返回
Software vulnerabilities in TensorFlow-based deep learning applications
DOI:10.1016/j.cose.2022.102948.png)
摘要
En 中文
Usage of Deep Learning (DL) methods is ubiquitous. It is common in the DL/Artificial Intelligence domain to use 3rd party software. TensorFlow is one of the most popular Machine Learning (ML) platforms. Every software product is a subject to security failures which often result from software vulnerabilities. In this paper, we focus on threats related to 6 common types of threats in TensorFlow implementation. We iden-tify them using Common Weakness Enumeration. We analyze more than 100 vulnerability instances. We focus on vulnerabilities' severity, impact on confidentiality, integrity and availability, as well as possible results of exploitation. We also use Orthogonal Defect Classification (ODC). The results show that a ma-jority of vulnerabilities are caused by missing/incorrect checking statements, however some fixes require more advanced algorithmic changes. Static Analysis Tools tested in our study show low effectiveness in detecting known vulnerabilities in TensorFlow, but we provide some recommendations based on the ob-tained alerts to improve overall code quality. Further analysis of vulnerabilities helped us to understand and characterize different vulnerability types and provide a set of observations. We believe that these observations can be useful for the creators of new static analysis tools as a source of inspiration and to build the test cases. We also aim to draw the programmers' attention to the prevalence of vulnerabilities in deep learning applications and a low effectiveness of automatic tools to find software vulnerabilities in such products.(c) 2022 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ )
Keyword:
Software vulnerability
TensorFlow
Deep learning
Security
Static analysis
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
DouBiGRU-A: Software defect detection algorithm based on attention mechanism and double BiGRU
COMPUTERS & SECURITY
IF5.4
Differential Substrate Recognition by Maltose Binding Proteins Influenced by Structure and Dynamics
Biochemistry
IF0
Software Vulnerability Analysis and Discovery Using Machine-Learning and Data-Mining Techniques: A Survey使用机器学习和数据挖掘技术进行软件漏洞分析和发现: 调查
Vulnerable Code Detection Using Software Metrics and Machine Learning使用软件度量和机器学习进行易受攻击的代码检测
IEEE ACCESS
IF3.6

