Evolutionary Multi-objective Optimization for Contextual Adversarial Example Generation
Shasha Zhou, Mingyu Huang, Yanan Sun, Ke Li
Abstract
The emergence of the ‘code naturalness’ concept, which suggests that software code shares statistical properties with natural language, paves the way for deep neural networks (DNNs) in software engineering (SE). However, DNNs can be vulnerable to certain human imperceptible variations in the input, known as adversarial examples (AEs), which could lead to adverse model performance. Numerous attack strategies have been proposed to generate AEs in the context of computer vision and natural language processing, but the same is less true for source code of programming languages in SE. One of the challenges is derived from various constraints including syntactic, semantics and minimal modification ratio. These constraints, however, are subjective and can be conflicting with the purpose of fooling DNNs. This paper develops a multi-objective adversarial attack method (dubbed MOAA ), a tailored NSGA-II, a powerful evolutionary multi-objective (EMO) algorithm, integrated with CodeT5 to generate high-quality AEs based on contextual information of the original code snippet. Experiments on 5 source code tasks with 10 datasets of 6 different programming languages show that our approach can generate a diverse set of high-quality AEs with promising transferability. In addition, using our AEs, for the first time, we provide insights into the internal behavior of pre-trained models.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 3e35391d-510e-4121-abef-d0e68bdd94fbCited by top-tier papers3
- XOXO: Stealthy Cross-Origin Context Poisoning Attacks against AI Coding AssistantsAdam Storek, Mukur Gupta, Noopur Bhatt, Aditya Gupta et al.ACL 2026 · 5 citations
- HogVul: Black-box Adversarial Code Generation Framework Against LM-based Vulnerability DetectorsJingxiao Yang, Ping He, Tianyu Du, Sun Bing et al.AAAI 2026 · 2 citations
- Rethinking Performance Analysis for Configurable Software Systems: A Case Study from a Fitness Landscape PerspectiveMingyu Huang, Peili Mao, Ke LiISSTA 2025 · 1 citation
Related papers
- Natural Attack for Pre-trained Models of CodeZhou Yang, Jieke Shi, Junda He, David LoICSE 2022 · 150 citations
- DIP: Dead code Insertion based Black-box Attack for Programming Language ModelCheolWon Na, YunSeok Choi, Jee-Hyong LeeACL 2023 · 13 citations
- AACEGEN: Attention Guided Adversarial Code Example Generation for Deep Code ModelsZhong Li, Chong Zhang, Minxue Pan, Tian Zhang et al.ASE 2024 · 4 citations
- Code Difference Guided Adversarial Example Generation for Deep Code ModelsZhao Tian, Junjie Chen, Zhi JinASE 2023 · 27 citations
- An Extensive Study on Adversarial Attack against Pre-trained Models of CodeXiaohu Du, Ming Wen, Zichao Wei, Shangwen Wang et al.FSE 2023 · 21 citations
