Directional fuzzy test method and system based on interpretable artificial intelligence association variation and exploration development double-queue circular scheduling
By introducing interpretable AI-generated sample masks and a dual-queue cyclic scheduling algorithm, the problems of insufficient sample correlation, unbalanced resource allocation, and lack of human-machine collaboration in targeted fuzz testing are solved, achieving efficient vulnerability detection and triggering.
Patent Information
- Application Number
- CN202511062948.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-31
- Publication Date
- 2025-11-21
AI Technical Summary
Existing targeted fuzz testing techniques suffer from problems such as a lack of correlation between samples and target code, an imbalance between exploration and development, insufficient model interpretability, and a lack of human-machine collaboration mechanisms, resulting in low testing efficiency and difficulty in triggering vulnerabilities.
Explainable artificial intelligence (XAI) technology is introduced to generate sample masks. Combined with a dual-queue cyclic scheduling algorithm and an adaptive learning mechanism, explicit associations are generated through a sample classification model, and sample mutations are dynamically scheduled to achieve human-machine collaborative testing.
It improves the accuracy and efficiency of fuzz testing, reduces the consumption of ineffective testing resources, and enables efficient detection and accurate triggering of deep vulnerabilities in complex software.
Smart Images

Figure CN120995460A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a directional fuzzy testing method and system based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling. Background Technology
[0002] Directed fuzz testing, as an automated security testing method, rapidly identifies potential vulnerabilities through randomized input mutations and has become a cornerstone of software security. Existing technologies mainly include three categories: path distance-based heuristic strategies (such as AFLGo), symbolic execution fusion methods (such as katch and QYSM), and machine learning-assisted methods (such as FuzzGuard and NEUZZ). Tools like AFLGo calculate the "path distance" between the input and the objective function through static analysis and dynamic instrumentation, dynamically adjusting sample priorities to guide the test path; symbolic execution methods perform deep path exploration by generating inputs that satisfy syntactic constraints; machine learning methods utilize deep learning models to learn input features, thereby meeting the sample format requirements during testing. However, these methods still have the following problems:
[0003] (1) Weak correlation between samples and target code: Existing tools do not establish an explicit correlation between input bytes and target code positions, and mutation strategies are blind;
[0004] (2) Rigid exploration and development balance mechanism: The rigid exploration and development balance mechanism in the existing targeted fuzz testing will lead to inefficient resource allocation and the inability to dynamically optimize the test direction, thus getting stuck in local optima, missing critical paths or target vulnerabilities.
[0005] (3) Insufficient interpretability of machine learning models: The "black box" nature of deep learning models leads to a lack of interpretability in path guidance strategies, making it difficult for users to understand the sample repair logic and increasing debugging difficulty;
[0006] (4) Lack of human-machine collaboration mechanism: Only shallow feedback such as coverage statistics is provided, and the model interpretation interface or sample mask adjustment function is not opened. Expert knowledge is difficult to intervene in the testing process, which limits the accuracy of targeted testing. Summary of the Invention
[0007] To address the problems of low testing efficiency and difficulty in triggering vulnerabilities in existing targeted fuzzing techniques, such as lack of correlation between samples and target code, imbalance between exploration and development, insufficient model interpretability, and lack of human-machine collaboration mechanisms, this invention provides a targeted fuzzing method and system based on interpretable artificial intelligence-based association mutation and exploration-development dual-queue cyclic scheduling. By introducing interpretable artificial intelligence (XAI) technology, an explicit association between input bytes and target code is established, generating a protected sample mask to guide precise mutation. A dual-queue dynamic scheduling algorithm is designed to adaptively balance the resource allocation between path exploration and target area testing. Combined with a real-time visualization interface, expert experience is integrated into the automated testing process, ultimately achieving efficient detection and precise triggering of deep vulnerabilities in complex software while reducing the resource consumption of ineffective testing.
[0008] In a first aspect, the present invention provides a directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling, comprising:
[0009] Obtain the initial sample set;
[0010] The trained sample classification model is used to divide all samples in the initial sample set into positive samples and negative samples, forming a positive sample set and a negative sample set. The positive sample refers to the sample whose execution flow contains the target basic block after the sample is input into the target program. The negative sample refers to the sample whose execution flow does not contain the target basic block after the sample is input into the target program.
[0011] The LIME framework is used to interpret the sample classification model and generate a sample mask set corresponding to the positive sample set. Each positive sample corresponds to a sample mask, which is used to indicate the allowed mutation information of each byte in the positive sample. Specifically, the key bytes in the positive sample that are related to reaching the target code region are set to not be mutated, and the remaining bytes are set to be mutated.
[0012] An exploration queue and a development queue are set up. The exploration queue is initialized using an initial sample set. The samples in the two queues are scheduled and mutated using a dual-queue cyclic simulated annealing algorithm to generate a new sample set. If the new sample is a positive sample, it is added to the development queue; otherwise, it is added to the exploration queue. When the scheduled sample is a positive sample, it is mutated based on the sample mask set.
[0013] Furthermore, the process of interpreting the sample classification model using the LIME framework and generating a sample mask set corresponding to the positive sample set specifically includes: for each positive sample, treating each byte in the positive sample as a feature, generating a feature importance map of the positive sample using the LIME framework; and generating a sample mask of the sample based on the feature importance map.
[0014] Furthermore, when the scheduled sample is a positive sample, the sample is mutated based on the sample mask set, specifically including:
[0015] For the positive sample s, obtain the index of its feature importance map and randomly select a mutation strategy;
[0016] If the training of the feature importance map has ended, then randomly select one byte from the positive sample s, and determine whether the selected byte is allowed to be mutated based on the sample mask of the positive sample s. If it is allowed, then apply the mutation strategy to the selected byte.
[0017] If the training of the feature importance map is not completed, a byte from the positive sample is randomly selected and a mutation strategy is applied to that byte.
[0018] Furthermore, the dual-queue cyclic simulated annealing algorithm specifically includes:
[0019] Initialize an exploration queue containing an initial sample set, and initialize an empty development queue;
[0020] If the stopping condition is not met, the following process is executed iteratively: A random number is generated; if the random number is less than the exploration probability, a sample is selected from the exploration queue; otherwise, a sample is selected from the development queue; after selecting a sample, a mutation operation is performed on the selected sample to generate a new sample; if the new sample is a positive sample or the new sample covers a new code region, it is added to the development queue; if it is a negative sample, it is added to the exploration queue; the annealing temperature is updated proportionally, and the test time is updated to the current runtime; if a new positive sample is detected to have been added to the development queue, the annealing temperature is reset to its initial value.
[0021] Furthermore, it also includes: incrementally training the sample classification model using a new sample set.
[0022] Furthermore, the incremental training of the sample classification model using a new sample set specifically includes:
[0023] Initialize a variable to record diversity changes, and initialize an empty set to store new samples;
[0024] For each sample in the original sample set, calculate its MinHash signature and calculate the maximum Jaccard similarity between the signature and the existing signature set; if the similarity is less than a preset similarity threshold, add the sample and its signature to the new sample set and the signature set respectively.
[0025] The proportion of newly added samples is calculated based on the size of the new sample set and used as the diversity change. If the diversity change exceeds the preset diversity threshold, the first k samples are selected from the new sample set to form a training batch. The training batch is used to incrementally train the sample classification model, and a sample mask is generated based on the incrementally trained sample classification model. Otherwise, the sample classification model remains unchanged.
[0026] Secondly, the present invention provides a directional fuzzy testing system based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling, comprising:
[0027] The sample acquisition module is used to acquire the initial sample set.
[0028] The sample learning module is used to classify all samples in the initial sample set into positive samples and negative samples using a trained sample classification model, forming a positive sample set and a negative sample set. The positive samples refer to those samples whose execution flow contains the target basic block after the sample is input into the target program; the negative samples refer to those samples whose execution flow does not contain the target basic block after the sample is input into the target program.
[0029] The interpretation module is used to interpret the sample classification model using the LIME framework and generate a sample mask set corresponding to the positive sample set. Each positive sample corresponds to a sample mask, which is used to indicate the allowed mutation information of each byte in the positive sample. Specifically, the key bytes in the positive sample that are related to reaching the target code region are set to not be mutated, while the remaining bytes are set to be mutated.
[0030] The fuzzing module is used to set up an exploration queue and a development queue. It initializes the exploration queue with an initial sample set, and uses a dual-queue cyclic simulated annealing algorithm to schedule and mutate samples in the two queues to generate a new sample set. If the new sample is a positive sample, it is added to the development queue; otherwise, it is added to the exploration queue. When the scheduled sample is a positive sample, it is mutated based on the sample mask set.
[0031] 8. The directed fuzzy testing system based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling according to claim 7 further includes:
[0032] The adaptive learning module is used to incrementally train the sample classification model using a new sample set.
[0033] Thirdly, the present invention provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the method as described in the first aspect.
[0034] Fourthly, the present invention provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method described in the first aspect.
[0035] The beneficial effects of this invention are as follows:
[0036] 1. This invention proposes a critical byte awareness method based on interpretable artificial intelligence. It generates sample masks through interpretable AI technology (LIME) to accurately protect critical input bytes associated with the target code and avoid invalid mutations.
[0037] 2. This invention proposes a dual-queue cyclic simulated annealing algorithm, which adaptively adjusts the simulated annealing parameters to balance resource allocation between the exploration and development phases, reduce redundant path testing, and prioritize the exploration of potentially high-risk paths.
[0038] 3. This invention proposes an adaptive incremental learning algorithm that combines efficient diversity analysis with adaptive model updates to ensure a balance between computational efficiency and continuous learning performance, enabling accurate and targeted fuzz testing even in rapidly changing testing environments.
[0039] 4. This invention proposes a method for improving testing accuracy through human-machine collaboration. The explanatory results (feature importance map) generated by LIME intuitively show the contribution of key bytes to vulnerability triggering. By adjusting the sample mask in real time to lock high-risk areas and combining expert experience, users can quickly locate testing bottlenecks. Attached Figure Description
[0040] Figure 1 A flowchart illustrating the directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling provided in an embodiment of the present invention;
[0041] Figure 2 A schematic diagram of a real-time visualization window provided in an embodiment of the present invention: (a) the original mask, (b) the improved mask;
[0042] Figure 3 A schematic diagram of the structure of a directional fuzzy testing system based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling provided in an embodiment of the present invention;
[0043] Figure 4 This is a structural block diagram of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0044] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of the embodiments of this invention will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0045] This invention aims to address the problems of low testing efficiency and difficulty in triggering vulnerabilities in existing targeted fuzzing techniques, caused by the lack of correlation between samples and target code, imbalance between exploration and development, insufficient model interpretability, and the absence of human-machine collaboration mechanisms. By introducing interpretable artificial intelligence (XAI) technology, an explicit correlation between input bytes and target code is established, generating a protected sample mask to guide precise mutation. A dual-queue dynamic scheduling algorithm is designed to adaptively balance resource allocation between path exploration and target region testing. Combined with a real-time visualization interface, expert experience is integrated into the automated testing process (i.e., enabling testers to adjust the sample mask in real time). Ultimately, this achieves efficient detection and precise triggering of deep vulnerabilities in complex software, while reducing the resource consumption of ineffective testing.
[0046] like Figure 1 As shown, this embodiment of the invention provides a directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling, including:
[0047] S101: Obtain the initial sample set;
[0048] S102: Use the trained sample classification model to divide all samples in the initial sample set into positive samples and negative samples, forming a positive sample set and a negative sample set; the positive sample refers to the sample whose execution flow contains the target basic block after the sample is input into the target program; the negative sample refers to the sample whose execution flow does not contain the target basic block after the sample is input into the target program.
[0049] S103: Use the LIME framework to interpret the sample classification model and generate a sample mask set corresponding to the positive sample set; wherein, one positive sample corresponds to one sample mask, and the sample mask is used to indicate the allowed mutation information of each byte in the positive sample, wherein the key bytes in the positive sample that reach the target code region are set to not be mutated, and the remaining bytes are set to be mutated.
[0050] S104: Set up an exploration queue and a development queue, and initialize the exploration queue using an initial sample set. Use a dual-queue cyclic simulated annealing algorithm to schedule and mutate samples in the two queues to generate a new sample set. If the new sample is a positive sample, it is added to the development queue; otherwise, it is added to the exploration queue. When the scheduled sample is a positive sample, the sample is mutated based on the sample mask set.
[0051] The targeted fuzz testing method provided in this invention utilizes LIME technology to analyze sample classification models and generate sample masks to protect byte positions highly related to the target code path, thus achieving interpretable AI-related mutation functionality. Furthermore, addressing the issue of missing data flow and control flow diversity caused by path constraints during targeted testing, this invention introduces a cyclic scheduling method with two exploratory queues for sample scheduling and mutation, increasing sample diversity within the queues.
[0052] In one embodiment, this invention provides a positive and negative sample classification algorithm. This algorithm aims to automatically classify sample e as E based on the distance between basic blocks S and T during dynamic execution. + and E - This allows for the collection of training data for the sample classification model. Based on the training data, a convolutional neural network is used to perform binary classification modeling on the samples, determining whether the input sample can reach the target code region. Ultimately, a sample classification model is obtained that can automatically divide the sample set into positive and negative sample sets. The definitions of positive and negative samples are as follows:
[0053] Let T be the target basic block, S be the initial program entry basic block, e be the sample, and E be the positive sample. + Negative samples are denoted as E. - For sample classification models, E + This refers to a sample e that, after being input into the target program, has its execution flow containing the target basic block T; while E - This refers to samples e that, after being input into the target program, do not have the target basic block T included in the execution flow during the execution of the target program. For detailed methods regarding the automatic classification of sample e, please refer to Algorithm 1.
[0054]
[0055] In one embodiment, the present invention provides a key byte awareness method based on interpretable artificial intelligence, using the LIME framework to interpret the trained sample classification model to understand the decision-making basis of the sample classification model and generate a feature importance map. Specifically, for each arriving sample E of length n... +Each byte in the dataset is randomly flipped (10% perturbation), generating 2000 perturbed samples. Simultaneously, a linear regression model is used to approximate the CNN's predictions on these perturbed samples. The coefficients of the fitted linear regression model are then used as the importance score for each byte. i Thus, for the sample E + Feature Importance Map (FIM) + Its formal representation is as follows:
[0056]
[0057] In FIM, bytes with high importance scores are considered crucial for reaching the target code region and are called key bytes, thus preventing mutations. Conversely, bytes with low importance scores are considered less important and are preferentially subject to mutation.
[0058] According to sample E + Feature Importance Map (FIM) + ), can be achieved through the transformation function f(s) i ) will FIM(E + ) converted to sample E + One-to-one corresponding sample mask M(E) + ), where M(E) + ) and f(s i Formalize as
[0059] M(E + )={m i |m i =f(s) i ),i∈1,2,3,…,n}
[0060]
[0061] Wherein, τ is a preset threshold. Correspondingly, this embodiment of the invention further proposes a mutation method for protecting key bytes, in conjunction with a sample mask set. This mutation method aims to utilize sample masks to ensure that key bytes considered important by the Feature Importance Map (FIM) are preserved during the mutation process, while other bytes are randomly modified to effectively explore new paths. By integrating sample masks, the mutation process balances the preservation of the basic byte sequence and the exploration of new inputs, significantly improving fuzziness effectiveness.
[0062] Specifically, the mutation method proceeds as follows: For each seed s, obtain the index of its feature importance map and randomly select a mutation strategy. If for the feature importance map FIM(E)... + If the training of ) has ended, then randomly select one byte from seed s and, based on its sample mask M(E) +The algorithm determines whether the selected byte is allowed to mutate. If so, it applies the mutation strategy to the selected byte. If training is not yet complete, it randomly selects a byte from the seed and applies the mutation strategy to that byte. Finally, the mutated seed is added to the mutation queue. The specific mutation algorithm combined with the sample mask is described in Algorithm 2.
[0063]
[0064] This invention utilizes interpretable artificial intelligence to generate feature importance maps, reducing the input sample exploration space and improving fuzz testing efficiency; it also protects sample format and improves the effective execution rate for target locations.
[0065] In one embodiment, the present invention also provides a dual-queue cyclic simulated annealing algorithm, which aims to divide the sample pool into two different queues: an exploration queue and a development queue; wherein the exploration queue is used to store negative samples; and the development queue is used to store positive samples, i.e., samples that have successfully reached the target code region. Dynamic balance between the two queues is achieved by utilizing a cyclic scheduling mechanism integrated with the simulated annealing principle.
[0066] The dual-queue cyclic simulated annealing algorithm in this embodiment incorporates an adaptive reset mechanism to ensure dynamic recalibration of the annealing process. Whenever a new arriving sample is identified in the exploration queue, it indicates the discovery of a new path to the target code region. To utilize this discovery, the algorithm resets the annealing temperature and refocuses its attention on exploration.
[0067] Specifically, the process of the dual-queue cyclic simulated annealing algorithm provided in this embodiment is as follows: First, an exploration queue containing an initial sample set is initialized, and an empty development queue is initialized. Then, without meeting the stopping condition, the following testing process is iteratively executed: A random number is generated; if the random number is less than the exploration probability, a sample is selected from the exploration queue; otherwise, a sample is selected from the development queue. After selecting a sample, a mutation operation is performed on the selected sample to generate a new sample. If the new sample is considered interesting (i.e., the new sample is a positive sample or the new sample covers a new code region), it is added to the development queue; if the new sample does not reach the target code region, it is added to the exploration queue; the annealing temperature is updated proportionally, and the test time is updated to the current runtime; if a new sample is detected reaching the target code region and added to the development queue, the annealing temperature is reset to its initial value. At the beginning of the test, samples are selected from the exploration queue with a high probability to discover new paths as much as possible. As time progresses and sample diversity increases, the probability of selecting samples from the development queue is gradually increased. However, when a new sample that "reaches the target" and covers a new code region is discovered, the temperature parameter is reset, and the exploration is restarted. This avoids getting stuck in local optima while allowing resources to be quickly concentrated on the critical path.
[0068] For detailed algorithm information, please refer to Algorithm 3.
[0069]
[0070]
[0071] This embodiment proposes a dual-queue cyclic simulated annealing algorithm with a dual-queue design and a dynamic scheduling mechanism based on the annealing principle. The annealing temperature is adaptively adjusted when new samples are discovered, enabling more effective exploration and utilization of the program state space and increasing the likelihood of discovering new and diverse samples containing newly discovered features. This mechanism facilitates a more thorough exploration of control flow and data flow characteristics related to vulnerability, enriching the diversity of target-related samples.
[0072] While exploring and developing a dual-queue cyclic scheduling method can increase the sample diversity in the queues, it may cause drift problems in the sample classification model. Therefore, based on the above embodiments, such as Figure 1 As shown, the directional fuzzy testing method provided in this embodiment of the invention further includes: S105: using an adaptive incremental learning algorithm to incrementally train the sample classification model based on a new sample set. Adaptive incremental learning achieves a balance between system overhead and model accuracy.
[0073] This invention aims to incrementally train a sample classification model using a newly generated sample set after mutation. The algorithm utilizes a combination of byte-level feature discrimination and Locality Sensitive Hash (LSH) to dynamically evaluate sample diversity and determine the necessity of incremental model updates. By mapping similar samples to the same hash bucket, LSH significantly reduces the computational cost associated with sample similarity evaluation, thereby effectively detecting substantial changes in diversity without requiring extensive pairwise similarity calculations. When a significant change in sample diversity is detected by LSH, an incremental training mechanism is triggered. This mechanism updates the model parameters based on the constantly changing sample distribution, ensuring its continuous adaptability to the current testing environment. During this update process, the model is fine-tuned based on the latest samples and regenerates corresponding sample masks. These updated masks ensure that the model maintains high prediction accuracy for new samples, effectively guiding the fuzzing process to reveal complex procedural behaviors.
[0074] The specific process is as follows: First, initialize a variable to record diversity changes and initialize an empty set to store new samples. For each sample, calculate its MinHash signature and calculate the maximum Jaccard similarity between this signature and the existing signature set. If the similarity is less than a preset similarity threshold, add the sample and its signature to the new sample set and signature set, respectively. Calculate the proportion of newly added samples as the diversity change. If the diversity change exceeds the preset diversity threshold, select the top k samples from the new sample set to form a training batch, use the training batch to incrementally train the sample classification model, and generate a sample mask. Otherwise, keep the sample classification model unchanged. Finally, return the updated sample classification model and sample mask. See Algorithm 4 for detailed algorithm information.
[0075]
[0076]
[0077] The adaptive incremental learning algorithm provided in this embodiment of the invention proposes to quickly identify the diversity distribution of samples in the current queue using the LSH method, thereby adaptively performing incremental learning, reducing blind resource consumption, and improving resource utilization.
[0078] In one embodiment, the present invention also provides a method for assisting directional fuzz testing using a real-time visualization window. Specifically, based on a key byte awareness method using interpretable artificial intelligence, all arriving samples E in the queue can be obtained. +The Feature Importance Map (FIM) identifies the importance of each byte in a sample in reaching the target code region. This coloring provides feedback to testers to explain the relationship between the code and the sample bytes. Testers can also adjust the sample mask in real time, allowing expert knowledge of the sample format to be integrated into the automated testing process, thus achieving a human-machine integrated vulnerability discovery method.
[0079] The sample mask visualization and real-time interactive method provided in this invention allows users to view and interactively adjust the range of protected bytes in real time, thereby guiding the mutation process of fuzz testing. This enables users to precisely control which bytes should not be mutated at different testing stages to achieve optimal testing results.
[0080] like Figure 3 As shown, this embodiment of the invention also provides a directional fuzzy testing system based on interpretable artificial intelligence and dual-queue dynamic scheduling, including: a sample acquisition module, a sample learning module, an interpretation module, a fuzzy testing module, and an adaptive learning module.
[0081] The sample acquisition module is used to acquire an initial sample set; the sample learning module is used to classify all samples in the initial sample set into positive and negative samples using a trained sample classification model, forming a positive sample set and a negative sample set; the positive sample refers to a sample whose execution flow contains the target basic block after the sample is input into the target program; the negative sample refers to a sample whose execution flow does not contain the target basic block after the sample is input into the target program; the interpretation module is used to interpret the sample classification model using the LIME framework and generate a sample mask set corresponding to the positive sample set; wherein, one positive sample corresponds to one sample mask, and the sample mask is used to indicate The permissible mutation information for each byte in the positive samples is defined, where key bytes leading to the target code region are set to not be mutated, while the remaining bytes are set to be mutated. The fuzzing module (mainly including a mutation module and an execution monitoring module) sets up an exploration queue and a development queue. It initializes the exploration queue using an initial sample set, and uses a dual-queue cyclic simulated annealing algorithm to schedule and mutate samples in both queues, generating a new sample set. If the new sample is positive, it is added to the development queue; otherwise, it is added to the exploration queue. When a scheduled sample is positive, it is mutated based on the sample mask set. An adaptive learning module is used to incrementally train the sample classification model using the new sample set.
[0082] The directional fuzzing system provided by this invention utilizes a key byte awareness method based on interpretable artificial intelligence to generate a feature importance map. A transformation function is then used to convert the feature importance map (FIM) into a sample mask, achieving a mutation method that protects key bytes while simultaneously integrating a real-time visual window, the testing process, and expert experience. It implements a dual-queue cyclic simulated annealing algorithm and an adaptive dynamic learning algorithm, combining both to enhance the diversity of target-related samples and correct model drift. Ultimately, this system addresses the problems of traditional fuzzing tools, such as the lack of correlation between mutations and target code, a rigid exploration-development balance mechanism, insufficient interpretability of machine learning models, and a lack of human-machine collaboration mechanisms.
[0083] It should be noted that the system provided in this embodiment of the invention is for implementing the above methods, and its specific functions can be referred to the above method embodiments, which will not be repeated here.
[0084] Figure 4 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 4 As shown, the electronic device may include a processor 401, a communications interface 402, a memory 403, and a communication bus 404. The processor 401, communications interface 402, and memory 403 communicate with each other via the communication bus 404. The processor 401 can call logical instructions from the memory 403 to execute a directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling.
[0085] Furthermore, when the logical instructions in the aforementioned memory 403 are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0086] This invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, and when the program instructions are executed by a computer, the computer can execute the directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling provided in the above-described method embodiments.
[0087] This invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When the computer program is executed by a processor, it implements the directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling provided in the above-described method embodiments.
[0088] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0089] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling, characterized in that, include: Obtain the initial sample set; The trained sample classification model is used to divide all samples in the initial sample set into positive samples and negative samples, forming a positive sample set and a negative sample set. The positive sample refers to the sample whose execution flow contains the target basic block after the sample is input into the target program. The negative sample refers to the sample whose execution flow does not contain the target basic block after the sample is input into the target program. The LIME framework is used to interpret the sample classification model and generate a sample mask set corresponding to the positive sample set. Each positive sample corresponds to a sample mask, which is used to indicate the allowed mutation information of each byte in the positive sample. Specifically, the key bytes in the positive sample that are related to reaching the target code region are set to not be mutated, and the remaining bytes are set to be mutated. An exploration queue and a development queue are set up. The exploration queue is initialized using an initial sample set. The samples in the two queues are scheduled and mutated using a dual-queue cyclic simulated annealing algorithm to generate a new sample set. If the new sample is a positive sample, it is added to the development queue; otherwise, it is added to the exploration queue. When the scheduled sample is a positive sample, it is mutated based on the sample mask set.
2. The directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling as described in claim 1, characterized in that, The method of using the LIME framework to interpret the sample classification model and generate a sample mask set corresponding to the positive sample set specifically includes: for each positive sample, treating each byte in the positive sample as a feature, generating a feature importance map of the positive sample using the LIME framework; and generating a sample mask of the sample based on the feature importance map.
3. The directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling as described in claim 1, characterized in that, When the scheduled sample is a positive sample, the sample is mutated based on the sample mask set, specifically including: For this positive sample s Obtain the index of its feature importance map and randomly select a mutation strategy; If training for the feature importance map has been completed, then the positive sample is randomly selected. s One byte in the positive sample s The sample mask is used to determine whether the selected byte is allowed to be mutated. If it is allowed, the mutation strategy is applied to the selected byte. If the training of the feature importance map is not completed, a byte from the positive sample is randomly selected and a mutation strategy is applied to that byte.
4. The directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling according to claim 1, characterized in that, The aforementioned dual-queue cyclic simulated annealing algorithm specifically includes: Initialize an exploration queue containing an initial sample set, and initialize an empty development queue; If the stopping condition is not met, the following process is executed iteratively: A random number is generated; if the random number is less than the exploration probability, a sample is selected from the exploration queue; otherwise, a sample is selected from the development queue; after selecting a sample, a mutation operation is performed on the selected sample to generate a new sample; if the new sample is a positive sample or the new sample covers a new code region, it is added to the development queue; if it is a negative sample, it is added to the exploration queue; the annealing temperature is updated proportionally, and the test time is updated to the current runtime; if a new positive sample is detected to have been added to the development queue, the annealing temperature is reset to its initial value.
5. The directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling according to any one of claims 2 to 4, characterized in that, Also includes: Incremental training of the sample classification model is performed using a new sample set.
6. The directional fuzzy testing method based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling according to claim 5, wherein the incremental training of the sample classification model using a new sample set specifically includes: Initialize a variable to record diversity changes, and initialize an empty set to store new samples; For each sample in the original sample set, calculate its MinHash signature and calculate the maximum Jaccard similarity between the signature and the existing signature set; if the similarity is less than a preset similarity threshold, add the sample and its signature to the new sample set and the signature set respectively. The proportion of newly added samples is calculated based on the size of the new sample set and used as the diversity change. If the diversity change exceeds the preset diversity threshold, the first k samples are selected from the new sample set to form a training batch. The training batch is used to incrementally train the sample classification model, and a sample mask is generated based on the incrementally trained sample classification model. Otherwise, the sample classification model remains unchanged.
7. A directional fuzzy testing system based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling, characterized in that, include: The sample acquisition module is used to acquire the initial sample set; The sample learning module is used to classify all samples in the initial sample set into positive samples and negative samples using a trained sample classification model, forming a positive sample set and a negative sample set. The positive samples refer to those samples whose execution flow contains the target basic block after the sample is input into the target program; the negative samples refer to those samples whose execution flow does not contain the target basic block after the sample is input into the target program. The interpretation module is used to interpret the sample classification model using the LIME framework and generate a sample mask set corresponding to the positive sample set. Each positive sample corresponds to a sample mask, which is used to indicate the allowed mutation information of each byte in the positive sample. Specifically, the key bytes in the positive sample that are related to reaching the target code region are set to not be mutated, while the remaining bytes are set to be mutated. The fuzzing module is used to set up an exploration queue and a development queue. It initializes the exploration queue with an initial sample set, and uses a dual-queue cyclic simulated annealing algorithm to schedule and mutate samples in the two queues to generate a new sample set. If the new sample is a positive sample, it is added to the development queue; otherwise, it is added to the exploration queue. When the scheduled sample is a positive sample, it is mutated based on the sample mask set.
8. The directed fuzzy testing system based on interpretable artificial intelligence-related mutation and exploratory development dual-queue cyclic scheduling according to claim 7 further includes: The adaptive learning module is used to incrementally train the sample classification model using a new sample set.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method as described in any one of claims 1 to 6.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 6.