DECODE: Dynamic Exploration for Constraint-Guided Vulnerability Discovery in Deep Learning Operators
Haotong Liu, Zhi Wang, Zhuohang Liu, Wanpeng Li
摘要
The security and robustness of deep learning (DL) frameworks are vital, as vulnerabilities in low-level operator implementations can lead to serious reliability and security risks. While testing has proven effective in uncovering such flaws, existing techniques struggle to accurately capture the complex input constraints required by DL operators, resulting in low test coverage and missed bugs. To address this, we propose DECODE, a fully automated framework that performs efficient and precise constraint extraction through dynamic analysis. DECODE models operator-specific input requirements by observing valid execution traces and exploring constraint relationships. It then uses these refined constraints to generate high-quality test inputs capable of exposing memory error vulnerabilities. We evaluated DECODE on two widely used DL frameworks - TensorFlow and PyTorch - where it uncovered 96 bugs (54 in TensorFlow and 42 in PyTorch), 82 of which have been confirmed by developers. Compared to state-of-the-art tools, DECODE detected 41, 75, and 87 more bugs than IvySyn, DocTer, and DeepREL, respectively, demonstrating its superior effectiveness in uncovering previously undetected vulnerabilities.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- ACETest: Automated Constraint Extraction for Testing Deep Learning OperatorsJingyi Shi, Yang Xiao, Yuekang Li, Yeting Li 等ISSTA 2023 · 被引用 24 次
- DocTer: documentation-guided fuzzing for testing deep learning API functionsDanning Xie, Yitong Li, Mijung Kim, Hung Viet Pham 等ISSTA 2022 · 被引用 72 次
- IvySyn: Automated Vulnerability Discovery in Deep Learning FrameworksNeophytos Christou, Di Jin, Vaggelis Atlidakis, Baishakhi Ray 等USENIX Security 2023
- NeuRI: Diversifying DNN Generation via Inductive Rule InferenceJiawei Liu, Jinjun Peng, Yuyao Wang, Lingming ZhangFSE 2023 · 被引用 24 次
- Fuzzing deep-learning libraries via automated relational API inferenceYinlin Deng, Chenyuan Yang, Anjiang Wei, Lingming ZhangFSE 2022 · 被引用 83 次
