[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-seo-128815-105":3,"detail-sidebar-cat-0-en-105":81,"doc-detail-128815-en":130},{"code":4,"msg":5,"data":6},0,"ok",{"site_id":7,"language":8,"slug":9,"title":10,"keywords":11,"description":12,"schema_data":13,"social_meta":74,"head_meta":76,"extra_data":78,"updated_unix":80},105,"en","a-machine-learning-approach-to-vulnerability-detection-combining-software-metrics-and-topic-modelling-evidence-from-smart-contracts-128815","A machine learning approach to vulnerability detection combining software metrics and topic modelling - Evidence from smart contracts","","This paper presents a methodology for software vulnerability detection that integrates structural and semantic analysis using software metrics and topic modelling. Smart contracts are used as a case study, with experiments examining structural properties and the presence of known security vulnerabilities. The study determines the most relevant metrics, compares multiple machine learning classifiers for binary and multi-label tasks, and improves performance by adding topic modelling. Cyclomatic complexity, nesting depth, and function calls correlate strongly with vulnerabilities, and Random Forest achieves strong results, further boosted by NonNegative Matrix Factorisation.",{"@graph":14,"@context":73},[15,34,56],{"@type":16,"itemListElement":17},"BreadcrumbList",[18,23,27,31],{"item":19,"name":20,"@type":21,"position":22},"https://docshare.wps.com","Home","ListItem",1,{"item":24,"name":25,"@type":21,"position":26},"https://docshare.wps.com/document/","Document",2,{"item":28,"name":29,"@type":21,"position":30},"https://docshare.wps.com/document/research-report/","Research & Report",3,{"item":32,"name":10,"@type":21,"position":33},"https://docshare.wps.com/document/a-machine-learning-approach-to-vulnerability-detection-combining-software-metrics-and-topic-modelling-evidence-from-smart-contracts-128815/128815/",4,{"url":32,"name":10,"@type":35,"image":36,"author":41,"headline":10,"publisher":44,"fileFormat":47,"inLanguage":8,"description":12,"dateModified":48,"datePublished":49,"encodingFormat":47,"isAccessibleForFree":50,"interactionStatistic":51},"DigitalDocument",{"url":37,"@type":38,"width":39,"height":40},"https://docshare.wps.com/thumbnails/a-machine-learning-approach-to-vulnerability-detection-combining-software-metrics-and-topic-modelling-evidence-from-smart-contracts-128815/128815.png","ImageObject",300,407,{"name":42,"@type":43},"Violet","Person",{"url":19,"name":45,"@type":46},"DocShare","Organization","application/pdf","2026-09-17","2026-08-06",true,{"@type":52,"interactionType":53,"userInteractionCount":55},"InteractionCounter",{"@type":54},"ViewAction",8,{"@type":57,"mainEntity":58},"FAQPage",[59,65,69],{"name":60,"@type":61,"acceptedAnswer":62},"How does the proposed approach combine software metrics and topic modelling for vulnerability detection?","Question",{"text":63,"@type":64},"It performs structural analysis using software metrics and adds semantic signals via topic modelling. The topic modelling component is integrated to improve classification performance beyond metrics alone.","Answer",{"name":66,"@type":61,"acceptedAnswer":67},"Which software metrics are reported as most associated with vulnerabilities?",{"text":68,"@type":64},"Cyclomatic complexity, nesting depth, and function calls show strong association with the presence of vulnerabilities in the studied smart contracts.",{"name":70,"@type":61,"acceptedAnswer":71},"What is the impact of topic modelling on classifier performance?",{"text":72,"@type":64},"Adding topic modelling using NonNegative Matrix Factorisation improves results, raising the multi-label F1-score to 0.881 compared with the metrics-only baseline.","https://schema.org",{"og:url":32,"og:type":75,"og:title":10,"og:site_name":45,"og:description":12},"article",{"robots":77,"canonical":32},"index,follow",{"doc_id":79,"site_id":7},128815,1786003653,{"code":4,"msg":82,"data":83},"success",[84,88,92,96,101,106,111,114,119,122,126],{"id":22,"doc_module":4,"doc_module_name":25,"category_name":85,"show_sort_weight":86,"slug":87},"Story & Novel",90,"story-novel",{"id":26,"doc_module":4,"doc_module_name":25,"category_name":89,"show_sort_weight":90,"slug":91},"Literature",80,"literature",{"id":33,"doc_module":4,"doc_module_name":25,"category_name":93,"show_sort_weight":94,"slug":95},"Exam",70,"exam",{"id":97,"doc_module":4,"doc_module_name":25,"category_name":98,"show_sort_weight":99,"slug":100},5,"Comic",60,"comic",{"id":102,"doc_module":4,"doc_module_name":25,"category_name":103,"show_sort_weight":104,"slug":105},6,"Technology",50,"technology",{"id":107,"doc_module":4,"doc_module_name":25,"category_name":108,"show_sort_weight":109,"slug":110},7,"Healthcare",40,"healthcare",{"id":55,"doc_module":4,"doc_module_name":25,"category_name":29,"show_sort_weight":112,"slug":113},30,"research-report",{"id":115,"doc_module":4,"doc_module_name":25,"category_name":116,"show_sort_weight":117,"slug":118},9,"Religion & Spirituality",20,"religion-spirituality",{"id":117,"doc_module":4,"doc_module_name":25,"category_name":120,"show_sort_weight":117,"slug":121},"World Cup","world-cup",{"id":123,"doc_module":4,"doc_module_name":25,"category_name":124,"show_sort_weight":123,"slug":125},10,"Lifestyle","lifestyle",{"id":127,"doc_module":4,"doc_module_name":25,"category_name":128,"show_sort_weight":97,"slug":129},19,"General","general",{"code":4,"msg":82,"data":131},{"doc_id":79,"user_id":132,"nickname":42,"user_avatar":133,"doc_module":4,"category_id":55,"category_name":29,"doc_title":10,"doc_description":12,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":55,"is_deleted":4,"is_public":22,"is_downloadable":22,"audit_status":22,"page_count":139,"language":140,"language_code":8,"site_id":7,"html_lang":8,"table_of_contents":141,"faqs":142,"seo_title":143,"seo_description":12,"update_tm":80,"read_time":144},1099523885336,"https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c","Machine Learning with Applications 22 (2025) 100759  \n| A machine learning approach to vulnerability detection combining software metrics and topic modelling: Evidence from smart contracts\u003Cbr>Giacomo Ibbaa,b, Rumyana Neykovab, Marco Ortua, Roberto Tonelli a, Steve Counsellb, Giuseppe Destefanisc ,∗\u003Cbr>a University of Cagliari, Cagliari, Italy\u003Cbr>b Brunel University of London, London, United Kingdom c University College London, London, United Kingdom |  |  |\n| --- | --- | --- |\n| A R T I C L E I N F O |  | A B S T R A C T |\n| Keywords:\u003Cbr>Vulnerability detection Software metrics Topic modelling Machine learning Source code analysis Smart contracts |  | This paper introduces a methodology for software vulnerability detection that combines structural and semantic analysis through software metrics and topic modelling. We evaluate the approach using smart contracts as a case study, focusing on their structural properties and the presence of known security vulnerabilities. We identify the most relevant metrics for vulnerability detection, evaluate multiple machine learning classifiers for both binary and multi-label classification, and improve classification performance by integrating topic modelling techniques.\u003Cbr>Our analysis shows that metrics such as cyclomatic complexity, nesting depth, and function calls are strongly associated with vulnerability presence. Using these metrics, the Random Forest classifier achieved strong performance in binary classification (AUC: 0.982, accuracy: 0.977, F1-score: 0.808) and multi-label classification (AUC: 0.951, accuracy: 0.729, F1-score: 0.839). The addition of topic modelling using NonNegative Matrix Factorisation further improved results, increasing the F1-score to 0.881. The evaluation is conducted on Ethereum smart contracts written in Solidity. |\n\n1. Introduction  \nUnderstanding how structural and semantic properties of code relate to security vulnerabilities remains a challenge in software analysis. While software metrics have long been used to support defect prediction in conventional systems (Okutan & Yıldız, 2014; Singh & Chug, 2017; Singh et al., 2010), their role in identifying security-related issues is less clear, particularly when applied to newer software artefacts. This paper introduces a methodology that combines metrics-based analysis with topic modelling to improve the detection and classification of software vulnerabilities.  \nWe evaluate this approach in the context of smart contracts, which are programs deployed on a blockchain that execute automatically when predefined conditions are met. Like conventional software components, they are written in programming languages such as Solidity and can be analysed through structural metrics. They differ from traditional software in that they operate in a decentralised environment where code directly manages financial assets, and once deployed they cannot be updated through standard release cycles. These characteristics increase the impact of vulnerabilities, since flaws may lead to  \nimmediate and irreversible financial losses (Atzei et al., 2017; Aufiero et al., 2024; Zheng et al., 2018). This connection highlights why techniques from software engineering, such as the use of metrics and semantic analysis, are applicable to smart contracts while also requiring adaptation to address their specific execution and risk environment.  \nAlthough metrics such as complexity, coupling, and cohesion are widely studied in traditional systems (Chidamber & Kemerer, 1994; Zhang et al., 2007a), their effectiveness in smart contracts is still uncertain. Preliminary studies focusing on metric-based analysis of smart contracts are limited (Tonelli et al., 2023), and their connection to security has not been examined in detail (Destefanis et al., 2018; Pinna et al., 2019). Moreover, the potential benefit of incorporating semantic information, such as lexical patterns or latent topics (Ortu et al., 2022), remains largely unexplored.  \nThis paper pre","cbCaifCw56TJYMmB","https://ap.wps.com/l/cbCaifCw56TJYMmB","pdf",2743073,18,"English","# Introduction\n## Research questions\n## Evaluation setup and classifiers","[{\"question\":\"How does the proposed approach combine software metrics and topic modelling for vulnerability detection?\",\"answer\":\"It performs structural analysis using software metrics and adds semantic signals via topic modelling. The topic modelling component is integrated to improve classification performance beyond metrics alone.\"},{\"question\":\"Which software metrics are reported as most associated with vulnerabilities?\",\"answer\":\"Cyclomatic complexity, nesting depth, and function calls show strong association with the presence of vulnerabilities in the studied smart contracts.\"},{\"question\":\"What is the impact of topic modelling on classifier performance?\",\"answer\":\"Adding topic modelling using NonNegative Matrix Factorisation improves results, raising the multi-label F1-score to 0.881 compared with the metrics-only baseline.\"}]","A machine learning approach to vulnerability detection combining software metrics and topic modelling - Evidence from smart contracts | PDF",45]