Reproducible research. Stronger insights.

Every literature reviewhas a denominator.

Toda revisão de literaturatem um denominador.

Before screening begins, a review must say which papers could have entered it. TopVenues turns that set into a declared, frozen and executable object: 20 cybersecurity venues, one versioned snapshot, one SHA-256, and one command that reproduces every count.

Antes da triagem, uma revisão precisa dizer quais artigos poderiam ter entrado nela. O TopVenues transforma esse conjunto em um objeto declarado, congelado e executável: 20 veículos de cibersegurança, um snapshot versionado, um SHA-256 e um comando que reproduz cada contagem.

20 declared venues converge on one snapshot USENIX Security2,1032.103 ACM CCS1,9721.972 TrustCom1,9151.915 ACM Computing Surveys1,8401.840 IEEE S&P1,4171.417 NDSS1,0591.059 IEEE Comm. Surveys & Tutorials842842 ACM ASIA CCS837837 ESORICS599599 ACSAC509509 IEEE EURO S&P421421 IEEE CNS381381 ACM CODASPY316316 ACM WiSec315315 RAID290290 ACM SACMAT204204 IEEE SaTML127127 ACM AISec7777 USENIX WOOT4444 FnT Privacy and Security1818 security-20-v515,286 records15.286 registros20 venues · 2019–202620 veículos · 2019–2026sha256 2487ea98…a9fe58
  1. USENIX Security2,1032.103
  2. ACM CCS1,9721.972
  3. TrustCom1,9151.915
  4. ACM Computing Surveys surveysurveys1,8401.840
  5. IEEE S&P1,4171.417
  6. NDSS1,0591.059
  7. IEEE Communications Surveys & Tutorials surveysurveys842842
  8. ACM ASIA CCS837837
  9. ESORICS599599
  10. ACSAC509509
  11. IEEE EURO S&P421421
  12. IEEE CNS381381
  13. ACM CODASPY316316
  14. ACM WiSec315315
  15. RAID290290
  16. ACM SACMAT204204
  17. IEEE SaTML127127
  18. ACM AISec7777
  19. USENIX WOOT4444
  20. Foundations and Trends in Privacy and Security surveysurveys1818
Figure 1. The current release. 20 declared venues converge on one snapshot. Line weight follows the number of records per venue; the 3 dashed lines are survey venues.Survey venues are tagged. Every value on this page about the current release is read from data/profiles/security-20-v5/manifest.json when the page is built.
Figura 1. A versão atual. 20 veículos declarados convergem em um único snapshot. A espessura da linha acompanha o número de registros por veículo; as 3 linhas tracejadas são periódicos de surveys.Os periódicos de surveys estão marcados. Todo valor desta página sobre a versão atual é lido de data/profiles/security-20-v5/manifest.json quando a página é gerada.
Current releaseVersão atual security-20-v5 TopVenues v1.14.0 · snapshot built 2026-09-22 · a maintained corpus, not the denominator of a paper (those are frozen).TopVenues v1.14.0 · snapshot gerado em 2026-09-22 · um corpus mantido, não o denominador de um artigo (esses estão congelados).
recordsregistros
15,28615.286
venues: 17 security, 3 surveyveículos: 17 de segurança, 3 de surveys
20
declared windowjanela declarada
2019–2026
with abstract (14,394)com resumo (14.394)
94.2%94,2%
with a BibTeX entrycom entrada BibTeX
100%100%

01MethodMétodo

Declared. Frozen. Executable.Declarado. Congelado. Executável.

scope

DeclaredDeclarado

The scope is written down before anything is counted: a venue list and a year window in a versioned configuration file.

O escopo é escrito antes de qualquer contagem: uma lista de veículos e uma janela de anos em um arquivo de configuração versionado.

snapshot

FrozenCongelado

Each release ships a compressed SQLite snapshot with a published SHA-256. A number cited in a paper stays bound to it when the tool changes.

Cada versão traz um snapshot SQLite comprimido com SHA-256 publicado. Um número citado em artigo continua preso a ele quando a ferramenta muda.

reproduce.sh

ExecutableExecutável

One command verifies the snapshot, runs the tests, starts the interface and reproduces the counts. No API key, GPU or institutional access; offline once installed.

Um comando verifica o snapshot, roda os testes, sobe a interface e reproduz as contagens. Sem chave de API, GPU ou acesso institucional; offline depois de instalado.

Scope is decided by venue, not by topicO escopo é decidido pelo veículo, não pelo tema

A paper is in the corpus because it appeared in a declared venue within the window, not because a classifier judged it to be about security. 17 venues are security venues and form a core of 12,586 records. The other 3 are survey venues (ACM Computing Surveys, IEEE Communications Surveys & Tutorials, Foundations and Trends in Privacy and Security), kept because reviews lean on surveys; they are labelled cross-area and one filter removes them.

Um artigo está no corpus porque saiu em um veículo declarado dentro da janela, não porque um classificador julgou que ele trata de segurança. 17 veículos são de segurança e formam um núcleo de 12.586 registros. Os outros 3 são periódicos de surveys (ACM Computing Surveys, IEEE Communications Surveys & Tutorials, Foundations and Trends in Privacy and Security), mantidos porque revisões se apoiam em surveys; eles têm o rótulo cross-area e um filtro os remove.

Gaps are reported, not hiddenLacunas são relatadas, não escondidas

DBLP supplies metadata and BibTeX, not abstracts. Abstracts come from open scholarly APIs and publisher pages, and coverage is reported per venue: ESORICS, for instance, has 39 abstracts for 599 records. A venue-stratified manual audit of 200 abstracts found 84.5% usable (95% Wilson interval 78.8%–88.9%).

O DBLP fornece metadados e BibTeX, não resumos. Os resumos vêm de APIs acadêmicas abertas e de páginas das editoras, e a cobertura é relatada por veículo: o ESORICS, por exemplo, tem 39 resumos para 599 registros. Uma auditoria manual estratificada por veículo, com 200 resumos, encontrou 84,5% utilizáveis (intervalo de Wilson de 95%: 78,8%–88,9%).

Per-venue coverage (20 venues)Cobertura por veículo (20 veículos)
VenueVeículoAreaÁreaRecordsRegistrosAbstractsResumosCoverageCoberturaYearsAnos
USENIX Securitysecuritysegurança2,1032.1032,0562.05697.8%97,8%2019–2025
ACM CCSsecuritysegurança1,9721.9721,9711.97199.9%99,9%2019–2025
TrustComsecuritysegurança1,9151.9151,9121.91299.8%99,8%2019–2025
ACM Computing Surveyssurveysurveys1,8401.8401,8391.83999.9%99,9%2019–2026
IEEE S&Psecuritysegurança1,4171.4171,3971.39798.6%98,6%2019–2026
NDSSsecuritysegurança1,0591.0591,0581.05899.9%99,9%2019–2026
IEEE Communications Surveys & Tutorialssurveysurveys84284281381396.6%96,6%2019–2026
ACM ASIA CCSsecuritysegurança83783782782798.8%98,8%2019–2026
ESORICSsecuritysegurança59959939396.5%6,5%2019–2025
ACSACsecuritysegurança509509509509100.0%100,0%2019–2025
IEEE EURO S&Psecuritysegurança421421421421100.0%100,0%2019–2026
IEEE CNSsecuritysegurança381381381381100.0%100,0%2019–2025
ACM CODASPYsecuritysegurança31631628128188.9%88,9%2019–2026
ACM WiSecsecuritysegurança31531527127186.0%86,0%2019–2026
RAIDsecuritysegurança29029022222276.6%76,6%2019–2025
ACM SACMATsecuritysegurança204204204204100.0%100,0%2019–2026
IEEE SaTMLsecuritysegurança127127747458.3%58,3%2023–2025
ACM AISecsecuritysegurança7777737394.8%94,8%2019–2023
USENIX WOOTsecuritysegurança4444282863.6%63,6%2025–2026
Foundations and Trends in Privacy and Securitysurveysurveys18181818100.0%100,0%2020–2025

02ToolFerramenta

A literature workbench on a fixed population.Uma bancada de literatura sobre uma população fixa.

A local web interface, in English or Portuguese, and a command-line tool over the same snapshot. Every aggregate links back to the records behind it.

Uma interface web local, em português ou inglês, e uma ferramenta de linha de comando sobre o mesmo snapshot. Todo agregado leva de volta aos registros que o sustentam.

Search page with ranked results for LLM in the Security top-4 scopePágina de busca com resultados ranqueados para LLM no escopo Top-4 de segurança
Ranked searchBM25 over titles and abstracts, with an explicit Security top-4 scope: ACM CCS, IEEE S&P, USENIX Security and NDSS.
Busca ranqueadaBM25 sobre títulos e resumos, com escopo explícito Top-4 de segurança: ACM CCS, IEEE S&P, USENIX Security e NDSS.
Two charts: papers per year and share of the year's corpus for LLM in the Security top-4Dois gráficos: artigos por ano e participação no corpus do ano para LLM no Top-4 de segurança
Topic trendsHow often a topic appears per year, in absolute counts and as a share of that year's corpus.
Tendências de temaCom que frequência um tema aparece por ano, em contagem absoluta e como fração do corpus daquele ano.
Researcher Radar with author trajectories for a topicRadar de pesquisadores com a trajetória de um autor para um tema
Researcher RadarExact-identity trajectories and direct coauthorship for a topic. Corpus observations, not measures of quality or impact.
Radar de pesquisadoresTrajetórias por identidade exata e coautoria direta para um tema. Observações do corpus, não medidas de qualidade ou impacto.
Evidence page showing snapshot identity and the manual abstract auditPágina de evidências com a identidade do snapshot e a auditoria manual dos resumos
Evidence and claim boundariesWhat the snapshot verifies, and what needs a separate protocol, such as the manual abstract audit.
Evidências e limites das afirmaçõesO que o snapshot verifica e o que exige um protocolo separado, como a auditoria manual de resumos.

The same operations from the command lineAs mesmas operações pela linha de comando

python -m src.cli --profile security-20-v5 search --rank "LLM security" \
  --tier-scope "Security top-4" --limit 20
python -m src.cli --profile security-20-v5 export --format bibtex --tech "fuzzing" \
  --tier-scope "Security top-4" -o fuzzing-tier1.bib

03FindingsResultados

What a fixed denominator makes measurable.O que um denominador fixo torna mensurável.

Two measurements from Paper A, taken on its May 2026 snapshot of 9,925 records. They are reproduced by that paper's release, not recomputed on the current corpus.

Duas medições do Artigo A, feitas sobre seu snapshot de maio de 2026, com 9.925 registros. Elas são reproduzidas pela versão daquele artigo, não recalculadas sobre o corpus atual.

29.2%29,2%

of the 2,537 papers published at the four CORE A* security venues in 2024–2025 had a matching arXiv cs.CR preprint (742 papers).

dos 2.537 artigos publicados nos quatro veículos CORE A* de segurança em 2024–2025 tinham um preprint correspondente no arXiv cs.CR (742 artigos).

The preprint came a median of 154 days before the conference. The rate held between 28.4% and 31.1% across the four venues.

O preprint veio, em mediana, 154 dias antes da conferência. A taxa ficou entre 28,4% e 31,1% nos quatro veículos.

16.5×16,5×

relative risk for a triage filter over 5,185 cs.CR preprints from 2023: preprints with a coauthor already published in the top-4 later appeared there 15.9% of the time, against 0.97% for the rest.

de risco relativo para um filtro de triagem sobre 5.185 preprints cs.CR de 2023: preprints com um coautor já publicado no top-4 apareceram depois nele em 15,9% dos casos, contra 0,97% dos demais.

The filter reads 36% of the preprints and keeps 90.3% of those that later reached the top-4.

O filtro lê 36% dos preprints e mantém 90,3% dos que depois chegaram ao top-4.

16.5× or 2.5×? Same filter, two baselines.16,5× ou 2,5×? Mesmo filtro, duas linhas de base.

16.5×16,5×
15.9% ÷ 0.97%15,9% ÷ 0,97%
flagged against unflagged preprints: relative risksinalizados contra não sinalizados: risco relativo
2.5×2,5×
15.9% ÷ 6.4%15,9% ÷ 6,4%
flagged against all preprints: conventional liftsinalizados contra todos os preprints: lift convencional

A correlational triage signal, not a judgement of quality. The controls, the author-position variants and the replication on the 2022 cohort are in Table 5 of Paper A.

Um sinal correlacional de triagem, não um juízo de qualidade. Os controles, as variantes por posição de autoria e a replicação na coorte de 2022 estão na Tabela 5 do Artigo A.

04PapersArtigos

Published evidence does not move.Evidência publicada não se move.

The software evolves. Each paper stays bound to one repository, one release, one snapshot and one SHA-256, and its numbers are reproduced from that snapshot, never from whatever the current release ships.

O software evolui. Cada artigo fica preso a um repositório, uma versão, um snapshot e um SHA-256, e seus números são reproduzidos desse snapshot, nunca do que a versão atual traz.

  1. paperartigo
  2. repositoryrepositório
  3. release
  4. snapshot
  5. sha-256
  6. commandcomando

Paper A · Main track, SBSeg 2026Artigo A · Trilha principal, SBSeg 2026

TopVenues: A Reproducible Corpus and Tooling Substrate for Cybersecurity Literature Reviews

Anais do XXVI Simpósio Brasileiro de Cibersegurança (SBSeg 2026), pp.p. 1150–1165

RepositoryRepositório
sidneibarbieri/topVenues
ReleaseVersão
sbseg2026-camera-ready
SnapshotSnapshot
May 2026 · 9,925 records · 11 venuesmaio de 2026 · 9.925 registros · 11 veículos
SHA-256
0f4dbaa97d0cf39abd2340adb3280643df090b5de9cd1a29bff39a0b53ef64cd
TestsTestes
252 tests252 testes
ReproduceReproduzir
git clone https://github.com/sidneibarbieri/topVenues
cd topVenues
git checkout sbseg2026-camera-ready
bash reproduce.sh

Paper B · Tools track, SBSeg 2026Artigo B · Salão de Ferramentas, SBSeg 2026

TopVenues: An Executable Corpus and Research Tool for Cybersecurity Literature Reviews

Anais Estendidos do XXVI Simpósio Brasileiro de Cibersegurança (SBSeg 2026), pp.p. 234–241

RepositoryRepositório
sidneibarbieri/topvenues-tool (printed in the paper; archived, read-onlyimpresso no artigo; arquivado, somente leitura)
ReleaseVersão
sbseg2026-sf-submission-r1
ProfilePerfil
security-20
SnapshotSnapshot
20,305 records · 20 venues · 2017–202620.305 registros · 20 veículos · 2017–2026
SHA-256
5a35bd6e3ec6845a0fde4cc3d6aa05b1db04e511cb39e783eeaee2cea7493b08
Printed in the paperImpresso no artigo
git clone https://github.com/sidneibarbieri/topvenues-tool
cd topvenues-tool
bash reproduce.sh --profile security-20
Same snapshot, hereMesmo snapshot, aqui
git clone https://github.com/sidneibarbieri/topVenues
cd topVenues
bash reproduce.sh --profile security-20

Current release · not a paperVersão atual · não é um artigo

The corpus TopVenues ships todayO corpus que o TopVenues distribui hoje

security-20-v5 succeeds security-20; it does not correct Paper B. Exact-resource deduplication and a declared 2019–2026 window make it a different population, with its own identity.

security-20-v5 sucede o security-20; não corrige o Artigo B. A deduplicação por recurso exato e a janela declarada de 2019–2026 fazem dele outra população, com identidade própria.

RepositoryRepositório
sidneibarbieri/topVenues
ProfilePerfil
security-20-v5 · 15,286 records · 20 venues · 2019–202615.286 registros · 20 veículos · 2019–2026
SHA-256
2487ea98bfae38982d9752e56391bbdb83820f134c01b8555dfc7d26d8a9fe58
Parquet
sidneibarbieri/topvenues · Hugging Face

One repositoryUm repositório

TopVenues lives in topVenues: the current tool on its main branch, Paper A frozen at its release. Until v1.10.0 the tool was developed in topvenues-tool, the address Paper B prints. That repository is archived and still answers the printed command. Continuous integration re-runs both papers on every change, so quality only moves forward.

O TopVenues mora em topVenues: a ferramenta atual na branch principal e o Artigo A congelado na sua versão. Até a v1.10.0 a ferramenta foi desenvolvida em topvenues-tool, o endereço que o Artigo B imprime. Aquele repositório está arquivado e continua atendendo ao comando impresso. A integração contínua reproduz os dois artigos a cada mudança, então a qualidade só avança.

About the DOIsSobre os DOIs

SBC assigned both DOIs in the proceedings metadata, but they are not yet registered with Crossref, so doi.org does not resolve them. The SOL links are the working ones.

A SBC atribuiu os dois DOIs nos metadados dos anais, mas eles ainda não foram registrados no Crossref, então o doi.org não os resolve. Os links do SOL são os que funcionam.

The widest exploratory corpus is on Hugging Face; it is not the denominator of any paper.

O corpus exploratório mais amplo está no Hugging Face; ele não é o denominador de nenhum artigo.

05StartComeçar

One command, then a local interface.Um comando, depois uma interface local.

Python 3.11–3.14, Git and Bash. No API key, GPU or institutional access.

Python 3.11–3.14, Git e Bash. Sem chave de API, GPU ou acesso institucional.

git clone --depth 1 --branch v1.14.0 https://github.com/sidneibarbieri/topVenues.git
cd topVenues
bash reproduce.sh --profile security-20-v5

Then open the interfaceDepois, abra a interface

source .venv/bin/activate
python -m streamlit run web/app.py

Only the dataSó os dados

The same snapshot as a Parquet export on Hugging Face, with the same SHA-256 recorded on its card.

O mesmo snapshot como exportação Parquet no Hugging Face, com o mesmo SHA-256 registrado no cartão.

from datasets import load_dataset

corpus = load_dataset("sidneibarbieri/topvenues", split="train")
security = corpus.filter(lambda paper: paper["area"] == "security")

With an AI assistantCom um assistente de IA

Claude Code or Codex can drive the CLI and answer from the snapshot, citing with the exported BibTeX and stating every denominator. Guide and prompts.

O Claude Code ou o Codex usam a CLI e respondem a partir do snapshot, citando com o BibTeX exportado e declarando cada denominador. Guia e prompts.

Code: MIT. Metadata and BibTeX: DBLP, CC0. Abstracts remain under their publishers' terms.

Código: MIT. Metadados e BibTeX: DBLP, CC0. Os resumos seguem os termos de suas editoras.

06DemoDemo

The tool end to end, in two and a half minutes.A ferramenta de ponta a ponta, em dois minutos e meio.

The list that moves on its own, the idea, one command on a fresh clone, search and export, where the corpus is silent, and what a fixed list makes measurable. Narration in English, captions in English and Brazilian Portuguese. It shows v1.14.0 on security-20-v5.

A lista que muda sozinha, a ideia, um comando num clone novo, busca e exportação, onde o corpus se cala, e o que uma lista fixa torna mensurável. Narração em inglês, legendas em inglês e português do Brasil. Mostra a v1.14.0 sobre o security-20-v5.

07CiteCitar

Cite the tool paper, and name the release you used.Cite o artigo da ferramenta e informe a versão que você usou.

Used TopVenues to search, build a review corpus, export references or rank authors? Cite Paper B, the tools-track paper, and name the release and profile, such as v1.14.0 · security-20-v5, so a reader can reopen the same snapshot. Using or building on the corpus method or its measurements? Cite Paper A. When both apply, cite both.

Usou o TopVenues para buscar, montar o corpus de uma revisão, exportar referências ou ranquear autores? Cite o Artigo B, da trilha de ferramentas, e informe a versão e o perfil, como v1.14.0 · security-20-v5, para que o leitor reabra o mesmo snapshot. Usa ou estende o método do corpus ou suas medições? Cite o Artigo A. Quando os dois se aplicam, cite os dois.

Paper B · using the toolArtigo B · uso da ferramenta
@inproceedings{barbieri2026topvenuestool,
  author    = {Sidnei Barbieri and {\'A}gney Lopes Roth Ferraz and Louren{\c{c}}o Alves {Pereira J{\'u}nior}},
  title     = {{TopVenues}: An Executable Corpus and Research Tool for Cybersecurity Literature Reviews},
  booktitle = {Anais Estendidos do XXVI Simp{\'o}sio Brasileiro de Ciberseguran{\c{c}}a (SBSeg 2026)},
  pages     = {234--241},
  year      = {2026},
  publisher = {Sociedade Brasileira de Computa{\c{c}}{\~a}o},
  address   = {Porto Alegre, RS, Brasil},
  doi       = {10.5753/sbseg_estendido.2026.33733},
  url       = {https://sol.sbc.org.br/index.php/sbseg_estendido/article/view/44470}
}
Paper A · method and measurementsArtigo A · método e medições
@inproceedings{barbieri2026topvenues,
  author    = {Sidnei Barbieri and {\'A}gney Lopes Roth Ferraz and Louren{\c{c}}o Alves {Pereira J{\'u}nior}},
  title     = {{TopVenues}: A Reproducible Corpus and Tooling Substrate for Cybersecurity Literature Reviews},
  booktitle = {Anais do XXVI Simp{\'o}sio Brasileiro de Ciberseguran{\c{c}}a (SBSeg 2026)},
  pages     = {1150--1165},
  year      = {2026},
  publisher = {Sociedade Brasileira de Computa{\c{c}}{\~a}o},
  address   = {Porto Alegre, RS, Brasil},
  doi       = {10.5753/sbseg.2026.29056},
  url       = {https://sol.sbc.org.br/index.php/sbseg/article/view/44350}
}

Found TopVenues useful? Cite it, and star the repository so that other researchers find it.

O TopVenues foi útil? Cite-o e dê uma estrela no repositório para que outros pesquisadores o encontrem.

Star on GitHubEstrela no GitHub