An automated fuzz testing method for AI mobile applications

By using automated fuzz testing methods, potential AI entry points in AI mobile applications are identified and attack questions are generated. Large language models are used to detect security vulnerabilities in jailbreak scenarios, solving the problem of difficulty in detecting security vulnerabilities in AI mobile applications in existing technologies, and achieving efficient security vulnerability detection and application stability improvement.

CN119885205BActive Publication Date: 2025-10-28UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510041633.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-10-28
Estimated Expiration
2045-01-10

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively detect and address security vulnerabilities in AI mobile applications, especially those caused by jailbreak vulnerabilities, which can lead to user privacy breaches and abnormal system functions.

Method used

An automated fuzz testing method for AI mobile applications is adopted. By identifying text input boxes as potential AI entry points, attack questions are generated and a large language model is used to determine whether security vulnerabilities exist. This includes classifying applications, identifying send buttons, generating jailbreak scenario templates, and attack question sets.

Benefits of technology

Effectively detect security vulnerabilities in AI mobile applications during use, improve testing efficiency and application robustness, and ensure the security and stability of applications in complex scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119885205B_ABST
    Figure CN119885205B_ABST
Patent Text Reader

Abstract

This invention discloses an automated fuzz testing method for AI mobile applications, belonging to the field of smart device security technology. The method includes classifying AI mobile applications, generating a set of dangerous or prohibited questions for each type, and creating a universal jailbreak scenario template applicable to all sets of dangerous or prohibited questions; acquiring an AI mobile application and identifying potential AI entry points; confirming whether a potential AI entry point is indeed an AI entry point; obtaining the type of AI mobile application corresponding to the AI ​​entry point; combining the set of dangerous or prohibited questions corresponding to the type and the universal jailbreak scenario template to generate attack questions; attacking the AI ​​mobile application to obtain generated information; and using a large language model to determine whether a security vulnerability exists. This invention provides, for the first time, a fully automated method to detect security vulnerabilities in AI mobile applications, which not only improves testing efficiency and sufficiency but also enhances the robustness and reliability of mobile applications. It can be widely applied in the field of automated security testing of AI mobile applications.
Need to check novelty before this filing date? Find Prior Art