This post is part of our research archive and is a selected publication. Although Armatyr was founded in 2026, members of our team have been conducting and publishing research in medical device and hospital IT security for over a decade. We maintain this archive to provide context for our experience and contributions to the field.

The authors propose a zero-knowledge approach that lets a medical device manufacturer prove an SBOM meets a regulator’s requirements without disclosing the underlying component details. Building on their own prior finding that even de-identified medical device SBOMs can be used to generate functional attack blueprints, they design a Zero-Knowledge Proof framework that lets hospital IT staff and regulators verify properties like “no critical CVEs present” without ever seeing the raw SBOM. Their full abstract is quoted below:

Recent regulatory initiatives require medical device manufacturers to produce and maintain Software Bills of Materials (SBOMs) to enhance visibility into the software supply chain and associated vulnerability risks. However, public release of SBOMs introduces a new attack surface by exposing component-level information that adversaries can exploit. Our prior work demonstrates that even de-identified SBOMs can be paired with public vulnerability databases and large language models (LLMs) to generate functional attack blueprints, reducing adversarial effort and successfully exploiting 77.8% of known vulnerabilities in a controlled environment. This transparency v. exposure dilemma motivates the need for privacy-preserving validation mechanisms. We propose a Zero-Knowledge Proof (ZKP) framework that enables stakeholders to verify SBOM properties, such as the absence of critical vulnerabilities, without disclosing sensitive supply chain details.

Jiarou Deng, Yang Yang, and Michael Rushanan. “A Zero-Knowledge Framework for Confidential and Verifiable SBOM Validation.” Annual Computer Security Applications Conference (ACSAC), 2025.