Leveraging Cross-Project Similarity for Data Augmentation and Security Bug Report Prediction

Jinfeng Ji, Geunseok Yang · IEEE Access · 2025

Introduction: Bug reports are typically classified into two categories: security and non-security. However, due to the varying levels of expertise among bug reporters, some security-related bug reports are misclassified as non-security, leading to an increased workload for developers and potential security risks. This issue highlights the need for an effective method to identify security bug reports. Methods: To address this challenge, we propose a predictive approach that based deep learning models for security bug report classification. We extract data from four open-source projects—Ambari, Camel, Derby, and Wicket—containing 56, 74, 179, and 47 security bug reports, respectively, alongside 944, 926, 821, and 953 non-security reports. Given the imbalanced dataset, we employ cross-project similarity-based data augmentation to enhance model training. We evaluate multiple deep learning models, including CNN, LSTM, GRU, Transformer, and BERT, to improve classification accuracy. Results: The experimental results demonstrate the effectiveness of our approach, achieving F1 scores ranging from 0.60 to 0.98. LSTM on Ambari and GRU on both Ambari and Camel achieved the highest performance of 0.98. The overall average F1 score across all models and datasets is 0.77, indicating a notable improvement in classification accuracy. Discussion: The results suggest that cross-project data augmentation effectively mitigates the class imbalance issue and enhances model performance. The variation in F1 scores across different models and datasets highlights the impact of model selection on classification effectiveness. LSTM and GRU consistently outperform other models, demonstrating their suitability for security bug classification tasks. Conclusion: Incorporating cross-project similarity-based data augmentation significantly improves the identification of security bug reports. This approach can help developers more effectively detect security-related issues, reducing misclassification risks and enhancing overall software security.

Read the paper · More papers on PaperTik