Fuzzing Deep Learning Models against Natural Robustness with Filter Coverage
Zhengyuan Wei, W. K. Chan · 2021 IEEE 21st International Conference on Software Quality, Reliability and Security (QRS) · 2021
Coverage-guided fuzzing on deep learning (DL) models can generate natural adversarial variants. However, no existing fuzzing work can show that covering or uncovering a coverage element of a test adequacy criterion can significantly change the accuracy of the DL model under test. This paper proposes a novel testing criterion, Filter Coverage, and a novel fuzzing technique FilterFuzz guided by this criterion. To the best of our knowledge, Filter Coverage is the first test adequacy criterion able to identify such a coverage element-blamed filter-in a DL model using convolutional filters by demonstrating a cause-and-effect chain. Both Filter Coverage and Neuron Coverage measure whether individual neurons are activated, but Filter Coverage is more selective and collective and higher in the abstraction level. FilterFuzz, guided by Filter Coverage, tackles the challenge of achieving a higher rate of generating natural adversarial variants against natural robustness. Our case study shows that FilterFuzz is significantly more effective than fuzzing guided by Neuron Coverage by 33% and produces more diverse kinds of such variants. Moreover, when applying to the problem of labeling cost reduction on generated natural variants, Filter Coverage identifies 4.3x to 4.7x of natural adversarial variants than random reordering. Our work also calls for a re-examination of the previous ineffective conclusions of Neuron Coverage.