[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-117543-en":3,"doc-seo-117543-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},117543,2336464648746,"Skyler","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","A machine learning approach to vulnerability detection combining software metrics and topic modelling - Evidence from smart contracts","This paper introduces a software vulnerability detection methodology that merges structural and semantic analysis using software metrics and topic modelling. The study evaluates smart contracts as the application domain, emphasizing their structural properties and the occurrence of known security vulnerabilities. It determines the most informative metrics, benchmarks multiple classifiers for binary and multi-label vulnerability tasks, and improves performance by integrating topic modelling with NonNegative Matrix Factorisation. Experiments on Ethereum Solidity contracts show cyclomatic complexity, nesting depth, and function calls correlate with vulnerabilities, with Random Forest achieving strong AUC, accuracy, and F1 outcomes.","Machine Learning with Applications 22 (2025) 100759  \n| A machine learning approach to vulnerability detection combining software metrics and topic modelling: Evidence from smart contracts\u003Cbr>Giacomo Ibbaa,b, Rumyana Neykovab, Marco Ortua, Roberto Tonelli a, Steve Counsellb, Giuseppe Destefanisc ,∗\u003Cbr>a University of Cagliari, Cagliari, Italy\u003Cbr>b Brunel University of London, London, United Kingdom c University College London, London, United Kingdom |  |  |\n| --- | --- | --- |\n| A R T I C L E I N F O |  | A B S T R A C T |\n| Keywords:\u003Cbr>Vulnerability detection Software metrics Topic modelling Machine learning Source code analysis Smart contracts |  | This paper introduces a methodology for software vulnerability detection that combines structural and semantic analysis through software metrics and topic modelling. We evaluate the approach using smart contracts as a case study, focusing on their structural properties and the presence of known security vulnerabilities. We identify the most relevant metrics for vulnerability detection, evaluate multiple machine learning classifiers for both binary and multi-label classification, and improve classification performance by integrating topic modelling techniques.\u003Cbr>Our analysis shows that metrics such as cyclomatic complexity, nesting depth, and function calls are strongly associated with vulnerability presence. Using these metrics, the Random Forest classifier achieved strong performance in binary classification (AUC: 0.982, accuracy: 0.977, F1-score: 0.808) and multi-label classification (AUC: 0.951, accuracy: 0.729, F1-score: 0.839). The addition of topic modelling using NonNegative Matrix Factorisation further improved results, increasing the F1-score to 0.881. The evaluation is conducted on Ethereum smart contracts written in Solidity. |\n\n1. Introduction  \nUnderstanding how structural and semantic properties of code relate to security vulnerabilities remains a challenge in software analysis. While software metrics have long been used to support defect prediction in conventional systems (Okutan & Yıldız, 2014; Singh & Chug, 2017; Singh et al., 2010), their role in identifying security-related issues is less clear, particularly when applied to newer software artefacts. This paper introduces a methodology that combines metrics-based analysis with topic modelling to improve the detection and classification of software vulnerabilities.  \nWe evaluate this approach in the context of smart contracts, which are programs deployed on a blockchain that execute automatically when predefined conditions are met. Like conventional software components, they are written in programming languages such as Solidity and can be analysed through structural metrics. They differ from traditional software in that they operate in a decentralised environment where code directly manages financial assets, and once deployed they cannot be updated through standard release cycles. These characteristics increase the impact of vulnerabilities, since flaws may lead to  \nimmediate and irreversible financial losses (Atzei et al., 2017; Aufiero et al., 2024; Zheng et al., 2018). This connection highlights why techniques from software engineering, such as the use of metrics and semantic analysis, are applicable to smart contracts while also requiring adaptation to address their specific execution and risk environment.  \nAlthough metrics such as complexity, coupling, and cohesion are widely studied in traditional systems (Chidamber & Kemerer, 1994; Zhang et al., 2007a), their effectiveness in smart contracts is still uncertain. Preliminary studies focusing on metric-based analysis of smart contracts are limited (Tonelli et al., 2023), and their connection to security has not been examined in detail (Destefanis et al., 2018; Pinna et al., 2019). Moreover, the potential benefit of incorporating semantic information, such as lexical patterns or latent topics (Ortu et al., 2022), remains largely unexplored.  \nThis paper pre","cbCaiaZiHKeo6LHH","https://ap.wps.com/l/cbCaiaZiHKeo6LHH","pdf",2743073,1,18,"English","en",105,"# Introduction\n## Research questions and evaluation setup\n## Software metrics and classifiers\n## Topic modelling integration and results","[{\"question\":\"What core idea does the paper propose for vulnerability detection?\",\"answer\":\"It combines structural analysis via software metrics with semantic information from topic modelling to detect and classify vulnerabilities.\"},{\"question\":\"How is the approach evaluated in the study?\",\"answer\":\"The evaluation uses Ethereum smart contracts written in Solidity, focusing on structural properties and known vulnerability presence.\"},{\"question\":\"Which metrics and modelling choices lead to the best reported performance?\",\"answer\":\"Metrics like cyclomatic complexity, nesting depth, and function calls are strongly associated with vulnerabilities; Random Forest performs well, and adding NonNegative Matrix Factorisation for topic modelling further improves F1-scores.\"}]","A machine learning approach to vulnerability detection combining software metrics and topic modelling - Evidence from smart contracts | PDF",1785676855,45,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"a-machine-learning-approach-to-vulnerability-detection-combining-software-metrics-and-topic-modelling-evidence-from-smart-contracts","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/a-machine-learning-approach-to-vulnerability-detection-combining-software-metrics-and-topic-modelling-evidence-from-smart-contracts/117543/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What core idea does the paper propose for vulnerability detection?","Question",{"text":75,"@type":76},"It combines structural analysis via software metrics with semantic information from topic modelling to detect and classify vulnerabilities.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How is the approach evaluated in the study?",{"text":80,"@type":76},"The evaluation uses Ethereum smart contracts written in Solidity, focusing on structural properties and known vulnerability presence.",{"name":82,"@type":73,"acceptedAnswer":83},"Which metrics and modelling choices lead to the best reported performance?",{"text":84,"@type":76},"Metrics like cyclomatic complexity, nesting depth, and function calls are strongly associated with vulnerabilities; Random Forest performs well, and adding NonNegative Matrix Factorisation for topic modelling further improves F1-scores.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]