Search arXivSearch

arXiv · 2402.13375

Vulnerability Webs: Systemic Risk in Software Networks

Abstract

Software development relies on code reuse to minimize costs, creating vulnerability risks through dependencies with substantial economic impact, as seen in the Crowdstrike and HeartBleed incidents. We analyze 52,897 dependencies across 16,102 Python repositories using a strategic network formation model incorporating observable and unobservable heterogeneity. Through variational approximation of conditional distributions, we demonstrate that dependency creation generates negative externalities. Vulnerability propagation, modeled as a contagion process, shows that popular protection heuristics are ineffective. AI-assisted coding, on the other hand, offers an effective alternative by enabling dependency replacement with in-house code.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Cornelius Fritz, Co-Pierre Georg, Angelo Mele, Michael Schweinberger. 2025-07-01. Vulnerability Webs: Systemic Risk in Software Networks. https://arxiv.org/abs/2402.13375

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Summary Indices in Treatment Effect Estimation

This paper studies the practice of combining multiple outcomes into a summary index to estimate a causal effect. For common estimators and index constructions, the estimate equals a weighted sum of the estimated effects on the components, with weights that are implicit and rarely reported. The paper derives the weights and shows that, for inverse-covariance-weighted indices, they can be negative and unrestricted in magnitude, so the index effect can have the opposite sign to every component effect. The paper proposes two procedures for valid inference on the index effect: a variance estimator that accounts for the data-dependent weights, and a shifted t-test that requires no such correction. Conventional t-tests of the null of no effect remain valid. Contrary to common claims, summary indices do not generally improve power. Three published studies illustrate the results.

econ.EM

The "Rough" HAR Model

This paper proposes discrete-time approximations to rough continuous-time models of realized variance (RV). The leading rough models can be viewed as autoregressive processes driven by fractional Gaussian noise. We show that the Wold representation of this noise concentrates its dependence at the first lag when the Hurst parameter is below one half. Augmenting the autoregressive (AR) and heterogeneous autoregressive (HAR) models with a first-order moving-average (MA(1)) component therefore approximates the roughness, and the MA coefficient maps almost linearly into the Hurst parameter. We refer to these extensions as the "rough" AR and "rough" HAR models. Estimating them on the log RV of ten ETFs, we find negative MA coefficients for every asset, and the implied Hurst parameters align closely with the estimates from the continuous-time models. In the HAR literature, the negative MA(1) component is a significant feature that has been largely overlooked. In out-of-sample comparisons, the "rough" models outperform their classical counterparts for nearly every asset and horizon, with the largest gains at short horizons, and their accuracy is comparable to that of the rough continuous-time models but much easier to estimate by standard off-the-shelf software.

econ.EM

Match forecasts in UEFA club competitions: Elo ratings versus Transfermarkt valuations

The pre-season strengths of European football clubs are usually measured by two proxies in the literature. Football Club Elo Ratings provide strictly performance-based Elo ratings from the early days of the European Cups, while Transfermarkt valuations are crowd-based estimates of squad market values. This paper compares them by evaluating their ability to forecast the results of matches played in the UEFA Champions League and the UEFA Europa League between the seasons 2020/21 and 2024/25. The two indicators yield almost identical out-of-sample accuracy when used separately. Combining the two measures leads to a modest improvement, but the best aggregation procedure is sensitive to the forecast target. Our results suggest that seeding based on Elo ratings would be (closely) optimal.

econ.EM