Visual Graph Representations for Supply Chain Risk Detection: A Novel Study on npm Packages
Resumo
Identifying structural signals in software supply chain dependencies remains an open research challenge. We propose an exploratory approach: representing dependency graphs as adjacency-matrix images, making computer vision tools, texture analysis, Fourier transforms, spatial statistics, directly applicable. For 30 npm packages (15 with documented CVEs, 15 with no documented CVEs in the same period), we convert each dependency subgraph into a normalised 64× 64 image and extract 16 visual features (LBP, GLCM, Fourier, basic stats). In this exploratory sample, six visual features show nominal group separation (p < 0.05), while none of the nine classical graph metrics does. LBP features are the most discriminative, reaching a medium effect size (|d| = 0.740) under spectral node ordering.Referências
Bronstein, M. M., Bruna, J., LeCun, Y., Szlam, A., and Vandergheynst, P. (2017). Geometric deep learning: Going beyond Euclidean data. IEEE Signal Processing Magazine, 34(4):18–42.
Decan, A., Mens, T., and Constantinou, E. (2018). On the impact of security vulnerabilities in the npm package dependency network. In Proceedings of the 15th International Conference on Mining Software Repositories (MSR), pages 181–191. ACM.
Google (2021). OSV: Open source vulnerabilities database. [link]. Accessed: 2025.
Haralick, R. M., Shanmugam, K., and Dinstein, I. (1973). Textural features for image classification. IEEE Transactions on Systems, Man, and Cybernetics, SMC-3(6):610–621.
Ladisa, P., Plate, H., Martinez, M., and Barais, O. (2023). SoK: Taxonomy of attacks on open-source software supply chains. In Proceedings of the IEEE Symposium on Security and Privacy (S&P), pages 1509–1526. IEEE.
Libraries.io (2021). Libraries.io open source repository and dependency metadata. [link]. Accessed: 2025.
Mann, H. B. and Whitney, D. R. (1947). On a test of whether one of two random variables is stochastically larger than the other. Annals of Mathematical Statistics, 18(1):50–60.
Nataraj, L., Karthikeyan, S., Jacob, G., and Manjunath, B. (2011). Malware images: Visualization and automatic classification. In Proceedings of the 8th International Symposium on Visualization for Cyber Security (VizSec), pages 1–7. ACM.
Ojala, T., Pietikäinen, M., and Mäenpää, T. (2002). Multiresolution gray-scale and rotation invariant texture classification with local binary patterns. IEEE Transactions on Pattern Analysis and Machine Intelligence, 24(7):971–987.
Shannon, C. E. (1948). A mathematical theory of communication. Bell System Technical Journal, 27(3):379–423.
von Luxburg, U. (2007). A tutorial on spectral clustering. Statistics and Computing, 17(4):395–416.
Williams, L., Benedetti, G., Hamer, S., Paramitha, R., Rahman, I., Tamanna, M., Tystahl, G., Zahan, N., Morrison, P., Acar, Y., Cukier, M., Kästner, C., Kapravelos, A., Wermke, D., and Enck, W. (2025). Research directions in software supply chain security. ACM Trans. Softw. Eng. Methodol., 34(5).
Zimmermann, M., Staicu, C.-A., Tenny, C., and Pradel, M. (2019). Small world with high risks: A study of security threats in the npm ecosystem. In Proceedings of the USENIX Security Symposium, pages 995–1010. USENIX Association.
Decan, A., Mens, T., and Constantinou, E. (2018). On the impact of security vulnerabilities in the npm package dependency network. In Proceedings of the 15th International Conference on Mining Software Repositories (MSR), pages 181–191. ACM.
Google (2021). OSV: Open source vulnerabilities database. [link]. Accessed: 2025.
Haralick, R. M., Shanmugam, K., and Dinstein, I. (1973). Textural features for image classification. IEEE Transactions on Systems, Man, and Cybernetics, SMC-3(6):610–621.
Ladisa, P., Plate, H., Martinez, M., and Barais, O. (2023). SoK: Taxonomy of attacks on open-source software supply chains. In Proceedings of the IEEE Symposium on Security and Privacy (S&P), pages 1509–1526. IEEE.
Libraries.io (2021). Libraries.io open source repository and dependency metadata. [link]. Accessed: 2025.
Mann, H. B. and Whitney, D. R. (1947). On a test of whether one of two random variables is stochastically larger than the other. Annals of Mathematical Statistics, 18(1):50–60.
Nataraj, L., Karthikeyan, S., Jacob, G., and Manjunath, B. (2011). Malware images: Visualization and automatic classification. In Proceedings of the 8th International Symposium on Visualization for Cyber Security (VizSec), pages 1–7. ACM.
Ojala, T., Pietikäinen, M., and Mäenpää, T. (2002). Multiresolution gray-scale and rotation invariant texture classification with local binary patterns. IEEE Transactions on Pattern Analysis and Machine Intelligence, 24(7):971–987.
Shannon, C. E. (1948). A mathematical theory of communication. Bell System Technical Journal, 27(3):379–423.
von Luxburg, U. (2007). A tutorial on spectral clustering. Statistics and Computing, 17(4):395–416.
Williams, L., Benedetti, G., Hamer, S., Paramitha, R., Rahman, I., Tamanna, M., Tystahl, G., Zahan, N., Morrison, P., Acar, Y., Cukier, M., Kästner, C., Kapravelos, A., Wermke, D., and Enck, W. (2025). Research directions in software supply chain security. ACM Trans. Softw. Eng. Methodol., 34(5).
Zimmermann, M., Staicu, C.-A., Tenny, C., and Pradel, M. (2019). Small world with high risks: A study of security threats in the npm ecosystem. In Proceedings of the USENIX Security Symposium, pages 995–1010. USENIX Association.
Publicado
01/09/2026
Como Citar
LIMA, Paulo Vitor C.; QUINCOZES, Silvio E.; NASCIMENTO, Marcelo Z. do.
Visual Graph Representations for Supply Chain Risk Detection: A Novel Study on npm Packages. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 1464-1470.
DOI: https://doi.org/10.5753/sbseg.2026.28944.
