{"id":"W4388768226","doi":"10.1002/smr.2639","title":"A catalog of metrics at source code level for vulnerability prediction: A systematic mapping study","year":2023,"lang":"en","type":"article","venue":"Journal of Software Evolution and Process","topic":"Software Engineering Research","field":"Computer Science","cited_by":4,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Saskatchewan","funders":"","keywords":"Computer science; Vulnerability (computing); Code review; Software quality; Software security assurance; Software; Data mining; Software metric; Predictive modelling; Quality (philosophy); Machine learning; Data science; Software development; Computer security; Information security","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":["metaresearch"],"consensus_categories":[],"category_scores_codex":[0.03640993,0.00108781,0.001686225,0.063259,0.001295441,0.002890704,0.001254459,0.000913912,0.001729948],"category_scores_gemma":[0.138535,0.0007714306,0.002470321,0.039607,0.000994512,0.00574104,0.002930805,0.001093588,0.0003754368],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.002769254,"about_ca_system_score_gemma":0.01257518,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.004918696,"about_ca_topic_score_gemma":0.00987088,"domain_scores_codex":[0.9769976,0.007180463,0.006777594,0.002098804,0.006521446,0.0004240461],"domain_scores_gemma":[0.7831463,0.1422155,0.02269862,0.007032628,0.04365261,0.001254448],"domain_codex":null,"domain_gemma":"methods","domain_candidate":"methods","domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"systematic_review","study_design_scores_codex":[0.0002495038,0.0002675399,0.144016,0.1487984,0.002409174,0.000735378,0.01030861,0.001256948,0.002704664,0.006397526,0.006736355,0.6761199],"study_design_scores_gemma":[0.0001881433,0.0016284,0.2558088,0.5196512,0.01759657,0.00261989,0.02974612,0.006401142,0.008636277,0.01041348,0.1469721,0.0003380052],"study_design_candidate":"systematic_review","study_design_consensus":null,"genre_codex":"review","genre_gemma":"review","genre_scores_codex":[0.3118408,0.6101332,0.04817962,0.003302013,0.0003698271,0.006262303,0.009619957,0.0003605294,0.009931755],"genre_scores_gemma":[0.6880297,0.2305223,0.06675463,0.0009349677,0.0001316008,0.006323603,0.006311463,0.0001489102,0.000842811],"genre_candidate":"review","genre_consensus":"review","teacher_disagreement_score":0.9635901,"threshold_uncertainty_score":0.1925564,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.06678564583861035,"score_gpt":0.3157488891498784,"score_spread":0.2489632433112681,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}