identify cross-ecosystem and cross-database transfer as unresolved.

References

Whether the gains observed for Java transfer to other ecosystems and vulnerability databases (e.g., OSV and Snyk) remains open.

Athena: Vulnerability-Affected Library Identification via Knowledge Graph Completion  (2609.01187 - Duy et al., 1 Sep 2026) in Limitations, paragraph “Ecosystem and dataset”