返回
CAGFuzz: Coverage-Guided Adversarial Generative Fuzzing Testing for Image-Based Deep Learning Systems
DOI:10.1109/TSE.2021.3124006.png)
摘要
En 中文
Deep Neural Network (DNN) driven technologies have been extensively employed in various aspects of our life. Nevertheless, the applied DNN always fails to detect erroneous behaviors, which may lead to serious problems. Several approaches have been proposed to enhance adversarial examples for automatically testing deep learning (DL) systems, such as image-based DL systems. However, the approaches contain the following two limitations. First, existing approaches only take into account small perturbations on adversarial examples, they design and generate adversarial examples for a certain particular DNN model. This might hamper the transferability of the examples for other DNN models. Second, they only use shallow features (e.g., pixel-level features) to judge the differences between the generated adversarial examples and the original examples. The deep features, which contain high-level semantic information, such as image object categories and scene semantics, are completely neglected. To address these two problems, we propose CAGFuzz, a Coverage-guided Adversarial Generative Fuzzing testing approach for image-based DL systems. CAGFuzz is able to generate adversarial examples for mainstream DNN models to discover their potential errors. First, we train an Adversarial Example Generator (AEG) based on general datasets. AEG only considers the data characteristics to alleviate the transferability problem. Second, we extract the deep features of the original and adversarial examples, and constrain the adversarial examples by cosine similarity to ensure that the deep features of the adversarial examples remain unchanged. Finally, we use the adversarial examples to retrain the models. Based on several standard datasets, we design a set of dedicated experiments to evaluate CAGFuzz. The experimental results show that CAGFuzz can detect more hidden errors, enhance the accuracy of the target DNN models, and generate adversarial examples with higher transferability.
Keyword:
Testing
Fuzzing
Generators
Neurons
Feature extraction
Perturbation methods
Semantics
Deep neural network
fuzz testing
adversarial example
coverage criteria
期刊
IF:
5.6
论文数:
2.9K
被引数:
1.1W
机构
引用论文
Welding characteristics of aluminum, copper, nickel and aluminum alloy with alumina coating using ultrasonic complex vibration welding equipments铝、铜、镍及铝合金氧化铝涂层超声复合振动焊接特性研究
Thermal expansions of Ln2Zr2O7 (Ln = La, Nd, Sm, and Gd) pyrochloreLn2Zr2O7 (ln = La,Nd,Sm和Gd) 烧绿石的热膨胀
Real-world time-to-castration resistance (CR) among patients (pts) with metastatic castration-sensitive prostate cancer (mCSPC) initiating apalutamide (APA), enzalutamide (ENZ), or abiraterone acetate (ABI) from an oncology database.来自肿瘤学数据库的阿帕鲁胺 (APA),恩扎鲁他胺 (ENZ) 或醋酸阿比曲酮 (ABI) 的转移性去势敏感性前列腺癌 (mCSPC) 患者 (pts) 的真实世界时间去势抵抗 (CR)。

