arrow
返回

Software vulnerabilities in TensorFlow-based deep learning applications

delete2023-01-01
delete10
delete
OA
AI
K
Katarzyna Filus *
J
Joanna Domańska
DOI:10.1016/j.cose.2022.102948delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Usage of Deep Learning (DL) methods is ubiquitous. It is common in the DL/Artificial Intelligence domain to use 3rd party software. TensorFlow is one of the most popular Machine Learning (ML) platforms. Every software product is a subject to security failures which often result from software vulnerabilities. In this paper, we focus on threats related to 6 common types of threats in TensorFlow implementation. We iden-tify them using Common Weakness Enumeration. We analyze more than 100 vulnerability instances. We focus on vulnerabilities' severity, impact on confidentiality, integrity and availability, as well as possible results of exploitation. We also use Orthogonal Defect Classification (ODC). The results show that a ma-jority of vulnerabilities are caused by missing/incorrect checking statements, however some fixes require more advanced algorithmic changes. Static Analysis Tools tested in our study show low effectiveness in detecting known vulnerabilities in TensorFlow, but we provide some recommendations based on the ob-tained alerts to improve overall code quality. Further analysis of vulnerabilities helped us to understand and characterize different vulnerability types and provide a set of observations. We believe that these observations can be useful for the creators of new static analysis tools as a source of inspiration and to build the test cases. We also aim to draw the programmers' attention to the prevalence of vulnerabilities in deep learning applications and a low effectiveness of automatic tools to find software vulnerabilities in such products.(c) 2022 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ )
Keyword:
Software vulnerability
TensorFlow
Deep learning
Security
Static analysis
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

P
Polish Academy of Sciences
学者数:
3.0W
论文数: 3.1W
被引数: 3.1W
引用论文

引用论文

CrossTalk opposing view: Which technique for controlling resistant hypertension? Carotid chemoreceptor denervation/modulation
err2014-09-15
err0
errOAAI
errL. E. K. Ratcliffe; W. Pijacka; F. D. McBryde; A. P. Abdala; D. J. Moraes; P. A. Sobotka; E. C. Hart; K. Narkiewicz; A. K. Nightingale; J. F. R. Paton
err分享
err收藏
Revisiting the VCCFinder approach for the identification of vulnerability-contributing commits
err2021-03-29
err7
errOAAI
errRiom, Timothe; Sawadogo, Arthur; Allix, Kevin; Bissyande, Tegawende F.; Moha, Naouel; Klein, Jacques
err分享
err收藏
Efficient Feature Selection for Static Analysis Vulnerability Prediction
errSENSORS
IF3.5
err2021-02-06
err21
errOAAI
errFilus, Katarzyna; Boryszko, Pawel; Domanska, Joanna; Siavvas, Miltiadis; Gelenbe, Erol
err分享
err收藏
Differential Substrate Recognition by Maltose Binding Proteins Influenced by Structure and Dynamics
err2018-09-11
err0
errOAAI
errShantanu Shukla; Khushboo Bafna; Caeley Gullett; Dean A. A. Myles; Pratul K. Agarwal; Matthew J. Cuneo
err分享
err收藏
err分享
err收藏
Selective vasodilation produced by renal denervation in adult spontaneously hypertensive rats.
err1986-05-01
err0
errOAAI
errA D Krueger; J Y Lee; P C Yang; S E Papaioannou; G M Walsh
err分享
err收藏
学者 查看更多内容