Robot software specification violation vulnerability detection method and related device
By fine-tuning the big model, using the big model as a test oracle, it automatically detects whether the robot software violates specification documents, solves the high cost and inefficiency problems caused by manual reading and manual writing in the existing technology, and realizes automated vulnerability detection.
Patent Information
- Application Number
- CN202510243497.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art requires the robot's document specification requirements manually by experts with robotics background, to manually complete the writing of test predictions and identify feedback indicators, which requires a lot of manpower and time and is costly.
The big model is prompted and fine-tuned through the specification documents and software source code of the robot under test to obtain a test oracle, which is used to automatically determine whether the output of the robot under test software violates the specification documents, and automatically score the quality of the test cases.
An automated vulnerability detection process is realized without manual participation, avoiding a large amount of manpower consumption, and improving the efficiency of vulnerability detection.
Smart Images

Figure CN120012117A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of robot software testing, and in particular to a robot software specification violation vulnerability detection method and related devices. Background Art
[0002] Robot software is a program used to control and manage robot hardware. It is the core that gives robots intelligence and has a complex and large system. Due to the widespread phenomenon of open source software and code reuse in the robot software development community, the software running on a specific physical robot may not be sufficiently adapted to the hardware, resulting in specification violation vulnerabilities, causing the control output of the robot software to violate the physical assumptions of the robot in the robot's specification document. For example, requiring the robot's joint rotation angle to exceed the calibrated physical limit. This specification violation vulnerability will bring serious safety hazards, may cause physical damage to the robot hardware, and even lead to unsafe behavior for humans. For example, if the robot arm exceeds its physical rotation limit due to improper software control, it may cause the mechanical parts to break, thereby damaging the equipment and even endangering the safety of surrounding workers.
[0003] Currently, RoboFuzz uses fuzz testing methods to detect specification violation vulnerabilities in robot software. Unlike traditional fuzz testing frameworks, it runs the robot software on both a virtual simulator and a physical robot in the real world, collects the states of both virtual and real robots and inputs them into the test oracle, thereby achieving more comprehensive vulnerability detection. If a test does not trigger a vulnerability, the semantic feedback engine will use manually identified feedback indicators to evaluate the quality of the test case (that is, how far the current state of the robot is from triggering a specification violation vulnerability), thereby guiding the generation of the next round of test cases.
[0004] However, writing test oracles and identifying feedback indicators in RoboFuzz require a lot of manpower and time. Specifically, experts with a robotics background need to manually read the robot's specification documents and software source code, and then manually write test oracles in fuzz testing. Each robot system takes about two weeks to complete the writing of test oracles. In addition, the feedback indicators it uses to evaluate the quality of test cases also need to be manually identified by experts. This brings a lot of manpower and time costs and is inefficient. Summary of the invention
[0005] The present invention provides a robot software specification violation vulnerability detection method and related devices, which are used to solve the problem that the prior art requires experts with a robot technology background to manually read the robot's document specification requirements, manually complete the writing of test predictions and the identification of feedback indicators, which results in a large amount of manpower and time consumption and high cost.
[0006] In view of this, the first aspect of the present application provides a method, the method comprising:
[0007] The test oracle is obtained by fine-tuning the large model through the specification documents and software source code of the robot under test;
[0008] Perform structural detection on the robot software under test and generate test cases based on the structural detection results and the seeds specified by the user;
[0009] Input the test case into the software of the robot under test for testing, and output the status information of the robot under test;
[0010] The state information is input into the test oracle to obtain a result of whether the test case triggers a specification violation vulnerability.
[0011] Optionally, it also includes:
[0012] The quality of the test case is scored by the test oracle, and the score is used as a feedback indicator.
[0013] Optionally, the step of fine-tuning the large model using the specification document and software source code of the robot under test to obtain the test oracle includes:
[0014] Perform data augmentation on the specification document of the robot under test;
[0015] Masking the software source code and the enhanced specification document, prompting the construction of the software source code, inputting the masked and prompted specification document and the software source code into the big model for fine-tuning, and using the fine-tuned big model as a test oracle in the vulnerability detection process;
[0016] The fine-tuning process includes: updating all parameters of the large model so that the large model learns the semantics of variables in the specification document and software source code.
[0017] Optionally, the data enhancement of the specification document of the robot under test includes:
[0018] The specification document of the robot under test is enhanced by a data enhancement method, wherein the data enhancement method includes synonym replacement, back translation and antonym construction.
[0019] Optionally, masking the software source code and the enhanced specification document includes:
[0020] The specification parameters in the specification document are replaced by a fixed mask, and the words in the software source code are replaced by a random mask.
[0021] Optionally, performing structural detection on the robot software under test and generating test cases according to the structural detection result and a seed specified by the user include:
[0022] Get the node list and input variable information of the robot software under test;
[0023] A test case is generated according to the node list and the input variable information through a seed specified by a user.
[0024] Optionally, the state information includes: the location and posture of each piece of hardware of the robot under test, and the motion state of the robot under test.
[0025] A second aspect of the present application provides a robot software specification violation vulnerability detection system, the system comprising:
[0026] A fine-tuning unit, which is used to fine-tune the large model through the specification documents and software source code of the robot under test to obtain the test oracle;
[0027] A generation unit, used to perform structural detection on the robot software under test and generate test cases according to the structural detection results and a seed specified by the user;
[0028] A testing unit, used for inputting the test case into the software of the robot under test for testing, and outputting the status information of the robot under test;
[0029] The detection unit is used to input the state information into the test oracle to obtain the result of whether the test case triggers a specification violation vulnerability.
[0030] A third aspect of the present invention provides a robot software specification violation vulnerability detection device, the device comprising a processor and a memory:
[0031] The memory is used to store program code and transmit the program code to the processor;
[0032] The processor is used to execute the steps of the robot software specification violation vulnerability detection method as described in the first aspect according to the instructions in the program code.
[0033] A fourth aspect of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium is used to store program code, and the program code is used to execute the robot software specification violation vulnerability detection method described in the first aspect above.
[0034] It can be seen from the above technical solutions that the present invention has the following advantages:
[0035] The existing technology for detecting robot software specification violation vulnerabilities requires experts with a robotics background to manually read the robot's document specifications, manually write test predictions and identify feedback indicators. This process requires a lot of manpower and time, and is costly.
[0036] The present invention provides a robot software specification violation vulnerability detection method, which proposes to use the specification document and software source code of the robot under test to fine-tune the large model, so that the large model learns the constraints in the specification document and the variable semantics in the source code, and then directly uses the fine-tuned large model as a test oracle in the vulnerability detection process to determine whether the output of the robot software under test violates the specification document. In addition, the large model can also automatically score the quality of the test case and directly use the score as a feedback indicator, thereby avoiding manual identification. The whole process can be carried out automatically without manual participation, which can avoid a large amount of manpower consumption in the robot software specification document vulnerability detection technology and improve the efficiency of vulnerability detection. Thereby solving the problem that the prior art requires experts with a robot technology background to manually read the robot's document specification requirements, manually complete the writing of test predictions and the identification of feedback indicators, resulting in a large amount of manpower and time consumption and high cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0038] Figure 1 A schematic diagram of a flow chart of a robot software specification violation vulnerability detection method provided by an embodiment of the present invention;
[0039] Figure 2 A method framework for detecting a robot software specification violation vulnerability provided by an embodiment of the present invention;
[0040] Figure 3 A flowchart of a method for detecting a robot software specification violation vulnerability provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0041] In order to make the purpose, features and advantages of the present invention more obvious and easy to understand, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described below are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0042] Terminology explanation:
[0043] Robotic Software: A computer program specifically designed to control a robotic system. It contains a series of algorithms and instructions that interact with the robotic hardware to automate tasks and operations.
[0044] Robotic Specification: A technical document that details the design, functions, and performance requirements of a robot. It includes the robot’s functional description, technical parameters, and architectural design to ensure that all parties have a consistent understanding of the robot’s requirements.
[0045] Specification Violation Vulnerability: The software fails to strictly follow the definitions and requirements in the specification document during implementation, resulting in security risks or functional defects. This vulnerability usually stems from mistakes in the development or design phase, ignoring certain restrictions in certain specification documents.
[0046] Fuzz Testing: An automated software testing technique that discovers vulnerabilities or defects in a program by inputting a large number of random test cases into the program being tested.
[0047] Test Oracle: Test Oracle is a component used to determine the correctness of test case output during software testing. It is used to determine the expected output of the program under specific input to verify whether the actual output meets expectations.
[0048] Large Language Model: A large language model, also known as a large model, is an artificial intelligence model based on deep learning technology that is trained to understand and generate natural language text. It processes large amounts of text data to learn the grammar, structure, and contextual semantics of a language to generate coherent text output with a certain degree of semantic understanding. This model can be applied to a variety of tasks, such as text generation, translation, question-answering systems, and dialogue agents, demonstrating strong language understanding and generation capabilities.
[0049] Prompt Tuning: It is a method to optimize large language models by designing clever prompts to guide the model to generate the required output, and through a specific training process, the model can better understand and apply knowledge in a specific field. Prompt tuning can align the goals of downstream tasks to pre-trained tasks, thereby activating the model's inherent knowledge and capabilities to solve specific tasks.
[0050] See also Figure 1 , a robot software specification violation vulnerability detection method provided in an embodiment of the present invention includes:
[0051] Step 101, the test oracle is obtained by fine-tuning the large model through the specification documents and software source code of the robot under test.
[0052] It should be noted that if Figure 2 As shown, Figure 2 The steps in the dashed box are offline steps (step 101). Given a robot under test, the specification document and software source code of the robot under test are used to fine-tune the large model and obtain the test oracle. The offline steps need to be completed before the vulnerability detection is carried out. The details are as follows:
[0053] In one embodiment, step 101 includes:
[0054] Step 1011: perform data enhancement on the specification document of the robot under test by using a data enhancement method, wherein the data enhancement method includes: synonym replacement, back translation, and antonym construction.
[0055] It should be noted that data enhancement is performed on the specification documents of the tested robot to provide more training data for the next step. Specifically, three methods are used: synonym replacement, back translation, and antonym construction.
[0056] In synonym replacement, the original text is segmented and POS tagged using the existing open source vocabulary database NLTK. Then, the words in the original text are replaced using the synonym set in the open source vocabulary database (such as WordNet). At most 2 words in each sentence will be replaced with synonyms.
[0057] In back translation, an open source translation API (such as the Google Translate API) is used to translate a sentence into another language and then translated back to the original language. For example, if the original document is in English, the sentence is first translated into Chinese and then translated back into English.
[0058] In the antonym construction, the big model API (such as GPT-4o) is called to randomly select a paragraph of text in the specification document, and let the big model generate text that does not conform to the specification of the document as a negative sample.
[0059] Step 1012: replace the specification parameters in the specification document with a fixed mask, replace the words in the software source code with a random mask, construct a prompt for the software source code, input the specification document and software source code after the mask and prompt construction into the large model for fine-tuning, and use the fine-tuned large model as a test oracle in the vulnerability detection process.
[0060] Among them, the fine-tuning process includes: updating all parameters of the large model so that the large model can learn the semantics of variables in the specification documents and software source code.
[0061] It should be noted that this step uses the robot specification document and the source code of the robot software under test to prompt fine-tuning of the large model.
[0062] First, the training data is masked. The goal of model training is to make the prediction results of the masked words as close to the original text as possible. Specifically, a combination of random masking and fixed masking strategies is used. Random masking means randomly replacing 10% of the words (Tokens) in a sentence with “ <mask>". Fixed mask means using regular expressions to locate specification parameters such as numbers and angles in the specification document sentences and replacing these specification parameters with " <mask>". The source code of the tested software only uses random masks and no fixed masks.
[0063] Then, construct a prompt. This step is only performed for the robot specification document. The software source code does not need to construct a prompt. For each sentence in the robot specification document, add a sentence "Does this comply with the specification? <mask>. "For positive samples, that is, text data that describes documents that meet the specifications, the expected model is " <mask>The predicted value of "" is "Yes". For negative samples, that is, text data that does not conform to the specification document, it is expected that the model's predicted value for "<MAS knowledge>" is "No".
[0064] Finally, the training data after completing mask and prompt construction is input into the large model for fine-tuning, and all parameters of the large model are updated, enabling the large model to learn the variable semantics in the robot specification document and software source code.
[0065] Step 102: Perform structure detection on the robot software under test, and generate test cases based on the structure detection results and the seeds specified by the user.
[0066] In one embodiment, step 102 includes:
[0067] Obtain the node list and input variable information of the robot software under test; generate test cases based on the seeds specified by the user, the node list, and the input variable information.
[0068] It should be noted that Figure 2 The parts outside the dashed box are all online steps (steps 102 - 104). First, perform structure detection on the robot software under test. Use the command-line tool built into the robot operating system to obtain the node list of the robot software under test, the input variables, their corresponding types, and ranges. Then, generate test cases. Use the seeds specified by the user to randomly generate initial inputs based on the variable list obtained in the previous step. When the test has run for one round, perform the next mutation according to the feedback score of the test oracle for this set of test cases. Specifically, each set of test cases consists of several variables, and the feedback score score ranges from 1 to 100. When mutating, randomly select (100 - score)% of the variables for mutation. For example, if the current score is 90, then select 10% of the variables from the current set of test cases for mutation, and the remaining variables remain unchanged. For continuous numerical type variables, the mutation strategy uses Gaussian mutation, with the current value as the mean and the standard deviation preset by the user as a parameter to generate a new value. The mutation formula is as follows, where N(0,σ) is a normal distribution with a mean of 0 and a standard deviation of σ.
[0069] .
[0070] For discrete variable types, adopt a random selection mutation strategy, and randomly select a value from the range of its optional values.
[0071] Step 103: Input the test cases into the robot software under test for testing, and output the status information of the robot under test.
[0072] In one embodiment, the state information includes: the location and posture of each piece of hardware of the robot under test, and the motion state of the robot under test.
[0073] It should be noted that the test case is executed. The test case generated in step 102 is input into the software of the robot under test for testing. This step is performed on the virtual robot in the simulator. After the test case is executed, the state of the virtual robot is read, including the position and posture (posture information, position coordinates) of each hardware, the motion state of the robot (linear velocity, angular velocity, acceleration), etc. After the test case is executed, the final state of the robot is recorded.
[0074] Step 104: Input the status information into the test oracle to obtain the result of whether the test case triggers a specification violation vulnerability.
[0075] It should be noted that the status information recorded in step 103 is input into the test oracle. All the recorded statuses are spliced into a paragraph, and a sentence "Does this comply with the specification?" is added at the end. <mask>”, let the big model predict " <mask>If the prediction value is "Yes", it means that the current test case does not trigger the specification violation vulnerability. The design prompt template "Please assess how close the current state of the robot is to triggering the specification violation vulnerability and accordingly rate the current test case on a scale of 1 to 100. The score is <mask>.”.
[0076] Furthermore, in one embodiment, the robot software specification violation vulnerability detection method of the present invention also includes: scoring the quality of the test case through a test oracle and using the score as a feedback indicator.
[0077] It should be noted that the large model (test oracle) is used to determine how far the current state of the robot is from triggering the vulnerability, and the current test case is scored between 1-100 to guide the generation of the next round of test cases; if the predicted value is "No", it means that the specification violation vulnerability is triggered in this round of testing, and the current test case and the state of the virtual robot are recorded, and a report on the vulnerability is output. The vulnerability report needs to include the values of all variables in the test case and the current state of the virtual robot.
[0078] A robot software specification violation vulnerability detection method provided in an embodiment of the present invention proposes to use the specification document and software source code of the robot under test to fine-tune the large model, so that the large model learns the constraints in the specification document and the variable semantics in the source code, and then directly uses the fine-tuned large model as a test oracle in the vulnerability detection process to determine whether the output of the robot software under test violates the specification document. In addition, the large model can also automatically score the quality of the test case and directly use the score as a feedback indicator, thereby avoiding manual identification. The entire process can be carried out automatically without human participation, which can avoid a large amount of manpower consumption in the robot software specification document vulnerability detection technology and improve the efficiency of vulnerability detection. This solves the problem that the existing technology requires experts with a robot technology background to manually read the robot's document specification requirements, manually complete the writing of test predictions and the identification of feedback indicators, resulting in a large amount of manpower and time consumption and high cost.
[0079] The above is a robot software specification violation vulnerability detection method provided in an embodiment of the present invention, and the following is a robot software specification violation vulnerability detection system provided in an embodiment of the present invention.
[0080] See also Figure 3 , a robot software specification violation vulnerability detection system provided in an embodiment of the present invention includes:
[0081] The fine-tuning unit 201 is used to perform prompt fine-tuning on the large model through the specification documents and software source code of the robot under test to obtain a test oracle.
[0082] The generating unit 202 is used to perform structural detection on the robot software under test and generate test cases according to the structural detection results and a seed specified by the user.
[0083] The testing unit 203 is used to input the test case into the software of the robot under test for testing, and output the status information of the robot under test.
[0084] The detection unit 204 is used to input the status information into the test oracle to obtain the result of whether the test case triggers a specification violation vulnerability.
[0085] Furthermore, an embodiment of the present invention also provides a robot software specification violation vulnerability detection device, the device comprising a processor and a memory:
[0086] The memory is used to store program code and transmit the program code to the processor;
[0087] The processor is used to execute the steps of the robot software specification violation vulnerability detection method as described in the above method embodiment according to the instructions in the program code.
[0088] Furthermore, a computer-readable storage medium is provided in an embodiment of the present invention, and the computer-readable storage medium is used to store program code, and the program code is used to execute the robot software specification violation vulnerability detection method described in the above method embodiment.
[0089] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0090] In the several embodiments provided by the present invention, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0091] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0092] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0093] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.
[0094] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.< / mask> < / mask> < / mask> < / mask> < / mask> < / mask> < / mask>
Claims
1. A method for detecting a robot software specification violation vulnerability, characterized in that: include: The test oracle is obtained by fine-tuning the large model through the specification documents and software source code of the robot under test; Perform structural detection on the robot software under test and generate test cases based on the structural detection results and the seeds specified by the user; Input the test case into the software of the robot under test for testing, and output the status information of the robot under test; The state information is input into the test oracle to obtain a result of whether the test case triggers a specification violation vulnerability.
2. The robot software specification violation vulnerability detection method according to claim 1, characterized in that: Also includes: The quality of the test case is scored by the test oracle, and the score is used as a feedback indicator.
3. The robot software specification violation vulnerability detection method according to claim 1, characterized in that: The test oracle is obtained by fine-tuning the large model through the specification documents and software source code of the robot under test, including: Perform data augmentation on the specification document of the robot under test; Masking the software source code and the enhanced specification document, prompting the construction of the software source code, inputting the masked and prompted specification document and the software source code into the big model for fine-tuning, and using the fine-tuned big model as a test oracle in the vulnerability detection process; The fine-tuning process includes: updating all parameters of the large model so that the large model learns the semantics of variables in the specification document and software source code.
4. The robot software specification violation vulnerability detection method according to claim 3, characterized in that: The data enhancement of the specification document of the robot under test includes: The specification document of the robot under test is enhanced by a data enhancement method, wherein the data enhancement method includes synonym replacement, back translation and antonym construction.
5. The robot software specification violation vulnerability detection method according to claim 3, characterized in that: The masking of the software source code and the enhanced specification document includes: The specification parameters in the specification document are replaced by a fixed mask, and the words in the software source code are replaced by a random mask.
6. The robot software specification violation vulnerability detection method according to claim 1, characterized in that: The structure detection of the robot software under test and the generation of test cases according to the structure detection results and the seeds specified by the user include: Get the node list and input variable information of the robot software under test; A test case is generated according to the node list and the input variable information through a seed specified by a user.
7. The robot software specification violation vulnerability detection method according to claim 1, characterized in that: The state information includes: the position and posture of each piece of hardware of the robot under test, and the motion state of the robot under test.
8. A robot software specification violation vulnerability detection system, characterized in that: include: A fine-tuning unit, which is used to fine-tune the large model through the specification documents and software source code of the robot under test to obtain the test oracle; A generation unit, used to perform structural detection on the robot software under test and generate test cases according to the structural detection results and a seed specified by the user; A testing unit, used for inputting the test case into the software of the robot under test for testing, and outputting the status information of the robot under test; The detection unit is used to input the state information into the test oracle to obtain the result of whether the test case triggers a specification violation vulnerability.
9. A robot software specification violation vulnerability detection device, characterized in that: The device comprises a processor and a memory: The memory is used to store program code and transmit the program code to the processor; The processor is used to execute the robot software specification violation vulnerability detection method described in any one of claims 1-7 according to the instructions in the program code.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store program code, and the program code is used to execute the robot software specification violation vulnerability detection method according to any one of claims 1 to 7.