Confrontation sample generation method and device, electronic device and storage medium
By converting the binary code of the similarity detection model into intermediate representations and adding perturbation information, using the characteristics of graph neural network and abstract syntax tree model, an adversarial sample that can accurately attack the similarity detection model is generated, solving the problem of low accuracy in adversarial sample generation.
Patent Information
- Application Number
- CN202510209188.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-07-04
AI Technical Summary
In the prior art, the accuracy of adversarial sample generation is low and there is a lack of targeted attack strategies.
By obtaining the type of the similarity detection model, converting its binary code into an intermediate representation, analyzing the key code information, and adding preset perturbation information to generate target adversarial samples, and using the characteristics of graph neural network and abstract syntax tree model for comprehensive perturbation.
It improves the accuracy and efficiency of adversarial sample generation, increases the analytical burden of the model, realizes accurate attacks on the internal mechanism of the model, and improves the misjudgment rate.
Smart Images

Figure CN120258083A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computers, and particularly to a method, device, electronic device, and storage medium for generating adversarial samples. Background Art
[0002] Deep learning models have been widely used in many fields. Although the accuracy of the models is getting higher and higher, they are also vulnerable to attacks, such as adversarial attacks. Adversarial attack refers to the process of generating adversarial samples by applying slight perturbations to the original dataset and deceiving the target model through the adversarial samples. Studying adversarial attacks can better judge the vulnerable parts of machine learning models, thereby improving the robustness of the models. In the related art, in terms of adversarial attacks against similarity detection models, there is usually a lack of targeted attacks on the internal mechanisms of the models, resulting in low accuracy of generating adversarial samples.
[0003] Currently, no effective solution has been proposed for the problem of low accuracy of generating adversarial samples in the related art. Summary of the Invention
[0004] Embodiments of the present application provide a method, device, electronic device, and storage medium for generating adversarial samples to at least solve the problem of low accuracy of generating adversarial samples in the related art.
[0005] In a first aspect, an embodiment of the present application provides a method for generating an adversarial sample, the method including:
[0006] Obtain a similarity detection model to be trained;
[0007] Determine the model type of the similarity detection model; based on the model type, convert the binary code of the similarity detection model into analysis data in an intermediate representation form, and parse the analysis data to obtain key code information; the intermediate representation form corresponds to the model type;
[0008] Add preset perturbation information to the key code information to generate a target adversarial sample.
[0009] In some of the embodiments, the converting the binary code of the similarity detection model into analysis data in an intermediate representation form based on the model type includes:
[0010] In the case where the model type indicates that the similarity detection model is a graph neural network model, convert the binary code into an analysis graph in an intermediate representation form of a graph representation form; wherein, the analysis data includes the analysis graph; in the analysis graph, nodes represent basic components of the binary code, and edges represent structural association relationships.
[0011] In some of these embodiments, adding preset perturbation information to the key code information to generate a target adversarial sample includes:
[0012] Based on the key code information, determining the positions to be perturbed in the graph to be analyzed;
[0013] Introducing preset additional nodes for the positions to be perturbed and generating the target adversarial sample; wherein the perturbation information includes the additional nodes.
[0014] In some of these embodiments, converting the binary code of the similarity detection model into data to be analyzed in an intermediate representation based on the model type includes:
[0015] In the case where the model type indicates that the similarity detection model is an abstract syntax tree model, converting the binary code into a tree to be analyzed with an intermediate representation of a syntax analysis tree; wherein the data to be analyzed includes the tree to be analyzed; in the tree to be analyzed, each node represents an operation or expression of the binary code.
[0016] In some of these embodiments, parsing the data to be analyzed to obtain key code information includes:
[0017] Obtaining each instance in the data to be analyzed;
[0018] Performing local interpretation on each of the instances to obtain weight data of corresponding nodes in the syntax analysis tree;
[0019] Calculating the key code information based on the weight data.
[0020] In some of these embodiments, adding preset perturbation information to the key code information to generate a target adversarial sample includes:
[0021] Determining redundant branch code based on the key code information and inserting the redundant branch code into the tree to be analyzed to generate the target adversarial sample; the perturbation information includes the redundant branch code; and / or,
[0022] Determining equivalent semantic code based on the key code information and performing an equivalent replacement process on the code part in the tree to be analyzed with the equivalent semantic code to generate the target adversarial sample; the perturbation information includes the redundant branch code.
[0023] In some of these embodiments, the equivalent semantic code includes symbol code, control flow semantics, byte operations, and algorithm expressions.
[0024] In a second aspect, an embodiment of the present application provides an apparatus for generating an adversarial sample, including:
[0025] An acquisition module, configured to acquire a similarity detection model to be trained;
[0026] An analysis module, configured to determine the model type of the similarity detection model; based on the model type, convert the binary code of the similarity detection model into analysis data in an intermediate representation form, and analyze the analysis data to obtain key code information; the intermediate representation form corresponds to the model type;
[0027] A generation module, configured to add preset perturbation information to the key code information to generate a target adversarial sample.
[0028] In a third aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the method for generating an adversarial sample as described in the first aspect above is implemented.
[0029] In a fourth aspect, an embodiment of the present application provides a storage medium, on which a computer program is stored. When the program is executed by a processor, the method for generating an adversarial sample as described in the first aspect above is implemented.
[0030] Compared with the related art, the method, device, electronic device, and storage medium for generating an adversarial sample provided by the embodiment of the present application acquire a similarity detection model to be trained; determine the model type of the similarity detection model; based on the model type, convert the binary code of the similarity detection model into analysis data in an intermediate representation form, and analyze the analysis data to obtain key code information; the intermediate representation form corresponds to the model type; add preset perturbation information to the key code information to generate a target adversarial sample.
[0031] Based on this, not only the generation efficiency of the adversarial sample is improved, but also the functional equivalence of the perturbed code is ensured, providing a new research perspective and defense strategy for the field of binary code similarity detection. At the same time, by making full use of the graph structure characteristics and combining static and dynamic levels for comprehensive perturbation, a full-range attack on the model is realized. This comprehensive perturbation strategy not only increases the parsing burden of the model, but also further improves its misjudgment rate, realizing an accurate attack on the internal mechanism of the model and solving the problem of low accuracy in generating adversarial samples.
[0032] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more concise and understandable. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] The accompanying drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0034] Figure 1 is a hardware structural block diagram of a terminal for a method of generating adversarial samples according to an embodiment of the present application;
[0035] Figure 2 is a flowchart of a method of generating adversarial samples according to an embodiment of the present application;
[0036] Figure 3 is a flowchart of another method of generating adversarial samples according to an embodiment of the present application;
[0037] Figure 4 is a schematic diagram of a graph to be analyzed according to an embodiment of the present application;
[0038] Figure 5 is a structural block diagram of a device for generating adversarial samples according to an embodiment of the present application. Detailed implementation manners
[0039] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be described and explained below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments provided in the present application without making creative efforts fall within the scope of protection of the present application. In addition, it can also be understood that although the efforts made in this development process may be complex and time-consuming, for those of ordinary skill in the art related to the content disclosed in the present application, some design, manufacturing or production changes based on the technical content disclosed in the present application are only conventional technical means and should not be understood as insufficient disclosure of the content of the present application.
[0040] Referring to "embodiments" in the present application means that specific features, structures or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The phrase appears in various positions in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those of ordinary skill in the art explicitly and implicitly understand that the embodiments described in the present application can be combined with other embodiments without conflict.
[0041] Unless otherwise defined, the technical terms or scientific terms involved in this application shall have the ordinary meanings understood by those with ordinary skills in the technical field to which this application belongs. The words such as "a", "an", "one kind", "the" and the like involved in this application do not indicate a limitation in quantity and may represent a singular or plural number. The terms "include", "comprise", "have" and any variations thereof involved in this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or modules (units) is not limited to the listed steps or units, but may further include unlisted steps or units, or may further include other steps or units inherent to these processes, methods, products or devices. The words such as "connect", "be connected", "couple" and the like involved in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The "plurality" involved in this application means greater than or equal to two. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, "A and / or B" may represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. The terms "first", "second", "third" and the like involved in this application are only used to distinguish similar objects and do not represent a specific order of the objects.
[0042] The method embodiment provided in this embodiment can be executed on a terminal, a computer or a similar computing device. Taking running on a terminal as an example, Figure 1 is a hardware structure block diagram of a terminal for a method of generating adversarial samples according to an embodiment of the present application. As Figure 1 shown, the terminal may include one or more ( Figure 1 only one is shown in the figure) processors 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. Optionally, the above terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only schematic and does not limit the structure of the above terminal. For example, the terminal may further include more or fewer components than those shown in Figure 1 the figure, or have a different configuration from that shown in Figure 1 the figure.
[0043] The memory 104 can be used to store computer programs, such as software programs and modules of application software, such as the computer program corresponding to the method for generating adversarial samples in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implements the above method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories may be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.
[0044] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by a communication provider of the terminal. In one instance, the transmission device 106 includes a network adapter (abbreviated as NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0045] This embodiment provides a method for generating adversarial samples. Figure 2 is a flowchart of a method for generating adversarial samples according to an embodiment of the present application, as Figure 2 shown, the process includes the following steps:
[0046] Step S210, obtain a similarity detection model to be trained.
[0047] Among them, this step is the prerequisite for generating adversarial samples, and a trained or training similarity detection model is required as the target. Specifically, the model can be obtained from a model library or a training environment to ensure that it can run normally and output a similarity evaluation result.
[0048] Step S220, determine the model type of the similarity detection model; based on the model type, convert the binary code of the similarity detection model into data to be analyzed in an intermediate representation form, and parse the data to be analyzed to obtain key code information; the intermediate representation form corresponds to the model type.
[0049] Different types of similarity detection models may adopt different algorithms and input formats. Therefore, it is necessary to clarify the type of the target model first. The way to obtain this model type can be: checking the configuration file, document, or source code of the model to determine its type (such as feature-based, graph-based, deep learning-based, etc.).
[0050] Next, convert the binary code into an intermediate representation that the model can process for subsequent analysis. Specifically, according to the model type, select an appropriate conversion tool or method to convert the binary code into the corresponding intermediate representation (such as an abstract syntax tree, control flow graph, instruction sequence, etc.). Subsequently, extract the key code information crucial for similarity detection from the intermediate representation, and use a parser or analysis framework to deeply analyze the data to be analyzed, identifying key elements such as functions, variables, control structures, and their relationships.
[0051] Step S230, add preset perturbation information to the key code information to generate a target adversarial sample.
[0052] In this step, according to the preset perturbation strategy (such as modifying the instruction order, inserting irrelevant code, changing variable names, etc.), introduce perturbations into the key code information to ensure that the perturbed code is equivalent or approximately equivalent to the original code in function, so as not to affect the normal operation of the program. It should be understood that the perturbed code can also be reconverted into binary format (if necessary) to generate the final target adversarial sample. Through the above steps, by adding carefully designed perturbation information to the key code information, a target adversarial sample that can mislead the similarity detection model is generated.
[0053] In the above method for generating adversarial samples, by determining the type of the similarity detection model, converting the binary code into an intermediate representation, and parsing to obtain the key code information; then, by adding preset perturbation information to these key information, a target adversarial sample that can mislead the model's judgment is generated. This method not only improves the generation efficiency of adversarial samples but also ensures the functional equivalence of the perturbed code, providing a new research perspective and defense strategy for the field of binary code similarity detection. At the same time, by fully utilizing the graph structure characteristics and combining static and dynamic aspects for comprehensive perturbation, a comprehensive attack on the model is achieved. This comprehensive perturbation strategy not only increases the parsing burden of the model but also further improves its misjudgment rate, achieving an accurate attack on the internal mechanism of the model and solving the problem of low accuracy in the generation of adversarial samples.
[0054] In some of the embodiments, the above-mentioned data to be analyzed that converts the binary code of the similarity detection model into an intermediate representation based on the model type may further include the following steps:
[0055] When the similarity detection model is indicated as a graph neural network model, convert the binary code into a graph to be analyzed with an intermediate representation in the form of a graph representation; wherein, the data to be analyzed includes the graph to be analyzed; in the graph to be analyzed, nodes represent the basic components of the binary code, and edges represent structural association relationships.
[0056] In this step, confirm that the similarity detection model is a graph neural network model (GNN). Considering that graph neural network models are particularly suitable for processing graph-structured data, it is necessary to accurately convert the structural and semantic information of the binary code into a graph representation so that the graph neural network model can effectively process and analyze it.
[0057] Among them, take the basic components of the binary code (such as functions, variables, instructions, etc.) as nodes in the graph. Each node can contain feature information related to this component, such as name, type, value, etc. According to the structural association relationships in the binary code (such as function call relationships, data flow relationships, control flow relationships, etc.), add corresponding edges in the graph. The type of edge can represent different association relationships and can contain weights or other attribute information as needed. Construct the graph to be analyzed: Through the above definitions of nodes and edges, construct a complete graph to be analyzed. This graph represents the overall structure of the binary code and the relationships between key components. In other words, in this case, the data to be analyzed mainly includes the graph to be analyzed. This graph contains all the key information of the binary code and is presented in a form that can be processed by the graph neural network model.
[0058] After obtaining the graph to be analyzed, the graph neural network model can be used to process and analyze it. The model will learn the features of the nodes and edges in the graph and their relationships, thereby achieving an accurate assessment of the similarity of the binary code. Specifically, an interpreter can be used to analyze the decision-making basis of the model when judging code similarity, and focus on identifying the structural associations that have a significant impact on the model's prediction. More specifically, the interpreter can determine which statements in a specific function play a decisive role in the model's prediction result. Through this analysis, the sensitive points of the model can be identified, and the binary file can be precisely modified accordingly.
[0059] Through the above embodiments, when the similarity detection model is a graph neural network model, convert the binary code into a graph to be analyzed in the form of a graph representation. This graph accurately represents the structural and semantic information of the binary code and is presented in a form that can be processed by the graph neural network model. Through this method, the advantages of the graph neural network model in processing graph-structured data can be fully utilized to achieve an effective assessment of the similarity of the binary code. This step provides a solid foundation for subsequent similarity detection and adversarial sample generation.
[0060] In some of these embodiments, adding preset perturbation information to the above-mentioned critical code information to generate a target adversarial sample may further include the following steps:
[0061] Based on the critical code information, determine the positions to be perturbed in the graph to be analyzed; for the positions to be perturbed, introduce preset additional nodes and generate a target adversarial sample; wherein the perturbation information includes the additional nodes.
[0062] Specifically, based on the critical code information parsed previously, deeply analyze the structure and characteristics of the graph to be analyzed to identify those positions that have an important impact on the similarity detection result, which are usually the key nodes or edges in the graph. For example, an interpreter can be used to explain the decision-making process of the model to identify the key parts that have an important impact on the model's decision-making; the interpreter may evaluate the contribution of each part to the model output based on methods such as gradients, importance scores, SHAP values (SHapley Additive exPlanations), and LIME (Local Interpretable Model-agnostic Explanations), and based on the interpretation results, select those parts that are most critical to the model's decision-making as the positions to be perturbed. It should also be noted that these positions may vary depending on the model, so individual interpretation and selection need to be performed for each model.
[0063] After that, determine the positions to be perturbed according to the analysis results. These positions can be a single node, a group of nodes, or the edges between nodes. When selecting the positions to be perturbed, it is necessary to consider their impact on the similarity detection result and the concealment after introducing the perturbation. According to the established modification rules, manually set the newly added nodes (i.e., the above-mentioned additional nodes) and their corresponding program codes. These additional nodes can have characteristics similar to the key nodes, and these nodes will not change the actual execution logic or behavior of the program, but can disrupt the original structural relationship of the graph and increase the complexity and connectivity of the graph. It should be noted that in practical applications, it is also necessary to carefully weigh the impact of introducing the perturbation information on the functionality and concealment of the code to ensure that the generated adversarial sample can effectively interfere with the model's judgment without having an adverse impact on the normal operation of the program.
[0064] Finally, the designed additional nodes are introduced into the perturbation positions in the graph to be analyzed. This introduction step can be achieved by adding new edges to connect the additional nodes and the existing nodes, or by modifying the weights and attributes of the existing edges. After introducing the additional nodes, the graph to be analyzed is reconstructed and converted back to the binary code format (if necessary). In this way, the target adversarial sample containing the preset perturbation information (i.e., the additional nodes) is generated. Additionally, to further influence the model's judgment, the attributes of the newly added nodes can be moderately adjusted. For example, by adding some redundant statements to modify the constant and string attributes while maintaining the overall semantics unchanged.
[0065] Through the above embodiments, by determining the perturbation positions and introducing the preset additional nodes as perturbation information, we can generate target adversarial samples that can interfere with the judgment of the similarity detection model. This method not only increases the concealment and functionality of the adversarial samples but also improves their effectiveness against the similarity detection model.
[0066] In some of these embodiments, the above step of converting the binary code of the similarity detection model into the intermediate representation form of the data to be analyzed based on the model type may further include the following steps:
[0067] In the case where the model type indicates that the similarity detection model is an abstract syntax tree model, the binary code is converted to the tree to be analyzed with the intermediate representation form being the syntax analysis tree; wherein, the data to be analyzed includes the tree to be analyzed; in the tree to be analyzed, each node represents an operation or expression of the binary code.
[0068] In this step, it is confirmed that the similarity detection model is an abstract syntax tree model. The abstract syntax tree model is a commonly used source code analysis technique that can represent the source code as a tree structure, where each node represents an operation or expression in the source code. For this model, the binary code is converted into a syntax analysis tree so that the abstract syntax tree model can effectively process and analyze it.
[0069] The conversion process will be described below. First, the binary code needs to be decompiled or disassembled into assembly code or high-level language code (such as C, C++ etc.), because it is difficult to perform syntax analysis directly on the binary code. Then, syntax analyzers such as ANTLR (ANother Tool for Language Recognition), Yacc (Yet Another Compiler-Compiler) / Lex (LEXical compiler) etc. are used to perform syntax analysis on the decompiled or disassembled code to generate a syntax analysis tree. Through syntax analysis, a syntax analysis tree representing the source code structure is obtained. Each node in this tree corresponds to an operation or expression in the source code, and the edges represent the syntax relationships between these operations or expressions. In this case, the data to be analyzed mainly includes the tree to be analyzed (i.e., the syntax analysis tree). This tree contains all the syntax information of the binary code (or the decompiled / disassembled code) and is presented in a form that can be processed by the abstract syntax tree model.
[0070] After obtaining the tree to be analyzed, the abstract syntax tree model can be used to process and analyze it. The model will learn the features of the nodes and edges in the tree, as well as the relationships between them, so as to achieve an accurate evaluation of the similarity of binary codes.
[0071] Through the above embodiments, when the similarity detection model is the abstract syntax tree model, the binary code (or the decompiled / disassembled code) is converted into a syntax analysis tree as the data to be analyzed. This tree accurately represents the syntax structure of the source code and is presented in a form that can be processed by the abstract syntax tree model. By this method, the advantages of the abstract syntax tree model in processing the source code structure can be fully utilized to achieve an effective evaluation of the similarity of binary codes. Through the above strategy, for different types of binary code similarity detection models, their recognition results can be effectively disrupted, and their ability to accurately judge similar codes can be reduced.
[0072] In some of the embodiments, the above-mentioned parsing of the data to be analyzed to obtain key code information may further include the following steps:
[0073] Obtain each instance in the data to be analyzed; perform local interpretation on each instance to obtain the weight data of the corresponding nodes in the syntax analysis tree; calculate the key code information based on the weight data.
[0074] Among them, each instance is extracted from the data to be analyzed. In the context of a syntax analysis tree, an instance may correspond to a subtree, a node, or a group of nodes in the tree. Specifically, traverse the tree to be analyzed, and regard each node (or subtree) in the tree as an instance for subsequent processing. Subsequently, local interpretation is performed on each instance to obtain the weight data of the corresponding node in the syntax analysis tree. Local interpretation refers to analyzing a single instance (here, a node or subtree in the syntax analysis tree) to understand its contribution to the whole (i.e., the similarity detection result). The way to obtain this weight data can be: select a method suitable for local interpretation, such as importance scores based on features, SHAP values, LIME, etc. Apply the selected interpretation method to each instance to obtain the contribution degree or weight of this instance to the similarity detection result. Its core idea is to use a simple linear model to fit a complex model in the local area of model prediction. For example: y = ax, where x corresponds to the feature, and a is the weight of the feature x. According to this weight, the importance of each node can be obtained. It should also be supplemented that the importance of a node is measured by a score, and the positive or negative of the score can indicate the contribution direction of this node in similarity determination.
[0075] Next, use the weight data obtained from local interpretation to determine which code parts (i.e., nodes or subtrees in the syntax analysis tree) have an important impact on the similarity detection result. Sort the instances according to the weight data, and select the instances with higher weights as candidates for key code information. Extract the corresponding code parts (i.e., nodes or subtrees in the syntax analysis tree) from the sorted instances, and these parts are the key code information. Further, weight and integrate the scores of nodes belonging to the same statement to obtain the overall importance evaluation of the statement, so as to identify the code parts that play a key role in model judgment.
[0076] Through the above embodiments, by performing local interpretation on each instance in the data to be analyzed (here, the syntax analysis tree), the weight data of the corresponding nodes in the syntax analysis tree can be obtained. Based on these data, key code information can be calculated, which is of great significance for understanding the decision-making process of similarity detection results and improving the transparency of the model.
[0077] In some of these embodiments, adding preset perturbation information to the above key code information to generate target adversarial samples may further include the following steps:
[0078] Determine redundant branch code based on the key code information, and insert the redundant branch code into the tree to be analyzed to generate a target adversarial sample; the perturbation information includes the redundant branch code; and / or, determine equivalent semantic code based on the key code information, and perform equivalent replacement processing on the code part in the tree to be analyzed with the equivalent semantic code to generate a target adversarial sample; the perturbation information includes the redundant branch code.
[0079] The above redundant branch code refers to those code branches that have no substantial impact on the program execution result. By inserting these redundant branches, perturbations can be introduced without changing the main function of the program. For the replacement operation of introducing redundant branches that do not affect the actual execution logic of the program, first, determine the specific position in the tree to be analyzed according to the previously extracted key code information. Then, write or select appropriate redundant branch code according to the requirements of the target adversarial sample. These codes should be compatible with the key code in syntax and structure, but logically do not affect the program execution result. Finally, insert the generated redundant branch code near the key code position in the tree to be analyzed, ensuring that they can be recognized and processed by the model, thereby disturbing the model's judgment of the syntax structure.
[0080] The above equivalent semantic code refers to those codes that have the same or similar functions but different manifestations. By replacing the key code with equivalent semantic code, subtle perturbations can be introduced while keeping the program function unchanged. Similarly, determine the specific position in the tree to be analyzed according to the key code information. Write or select appropriate equivalent semantic code according to the requirements of the target adversarial sample and the specific content of the key code. These codes should be equivalent to the original code in function, but different in syntax, structure or implementation details. In the tree to be analyzed, replace the key code with the generated equivalent semantic code. Ensure that the replaced code still maintains the function of the original program logically. Through the above steps, the equivalent semantic code is replaced in the tree to be analyzed, thereby generating a target adversarial sample containing preset perturbation information.
[0081] Through the above embodiments, by inserting redundant branch code or performing equivalent replacement processing of equivalent semantic code based on key code information, a target adversarial sample containing preset perturbation information can be generated. These methods provide effective means for evaluating the robustness of the similarity detection model and defending against adversarial attacks.
[0082] In some of these embodiments, the above equivalent semantic code includes symbolic code, control flow semantics, byte operations, and algorithmic expressions. Among them, for semantic equivalent replacement, the statement can be replaced with an equivalent but different form through these four ways of symbolic code, control flow semantics, byte operations, and algorithmic expressions.
[0083] For the replacement method of symbolic code, specifically, a minus sign can be added before constants and variables. Among them, scan the code to identify all constants and variables; add a minus sign or double minus sign before these constants and variables; add a minus sign before the constants or variables in the code. From a mathematical perspective, a sign flip is done, but in fact, the semantics is not changed. For example: exprA = exprB => --exprA = --exprB.
[0084] For the control flow semantics, a replacement method for flattening the control flow can be implemented. Among them, scan the code to identify all control flow statements such as if, while, for, etc.; according to the conditional expression, convert the control flow structure into a switch statement. For the if-else structure, the judgment condition is converted into a case of switch; for for and while loops, the branch execution can be simulated through switch.
[0085] For byte operation transformation, specifically, it can be: scan the code to identify all bit operations and perform equivalent replacement on the bit operations, such as: a = a ^ b => a = (~a & b) | (a & ~b).
[0086] For arithmetic transformation, specifically, it can be: scan the code to identify all arithmetic operations and convert common arithmetic operations into equivalent expressions in different forms. For example, the conversion rules adopted can be: a = b + c => r = rand(); a = b + r; a = a + c; a = a - r.
[0087] The present application will be described and illustrated below with specific embodiments. For the similarity detection model based on the graph neural network structure, Figure 3 is a flowchart of another method for generating adversarial samples according to an embodiment of the present application. As Figure 3 shown, the generation process of its adversarial samples includes the following steps:
[0088] Step S301, convert the binary code of the similarity detection model into a graph to be analyzed. Specifically, please refer to Figure 4 , there are 19 nodes in the graph. The thickened edges are the "important edges" that have a positive impact on the similarity decision of the model when using the interpreter to analyze the similarity of the model for predicting binary code.
[0089] Step S302, perform structural intervention on the identified key edges, introduce intermediate nodes between certain marked edges, and convert the original path into a segmented connected form through specific jump instructions or other means. These newly added intermediate nodes will not modify the variable state or register value in the program, ensuring that the overall logic and semantics remain unchanged.
[0090] Step S303, among the introduced intermediate nodes, appropriately perturb their attributes. Among them, mainly by increasing the eigenvalue related to the program structure, such as the number of constants and the number of strings, and adding a fixed value to each node, so as to further enhance the interference effect and affect the judgment result of the model on the similarity structure.
[0091] Through the above embodiments, an accurate attack against the internal mechanism of the model is achieved. Meanwhile, by making full use of the characteristics of the graph structure and combining static and dynamic aspects for comprehensive perturbation, an all-round attack on the model is realized. This comprehensive perturbation strategy not only increases the parsing burden of the model but also further improves its misjudgment rate, thus providing a useful reference for adversarial attacks and defense strategies.
[0092] It should be noted that the steps shown in the above process or the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order from here.
[0093] This embodiment also provides a generating device for adversarial samples. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used hereinafter, terms such as "module", "unit", "sub-unit", etc. can be a combination of software and / or hardware that can achieve a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0094] Figure 5 is a structural block diagram of a generating device for adversarial samples according to an embodiment of the present application. As Figure 5 shown, the device includes: an acquisition module 51, an analysis module 52, and a generation module 53; where:
[0095] The acquisition module 51 is used to acquire a similarity detection model to be trained; the analysis module 52 is used to determine the model type of the similarity detection model; based on the model type, convert the binary code of the similarity detection model into analysis data in an intermediate representation form, and analyze the analysis data to obtain key code information; the intermediate representation form corresponds to the model type; the generation module 53 is used to add preset perturbation information to the key code information to generate a target adversarial sample.
[0096] In some of these embodiments, the above analysis module 52 is further used, when the model type indicates that the similarity detection model is a graph neural network model, to convert the binary code into analysis graph in an intermediate representation form as a graph representation form; where the analysis data includes the analysis graph; in the analysis graph, nodes represent the basic components of the binary code, and edges represent structural association relationships.
[0097] In some of these embodiments, the above generation module 53 is further used to determine the position to be perturbed in the analysis graph based on the key code information; the generation module 53 is further used to introduce preset additional nodes for the position to be perturbed and generate a target adversarial sample; where the perturbation information includes additional nodes.
[0098] In some of these embodiments, the above-mentioned parsing module 52 is further configured to, when the model type indicates that the similarity detection model is an abstract syntax tree model, convert the binary code into an analysis tree whose intermediate representation is a syntax analysis tree; wherein, the data to be analyzed includes the analysis tree; in the analysis tree, each node represents an operation or expression of the binary code.
[0099] In some of these embodiments, the above-mentioned parsing module 52 is further configured to obtain each instance in the data to be analyzed; the parsing module 52 is further configured to perform local interpretation on each instance to obtain the weight data of the corresponding node in the syntax analysis tree; the parsing module 52 is further configured to calculate the key code information based on the weight data.
[0100] In some of these embodiments, the above-mentioned generation module 53 is further configured to determine redundant branch codes based on the key code information, and insert the redundant branch codes into the analysis tree to generate a target adversarial sample; the perturbation information includes the redundant branch codes; and / or, the above-mentioned generation module 53 is further configured to determine equivalent semantic codes based on the key code information, and perform an equivalent replacement process on the code part in the analysis tree with the equivalent semantic codes to generate a target adversarial sample; the perturbation information includes the redundant branch codes.
[0101] In some of these embodiments, the above-mentioned equivalent semantic codes include symbol codes, control flow semantics, byte operations, and algorithm expressions.
[0102] It should be noted that the above-mentioned various modules can be functional modules or program modules, and can be implemented either by software or by hardware. For the modules implemented by hardware, the above-mentioned various modules can be located in the same processor; or the above-mentioned various modules can also be located in different processors in any combined form. Specific examples in this embodiment can refer to the examples described in the above-mentioned embodiment and optional implementation manners, and will not be elaborated in this embodiment.
[0103] This embodiment also provides an electronic device, including a memory and a processor, where a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above-mentioned method embodiments.
[0104] Optionally, the above-mentioned electronic device may further include a transmission device and an input / output device, wherein, the transmission device is connected to the above-mentioned processor, and the input / output device is connected to the above-mentioned processor.
[0105] Optionally, in this embodiment, the above-mentioned processor may be configured to execute the following steps through a computer program:
[0106] S1, obtain a similarity detection model to be trained.
[0107] S2. Determine the model type of the similarity detection model; based on the model type, convert the binary code of the similarity detection model into the data to be analyzed in an intermediate representation form, and parse the data to be analyzed to obtain key code information; the intermediate representation form corresponds to the model type.
[0108] S3. Add preset perturbation information to the key code information to generate a target adversarial sample.
[0109] It should be noted that the specific examples in this embodiment can refer to the examples described in the above embodiments and optional implementation manners, and will not be repeated here.
[0110] In addition, in combination with the method for generating an adversarial sample in the above embodiment, an embodiment of the present application can be implemented by providing a storage medium. A computer program is stored on the storage medium; when the computer program is executed by a processor, the method for generating any one of the adversarial samples in the above embodiment is implemented.
[0111] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties.
[0112] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0113] Those skilled in the art should understand that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0114] The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A method for generating adversarial examples, characterized in that, The method includes: Obtaining a similarity detection model to be trained; Determining the model type of the similarity detection model; based on the model type, converting the binary code of the similarity detection model into analysis data in an intermediate representation form, and parsing the analysis data to obtain key code information; the intermediate representation form corresponds to the model type; Adding preset perturbation information to the key code information to generate a target adversarial sample.
2. The generation method according to claim 1, characterized in that, The converting the binary code of the similarity detection model into analysis data in an intermediate representation form based on the model type includes: When the model type indicates that the similarity detection model is a graph neural network model, converting the binary code into an analysis graph in an intermediate representation form of a graph representation; wherein, the analysis data includes the analysis graph; in the analysis graph, nodes represent basic components of the binary code, and edges represent structural association relationships.
3. The generation method according to claim 2, characterized in that The adding preset perturbation information to the key code information to generate a target adversarial sample includes: Based on the key code information, determining the positions to be perturbed in the analysis graph; Introducing preset additional nodes for the positions to be perturbed and generating the target adversarial sample; wherein, the perturbation information includes the additional nodes.
4. The generation method according to claim 1, wherein The converting the binary code of the similarity detection model into analysis data in an intermediate representation form based on the model type includes: When the model type indicates that the similarity detection model is an abstract syntax tree model, converting the binary code into an analysis tree in an intermediate representation form of a syntax analysis tree; wherein, the analysis data includes the analysis tree; in the analysis tree, each node represents an operation or expression of the binary code.
5. The generation method according to claim 4, wherein The parsing the analysis data to obtain key code information includes: Obtaining each instance in the analysis data; Performing local interpretation on each instance to obtain weight data of corresponding nodes in the syntax analysis tree; Calculating to obtain the key code information based on the weight data.
6. The generation method according to claim 4, characterized in that, The adding preset perturbation information to the key code information to generate a target adversarial sample includes: Determining redundant branch codes based on the key code information and inserting the redundant branch codes into the analysis tree to generate the target adversarial sample; the perturbation information includes the redundant branch codes; and / or, Determining equivalent semantic codes based on the key code information and performing equivalent replacement processing on the code part in the analysis tree with the equivalent semantic codes to generate the target adversarial sample; the perturbation information includes the redundant branch codes.
7. The generation method according to claim 6, wherein The equivalent semantic codes include symbol codes, control flow semantics, byte operations, and algorithm expressions.
8. An adversarial sample generation device, characterized in that, Includes: An acquisition module, configured to obtain a similarity detection model to be trained; An analysis module, configured to determine the model type of the similarity detection model; Based on the model type, converting the binary code of the similarity detection model into analysis data in an intermediate representation form, and parsing the analysis data to obtain key code information; The intermediate representation form corresponds to the model type; A generation module, configured to add preset perturbation information to the key code information to generate a target adversarial sample.
9. An electronic device, comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to run the computer program to execute the adversarial sample generation method according to any one of claims 1 to 7.
10. A storage medium, characterized in that, The storage medium stores a computer program, wherein the computer program is configured to execute the adversarial sample generation method according to any one of claims 1 to 7 when running.