Sep 2026· African Journal of Advances in Science and Technology Research· 0 citations· 10 references
Abstract
The growing complexity of software ecosystems has made the Software Supply Chain (SSC) a primary target for cyberattacks, as evidenced by SolarWinds, Log4Shell, and the XZ Utils backdoor. Traditional Software Composition Analysis (SCA) and static scanning tools are reactive and poorly suited to detecting novel or provenance-based threats in dependencies, build pipelines, and package registries. This study proposes and evaluates an Artificial Intelligence (AI)-driven framework for software supply chain security and risk assessment that integrates a Graph Neural Network (GNN) for dependency-graph risk propagation, a Transformer encoder for source-code anomaly detection, and a Long Short-Term Memory (LSTM) network for modelling temporal drift in build and release pipelines. Outputs from the three learners are combined through an ensemble fusion layer to generate an interpretable risk score for each component. The study adopted a design-science and quantitative approach. The framework was trained and evaluated on a curated dataset comprising 6.4 million GitHub commits, 5,000 registry packages, 38,600 CVE-to-package mappings, 2,313 synthetic Software Bills of Materials (SBOMs), and 312 malicious artefacts. Results show that the hybrid ensemble achieved 96.3% accuracy, 95.6% precision, 94.8% recall, an F1-score of 95.2%, and an AUC-ROC of 0.98, outperforming GNN, LSTM, Random Forest, SVM, and Logistic Regression baselines by 6–18 percentage points across metrics. Combining structural, semantic, and temporal signals improves detection of malicious and high-risk components over single-model approaches, while producing risk scores aligned with NIST SSDF and the EU Cyber Resilience Act. The paper concludes with recommendations for AI-driven risk scoring in DevSecOps and SBOM governance.
Agile methods continue to gain popularity. In particular, the Scrum method appears to be on the verge of becoming a de-facto standard in the industry, leading the so called Agile movement. While there are success stories and recommendations, there is little scientifically valid evidence of the challenges in the adoptio...
A. Marchenko, P. Abrahamsson· Agile Conference· 59 citations· ⚡11
A comprehensive taxonomy of the challenges faced when a medium-scale organization decided to adopt software platforms is provided, namely: business challenges, organizational challenges, technical challenges, and people challenges.
Yaser Ghanam, F. Maurer, P. Abrahamsson· Information and Software Tec...· 41 citations· ⚡3
It is shown that high article processing charges are not sufficiently justified by the publishers, which often lack transparency and may prevent authors from adopting OA.
D. Graziotin, Xiaofeng Wang, P. Abrahamsson· Scientometrics· 21 citations· ⚡1
MCGLPPI, a novel geometric representation learning framework that combines graph neural networks (GNNs) with the MARTINI molecular coarse-grained (CG) model to predict overall PPI properties accurately and efficiently, offers an effective and efficient solution for PPI overall property predictions.
Yang Yue, Shu Li, Yihua Cheng et al.· bioRxiv· 15 citations
PepPCBench enables a robust evaluation of PFNN-based methods and supports their continued development for peptide-protein structure prediction, and highlights the influence of peptide length, conformational flexibility, and training set similarity on prediction accuracy.
Si-Long Zhai, Huifeng Zhao, Ji-Ke Wang et al.· Journal of Chemical Informat...· 13 citations· ⚡1
OmniMol is presented, a framework using hypergraphs to improve predictions of molecular properties, addressing challenges of imperfect data annotation and enhancing model explainability, and achieves state-of-the-art performance in properties prediction.
Assistant Professor Pat Pataranutaporn describes a new interface that lets everyday users glimpse inside an AI's neural network before their chatbot ever says a word.
Microsoft Research Blog· microsoft.comJul 13, 2026
Cryptographic code supports vital protections in modern computing systems. Learn how a new method helps verify code as developers write it while preserving speed and adaptability as it gets implemented and evolves. The post Verifying Rust cryptography in SymCrypt, from standards to code appeared first on Microsoft Research.
MIT News · Artificial Intelligence· news.mit.eduJul 6, 2026
PhD student Rachel Sava, winner of the Envisioning the Future of Computing Prize, explores transformative improvements and dystopian risks of neural technology.