arrow
返回

CAGFuzz: Coverage-Guided Adversarial Generative Fuzzing Testing for Image-Based Deep Learning Systems

delete2022-11-01
delete12
PRE
AI
张
张鹏程 (Pengcheng Zhang) *
任斌 封面图
任斌 (Bin Ren)
H
Hai Dong
Q
Qiyin Dai
DOI:10.1109/TSE.2021.3124006delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Deep Neural Network (DNN) driven technologies have been extensively employed in various aspects of our life. Nevertheless, the applied DNN always fails to detect erroneous behaviors, which may lead to serious problems. Several approaches have been proposed to enhance adversarial examples for automatically testing deep learning (DL) systems, such as image-based DL systems. However, the approaches contain the following two limitations. First, existing approaches only take into account small perturbations on adversarial examples, they design and generate adversarial examples for a certain particular DNN model. This might hamper the transferability of the examples for other DNN models. Second, they only use shallow features (e.g., pixel-level features) to judge the differences between the generated adversarial examples and the original examples. The deep features, which contain high-level semantic information, such as image object categories and scene semantics, are completely neglected. To address these two problems, we propose CAGFuzz, a Coverage-guided Adversarial Generative Fuzzing testing approach for image-based DL systems. CAGFuzz is able to generate adversarial examples for mainstream DNN models to discover their potential errors. First, we train an Adversarial Example Generator (AEG) based on general datasets. AEG only considers the data characteristics to alleviate the transferability problem. Second, we extract the deep features of the original and adversarial examples, and constrain the adversarial examples by cosine similarity to ensure that the deep features of the adversarial examples remain unchanged. Finally, we use the adversarial examples to retrain the models. Based on several standard datasets, we design a set of dedicated experiments to evaluate CAGFuzz. The experimental results show that CAGFuzz can detect more hidden errors, enhance the accuracy of the target DNN models, and generate adversarial examples with higher transferability.
Keyword:
Testing
Fuzzing
Generators
Neurons
Feature extraction
Perturbation methods
Semantics
Deep neural network
fuzz testing
adversarial example
coverage criteria

期刊

IEEE Transactions on Software Engineering 封面图
IEEE Transactions on Software Engineering
IF:
5.6
论文数:
2.9K
被引数:
1.1W

机构

H
Hohai University
学者数:
2.3W
论文数: 1.8W
被引数: 2.1W
引用论文

引用论文

Kimberlite Terminology and Classification金伯利岩术语和分类
err2013-07-12
err0
PREAI
errB. H. Scott Smith; T. E. Nowicki; J. K. Russell; K. J. Webb; R. H. Mitchell; C. M. Hetman; M. Harder; E. M. W. Skinner; Jv. A. Robey
err分享
err收藏
Stability of adaptive behaviors in middle-school children with autism spectrum disorders
err2007-10-01
err0
PREAI
errRobin L. Gabriels; Bonnie Jean Ivers; Dina E. Hill; John A. Agnew; John McNeill
err分享
err收藏
ImageNet Large Scale Visual Recognition ChallengeImageNet大规模视觉识别挑战
err2015-04-11
err2.7W
PREAI
errRussakovsky, Olga; Deng, Jia; Su, Hao; Krause, Jonathan; Satheesh, Sanjeev; Ma, Sean; Huang, Zhiheng; Karpathy, Andrej; Khosla, Aditya; Bernstein, Michael; Berg, Alexander C.; Fei-Fei, Li
err分享
err收藏
学者 查看更多内容