This post is part of our research archive and is a selected publication. Although Armatyr was founded in 2026, members of our team have been conducting and publishing research in medical device and hospital IT security for over a decade. We maintain this archive to provide context for our experience and contributions to the field.

The authors study the tension between publishing SBOMs for transparency and the risk that the same documents give attackers a ready-made map of a healthcare system’s exploitable software components. Using a de-identified, FDA-compliant SBOM from a real medical device, they show that even a minimally detailed SBOM can be fed into a large language model to automatically generate a working attack blueprint. The results suggest that public SBOM disclosure, as currently practiced, can meaningfully lower the cost and effort required to exploit a device. Their full abstract is quoted below:

The U.S. Food and Drug Administration (FDA) emphasizes the importance of cybersecurity transparency in ensuring the safety and effectiveness of medical devices. Specifically, the FDA recommends that manufacturers provide a continuously updated Software Bill of Materials (SBOM), for example, through a web portal, to support shared responsibility in cybersecurity risk management, vulnerability assessment, and mitigation. While we support this principle, we caution against the public release of SBOMs without first evaluating the potential risks introduced by adversarial access. In this paper, we present a case study using a de-identified, FDA-compliant SBOM derived from a real-world medical device. We extract known vulnerabilities (CVEs) from the SBOM and automatically generate an attack blueprint using a large language model (LLM). We validate this approach in a controlled containerized environment, demonstrating that even a minimally detailed SBOM can reduce adversary effort and streamline exploitation planning. And, we provide results that illustrate the risk of SBOM transparency, underscoring the need for rethinking public disclosure.

Jiarou Deng, Yang Yang, and Michael Rushanan. “The SBOM Transparency v. Exposure Dilemma: A Case Study on Adversarial Access to Public SBOMs in Healthcare.” Proceedings of the Healthcare Security Workshop (HealthSec), 2025.