Skip to content

Securing the open-source ecosystem: AI-enhanced and explainable supply chain security for reliable software development

Oct 2026 · Scientific Reports · 0 citations
Software Engineering Research

Abstract

Modern software supply chains face increasing risks from vulnerable and anomalous dependencies, necessitating automated and interpretable detection methods integrated within Continuous Integration and Continuous Deployment (CI/CD) workflows. Open-source software (OSS) ecosystems are increasingly targeted by sophisticated attacks—including AI model poisoning, dependency confusion, contributor hijacking, and transitive dependency anomalies—that often evade traditional CVE-centric tools such as Snyk and Dependabot. These reactive solutions are primarily designed for known vulnerabilities and may exhibit high false-positive rates when applied to behavioral anomalies, while also lacking interpretable and actionable guidance for developers. This limitation creates a critical barrier to reliable and secure software development in modern DevSecOps environments. To address this gap, this paper introduces XAI-SCS, an intelligent, explainable decision-support framework for OSS supply chain security that performs metadata-driven behavioral risk assessment to proactively identify anomalous package activity. A hybrid CNN–LSTM–Autoencoder architecture achieves strong anomaly-detection performance on the held-out test set (F1 = 0.91), with low repeated-run variability (mean F1 = 0.90 ± 0.02 across five runs) on a federated dataset of 12,000 npm/PyPI package versions, primarily trained using CVE-linked labels and GAN-simulated poisoning samples. A separate held-out evaluation set of 240 manually curated real-world non-CVE OSS supply-chain incidents was used exclusively for external generalization assessment. Accordingly, the non-CVE results are interpreted as preliminary evidence of transferability to selected metadata-visible behavioral anomalies rather than comprehensive real-world non-CVE threat coverage. To support transparent developer decision-making, SHAP-based explanations and counterfactual remediation suggestions produced high perceived clarity (4.3 ± 0.4/5) and actionability (4.1 ± 0.5/5) and self-reported remediation intent (96%, n  = 82). However, these findings reflect developer perceptions in a controlled study and do not yet demonstrate measured improvements in real-world remediation time, fix completion, or vulnerability resolution within operational DevSecOps teams. Optional high-assurance deployment extensions, including Federated Continual Learning, zero-knowledge attestation via zk-SNARKs, and post-quantum secure enclaves, are presented as exploratory architectural pathways for future privacy-preserving, verifiable, and confidential deployment, rather than as part of the core empirical evaluation. Embedded in controlled, CI/CD-representative workflows with 0.8-second average latency, XAI-SCS remains competitive with CVE-centric tools on known-vulnerability cases while providing preliminary evidence of complementary metadata-level behavioral risk screening in GAN-simulated and limited curated non-CVE evaluation subsets. The comparison is therefore interpreted as evidence that XAI-SCS can complement CVE-centric SCA tools by adding metadata-level behavioral screening and developer-facing explanations, rather than replacing or universally outperforming tools such as Snyk and Dependabot. This work’s primary contribution is a metadata-driven, CI/CD-integrated intelligent decision-support framework that delivers high-accuracy behavioral anomaly detection (F1 = 0.91) and transparent, developer-facing explanations (clarity 4.3/5, remediation intent 96%) for OSS supply chain risk assessment. Optional high-assurance deployment extensions (federated learning, cryptographic attestation, secure enclaves) are discussed separately and do not form part of the core empirical evaluation.

Read PDF

Similar papers

#computer vision Review Sep 2017

Agile Software Development Methods: Review and Analysis

This publication proposes a definition and a classification of agile software development approaches and analyses ten software development methods that can be characterized as being "agile" against the defined criterion.

P. Abrahamsson, O. Salo, Jussi Ronkainen et al. · 727 citations · ⚡54
#computer vision Jun 2008

The impact of agile practices on communication in software development

The study shows that agile practices improve both informal and formal communication, but indicates that, in larger development situations involving multiple external stakeholders, a mismatch of adequate communication mechanisms can sometimes even hinder the communication.

M. Pikkarainen, Jukka Haikara, O. Salo et al. · 401 citations · ⚡48
#machine learning Review Open access Oct 2014

Software development in startup companies: A systematic mapping study

The results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.

Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al. · 394 citations · ⚡54
#computer vision Review Mar 2008

Agile methods in European embedded software development organisations: a survey on the actual use and usefulness of Extreme Programming and Scrum

The results show that the embedded industry has been able to apply agile methods in its development processes and that the appreciation of the agile methods and their individual practices appears to increase once adopted and applied in practice.

O. Salo, P. Abrahamsson · 238 citations · ⚡9
#computer vision Open access Jul 2017

What happens when software developers are (un)happy

Consequences of happiness and unhappiness that are beneficial and detrimental for developers' mental well-being, the software development process, and the produced artifacts are found.

D. Graziotin, Fabian Fagerholm, Xiaofeng Wang et al. · 236 citations · ⚡13
#computer vision Open access Oct 2004

Mobile-D: an agile approach for mobile application development

The Mobile-D approach is briefly outlined here and the experiences gained from four case studies are discussed, which helped develop an agile development approach for mobile application development.

P. Abrahamsson, Antti Hanhineva, H. Hulkko et al. · 225 citations · ⚡18

Related blog posts

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

GPT-Lab Sep 23, 2026

Requirements Don’t Live in Isolation: What We’re Exploring with Req-Space

Requirements in large systems rarely exist in isolation. Their meaning depends on the wider project context - other requirements, policies, decisions, tests, and implementation details. That becomes especially important when AI is used for review, because spotting a possible conflict or gap is only the beginning. ReqSpace explores how AI, visualisation, and connected project context can help reviewers understand those findings, trace the relationships behind them, and focus on the questions that…

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.