arrow
Return

Software vulnerabilities in TensorFlow-based deep learning applications

delete2023-01-01
delete10
delete
OA
AI
K
Katarzyna Filus *
J
Joanna Domańska
DOI:10.1016/j.cose.2022.102948delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Usage of Deep Learning (DL) methods is ubiquitous. It is common in the DL/Artificial Intelligence domain to use 3rd party software. TensorFlow is one of the most popular Machine Learning (ML) platforms. Every software product is a subject to security failures which often result from software vulnerabilities. In this paper, we focus on threats related to 6 common types of threats in TensorFlow implementation. We iden-tify them using Common Weakness Enumeration. We analyze more than 100 vulnerability instances. We focus on vulnerabilities' severity, impact on confidentiality, integrity and availability, as well as possible results of exploitation. We also use Orthogonal Defect Classification (ODC). The results show that a ma-jority of vulnerabilities are caused by missing/incorrect checking statements, however some fixes require more advanced algorithmic changes. Static Analysis Tools tested in our study show low effectiveness in detecting known vulnerabilities in TensorFlow, but we provide some recommendations based on the ob-tained alerts to improve overall code quality. Further analysis of vulnerabilities helped us to understand and characterize different vulnerability types and provide a set of observations. We believe that these observations can be useful for the creators of new static analysis tools as a source of inspiration and to build the test cases. We also aim to draw the programmers' attention to the prevalence of vulnerabilities in deep learning applications and a low effectiveness of automatic tools to find software vulnerabilities in such products.(c) 2022 The Author(s). Published by Elsevier Ltd. This is an open access article under the CC BY license ( http://creativecommons.org/licenses/by/4.0/ )
Keywords:
Software vulnerability
TensorFlow
Deep learning
Security
Static analysis
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

P
Polish Academy of Sciences
Scholars:
3.0W
Papers: 3.1W
Citations: 3.1W
Cited Papers

Cited Papers

CrossTalk opposing view: Which technique for controlling resistant hypertension? Carotid chemoreceptor denervation/modulation
err2014-09-15
err0
errOAAI
errL. E. K. Ratcliffe; W. Pijacka; F. D. McBryde; A. P. Abdala; D. J. Moraes; P. A. Sobotka; E. C. Hart; K. Narkiewicz; A. K. Nightingale; J. F. R. Paton
errShare
errSave
Revisiting the VCCFinder approach for the identification of vulnerability-contributing commits
err2021-03-29
err7
errOAAI
errRiom, Timothe; Sawadogo, Arthur; Allix, Kevin; Bissyande, Tegawende F.; Moha, Naouel; Klein, Jacques
errShare
errSave
Efficient Feature Selection for Static Analysis Vulnerability Prediction
errSENSORS
IF3.5
err2021-02-06
err21
errOAAI
errFilus, Katarzyna; Boryszko, Pawel; Domanska, Joanna; Siavvas, Miltiadis; Gelenbe, Erol
errShare
errSave
Evaluating and comparing memory error vulnerability detectors
err2021-09-01
err11
errOAAI
errNong, Yu; Cai, Haipeng; Ye, Pengfei; Li, Li; Chen, Feng
errShare
errSave
Differential Substrate Recognition by Maltose Binding Proteins Influenced by Structure and Dynamics
err2018-09-11
err0
errOAAI
errShantanu Shukla; Khushboo Bafna; Caeley Gullett; Dean A. A. Myles; Pratul K. Agarwal; Matthew J. Cuneo
errShare
errSave
Vulnerable Code Detection Using Software Metrics and Machine Learning
err2020-01-01
err15
errOAAI
errMedeiros, Nadia; Ivaki, Naghmeh; Costa, Pedro; Vieira, Marco
errShare
errSave
Selective vasodilation produced by renal denervation in adult spontaneously hypertensive rats.
err1986-05-01
err0
errOAAI
errA D Krueger; J Y Lee; P C Yang; S E Papaioannou; G M Walsh
errShare
errSave
researcher View more