Uploaded May 2026 | Updated September 2026, 1 hour ago
David Starobinski (Boston University, US), Sevval Simsek (Boston University, US)
Modern software supply chains are complex, driving the need for tools to manage dependencies and detect vulnerabilities. However, integrating these tools for unified vulnerability-dependency views is an open challenge. We introduce VDGraph, a knowledge graph methodology that merges project dependency data and vulnerability scan outputs into a holistic graph that represents the complex dependency chains leading to vulnerabilities, and is queryable. We formally analyze VDGraph’s properties and resolve dependency and vulnerability data conflicts. A proof-of-concept using CycloneDX Maven plugin and Google’s OSV-Scanner demonstrates automation and scalability across over 100 Maven-based Java projects. Queries on VDGraph uncover concentrated risk points and show that most vulnerabilities are deeply nested inside projects (i.e, depth of three or greater). We further demonstrate VDGraph’s capability of efficiently visualizing and patching vulnerable projects
---
Prof. David Starobinski is a Professor of Electrical and Computer Engineering and of Systems Engineering at Boston University, with an affiliated appointment in the Department of Computer Science. His research interests are in cybersecurity, wireless networking, blockchain and cryptocurrency, and network economics.
Sevval Simsek is a Computer Engineering PhD candidate at Boston University. She is a part of Networking and Information Systems Lab, and has been focusing on ML for Cybersecurity, and improving cybersecurity operations with graphs and algorithms.
David Starobinski (Boston University, US), Sevval Simsek (Boston University, US)
Modern software supply chains are complex, driving the need for tools to manage dependencies and detect vulnerabilities. However, integrating these tools for unified vulnerability-dependency views is an open challenge. We introduce VDGraph, a knowledge graph methodology that merges project dependency data and vulnerability scan outputs into a holistic graph that represents the complex dependency chains leading to vulnerabilities, and is queryable. We formally analyze VDGraph’s properties and resolve dependency and vulnerability data conflicts. A proof-of-concept using CycloneDX Maven plugin and Google’s OSV-Scanner demonstrates automation and scalability across over 100 Maven-based Java projects. Queries on VDGraph uncover concentrated risk points and show that most vulnerabilities are deeply nested inside projects (i.e, depth of three or greater). We further demonstrate VDGraph’s capability of efficiently visualizing and patching vulnerable projects
---
Prof. David Starobinski is a Professor of Electrical and Computer Engineering and of Systems Engineering at Boston University, with an affiliated appointment in the Department of Computer Science. His research interests are in cybersecurity, wireless networking, blockchain and cryptocurrency, and network economics.
Sevval Simsek is a Computer Engineering PhD candidate at Boston University. She is a part of Networking and Information Systems Lab, and has been focusing on ML for Cybersecurity, and improving cybersecurity operations with graphs and algorithms.










