Neuron coverage quantifies the number and distribution of activated neurons in Deep Neural Networks (DNNs) during testing, serving as a critical metric for evaluating DNN adequacy. It reveals the internal logic of models and uncovers potential issues. Adversarial samples, generated by introducing subtle perturbations to inputs, induce incorrect model predictions and are essential for assessing a model’s robustness against anomalous inputs. Enhancing neuron coverage activates more model pathways, thereby increasing the diversity of test samples. Utilizing coverage feedback to generate adversarial samples optimizes perturbation directions, enhances attack effectiveness, and improves the comprehensiveness and efficacy of testing by exploring diverse model pathways. Here, we present a diffusion-based neuron coverage feedback fuzz testing method, which aims to improve the sufficiency and robustness of DNN testing through a two-stage collaborative optimization framework combining gradient-guided initial perturbation generation and SDEdit-driven naturalness enhancement. This approach integrates gradient optimization with a diffusion generation process to maintain sample naturalness while strengthening adversarial capabilities against target classifiers. During generation, neuron coverage serves as a feedback mechanism guiding the creation and optimization of adversarial samples. Experimental results demonstrate that our method significantly increases both the misclassification rates and neuron coverage across multiple datasets, including MNIST, CIFAR-10, and ImageNet, while maintaining a favorable balance in sample naturalness. Ablation studies further confirm the pivotal roles of the neuron coverage feedback module and the diffusion process in enhancing adversarial sample effectiveness.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Diffusion-Based Neuron Coverage Feedback Fuzz Testing Method

  • Kexin Yang,
  • Junhua Wu,
  • Yue Cui,
  • Guangshun Li

摘要

Neuron coverage quantifies the number and distribution of activated neurons in Deep Neural Networks (DNNs) during testing, serving as a critical metric for evaluating DNN adequacy. It reveals the internal logic of models and uncovers potential issues. Adversarial samples, generated by introducing subtle perturbations to inputs, induce incorrect model predictions and are essential for assessing a model’s robustness against anomalous inputs. Enhancing neuron coverage activates more model pathways, thereby increasing the diversity of test samples. Utilizing coverage feedback to generate adversarial samples optimizes perturbation directions, enhances attack effectiveness, and improves the comprehensiveness and efficacy of testing by exploring diverse model pathways. Here, we present a diffusion-based neuron coverage feedback fuzz testing method, which aims to improve the sufficiency and robustness of DNN testing through a two-stage collaborative optimization framework combining gradient-guided initial perturbation generation and SDEdit-driven naturalness enhancement. This approach integrates gradient optimization with a diffusion generation process to maintain sample naturalness while strengthening adversarial capabilities against target classifiers. During generation, neuron coverage serves as a feedback mechanism guiding the creation and optimization of adversarial samples. Experimental results demonstrate that our method significantly increases both the misclassification rates and neuron coverage across multiple datasets, including MNIST, CIFAR-10, and ImageNet, while maintaining a favorable balance in sample naturalness. Ablation studies further confirm the pivotal roles of the neuron coverage feedback module and the diffusion process in enhancing adversarial sample effectiveness.