DECODE: Dynamic Exploration for Constraint-Guided Vulnerability Discovery in Deep Learning Operators
Haotong Liu, Zhi Wang, Zhuohang Liu, Wanpeng Li
Abstract
The security and robustness of deep learning (DL) frameworks are vital, as vulnerabilities in low-level operator implementations can lead to serious reliability and security risks. While testing has proven effective in uncovering such flaws, existing techniques struggle to accurately capture the complex input constraints required by DL operators, resulting in low test coverage and missed bugs. To address this, we propose DECODE, a fully automated framework that performs efficient and precise constraint extraction through dynamic analysis. DECODE models operator-specific input requirements by observing valid execution traces and exploring constraint relationships. It then uses these refined constraints to generate high-quality test inputs capable of exposing memory error vulnerabilities. We evaluated DECODE on two widely used DL frameworks - TensorFlow and PyTorch - where it uncovered 96 bugs (54 in TensorFlow and 42 in PyTorch), 82 of which have been confirmed by developers. Compared to state-of-the-art tools, DECODE detected 41, 75, and 87 more bugs than IvySyn, DocTer, and DeepREL, respectively, demonstrating its superior effectiveness in uncovering previously undetected vulnerabilities.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 8f4b85e6-6126-46d5-8d95-682c2c9fd9f6Related papers
- ACETest: Automated Constraint Extraction for Testing Deep Learning OperatorsJingyi Shi, Yang Xiao, Yuekang Li, Yeting Li et al.ISSTA 2023 · 24 citations
- DocTer: documentation-guided fuzzing for testing deep learning API functionsDanning Xie, Yitong Li, Mijung Kim, Hung Viet Pham et al.ISSTA 2022 · 72 citations
- IvySyn: Automated Vulnerability Discovery in Deep Learning FrameworksNeophytos Christou, Di Jin, Vaggelis Atlidakis, Baishakhi Ray et al.USENIX Security 2023
- NeuRI: Diversifying DNN Generation via Inductive Rule InferenceJiawei Liu, Jinjun Peng, Yuyao Wang, Lingming ZhangFSE 2023 · 24 citations
- Fuzzing deep-learning libraries via automated relational API inferenceYinlin Deng, Chenyuan Yang, Anjiang Wei, Lingming ZhangFSE 2022 · 83 citations
