Unmanned aerial vehicle flight control system vulnerability detection method based on data flow analysis and LLM
Through the combination of data flow analysis and large language models, structured natural language descriptions are generated and reverse semantic mapping is reversed into executable code, which solves the problems of low use case generation efficiency, insufficient logical vulnerability detection depth and difficulty in multimodal interactive scenario coverage in drone software testing, and realizes efficient vulnerability detection and automated verification.
Patent Information
- Application Number
- CN202510378133.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-07-11
AI Technical Summary
Traditional drone software testing methods have insufficient efficiency in generating test cases, insufficient depth of logical vulnerability detection, difficulty in covering multimodal interactive scenarios, and a semantic gap between natural language and code, resulting in low vulnerability detection efficiency.
Using a method of combining data flow analysis with large language model (LLM), we use the method of establishing an operation-code mapping relationship library, generating structured natural language descriptions, building a combined test scenario and inversely mapping it into executable test code, forming a multi-stage LLM processing framework to realize intelligent generation, code-based verification and vulnerability positioning of test cases.
It significantly improves the testing automation level and vulnerability detection accuracy of drone flight control software, can identify logical vulnerabilities that are difficult to detect by traditional tools, realizes full process automation and has cross-platform adaptability.
Smart Images

Figure CN120296746A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the cross - field of intelligent software testing and drone safety technology, and particularly relates to a method for detecting vulnerabilities in a drone flight control system based on data flow analysis and LLM. It is especially applicable to the intelligent generation of test cases, code - based verification, and potential logic vulnerability location in the multi - module interaction scenario of drone control software, covering code semantic parsing, natural - language test scenario construction, automated script conversion, and vulnerability diagnosis technology. Background Art
[0002] With the wide application of drones in fields such as industrial inspection and logistics transportation, the software reliability of its flight control system has become a key safety indicator. Traditional drone software testing methods mainly face the following technical bottlenecks:
[0003] 1. Insufficient efficiency in test case generation: Existing test methods based on rule engines or symbolic execution (such as tools like KLEE, S2E, etc.) rely on manually defining test scenarios and are difficult to cover the complex state machine transitions of drones (such as the concurrent execution of emergency braking and waypoint tasks) and the multi - modal combinations of sensor inputs.
[0004] 2. Limited depth in logical vulnerability detection: Although static analysis techniques (such as data flow analysis and control flow analysis) can detect code syntax errors, they lack semantic - level verification of the rationality of business logic. For example, traditional tools cannot identify logical defects such as "landing instruction does not verify the current altitude" or "modifying the return point to a no - fly zone and then returning".
[0005] 3. Weak dynamic test coverage ability: Existing dynamic test frameworks (such as the PX4 SITL simulation environment) require manual writing of test scripts and are difficult to automatically generate test cases involving multi - operation timing interference (such as modifying the starting point of the drone during the execution of a task), resulting in a high rate of missed detection of logical vulnerabilities.
[0006] 4. Semantic gap between natural language and code: Although large language models (such as Deepseek, GPT series) have been applied to code generation, existing methods do not establish domain - specific knowledge constraints for drones (such as flight mode state machines, interface parameter ranges), resulting in adaptability problems such as illegal interface call parameters and missing state dependencies in the generated test scripts.
[0007] Therefore, there is an urgent need for a test framework that integrates code static analysis and large language model reasoning to achieve semantic expression and automated verification of test logic through a natural - language intermediate layer, thereby systematically improving the vulnerability detection efficiency and scenario coverage rate of drone flight control software. Summary of the Invention
[0008] The objective of the present invention is to provide a method for detecting vulnerabilities in an unmanned aerial vehicle (UAV) flight control system based on data flow analysis and large language models (LLMs). By deeply integrating static code parsing and dynamic generative reasoning, it solves problems such as low test case generation efficiency, insufficient depth of logical vulnerability detection, difficulty in covering multi-modal interaction scenarios, and the semantic gap between natural language and code in traditional testing methods. At the same time, a multi-stage LLM processing framework and natural language intermediate representation technology are proposed to achieve a closed-loop process of intelligent test case generation, code-based verification, and vulnerability location, significantly improving the test automation level and vulnerability detection accuracy of UAV flight control software.
[0009] To achieve the above objective, the present invention adopts the following technical solutions:
[0010] A method for detecting vulnerabilities in an unmanned aerial vehicle (UAV) flight control system based on data flow analysis and large language models (LLMs) includes the following steps:
[0011] S1. Extract code function modules related to user operations in the UAV flight control system through data flow analysis methods, and establish an operation-code mapping relationship library;
[0012] Including:
[0013] S1.1. Establish a user operation type library covering user standard operations such as takeoff instructions, landing instructions, waypoint upload, emergency braking, and mode switching;
[0014] S1.2. Based on control flow graph analysis, locate the entry functions corresponding to each operation, and use backward slicing technology to extract code segments related to operation execution;
[0015] S1.3. Construct a data dependency graph to identify three types of key data nodes involved in the code segments: state variables, sensor inputs, and user instruction inputs;
[0016] S1.4. Cluster and fuse code segments with data intersections to generate operation function modules containing complete control chains;
[0017] S1.5. Add metadata tags to each module, including operation type, code line range, input and output parameter sets, and associated hardware device lists.
[0018] S2. Use a large language model to generate a structured natural language semantic description for each function module code to form a multi-dimensional semantic feature vector;
[0019] The following steps are used to generate the semantic description:
[0020] S2.1. Design a structured description template containing five fields: function intention, input parameter constraints, output behavior expectations, exception handling mechanisms, and hardware interaction interfaces;
[0021] S2.2. Input the code snippet and the context annotation into the large language model, and use the chain of thought prompting engineering to generate the initial description;
[0022] S2.3. Design a reflection mechanism under the large language model framework to verify the description integrity, and trigger an iterative correction instruction for the description missing required fields;
[0023] S3. Based on the relevance analysis of the semantic features of multiple modules, construct a combined test scenario and generate natural language test cases;
[0024] It includes the following test case generation mechanisms:
[0025] S3.1. Use the large language model to construct a cross-module association graph, and analyze the timing dependency relationship and the possibility of state conflicts between operations;
[0026] S3.2. Generate a combined test strategy to cover three types of scenarios: single-operation boundary value test, double-operation timing interference test, and multi-operation concurrent pressure test;
[0027] S3.3. Construct a test step chain including precondition trigger, execution process interruption, and post-state verification;
[0028] S3.4. Attach the expected state result of the drone to each test case to facilitate subsequent nodes to understand the task objective and further generate test script code and verify whether a vulnerability is triggered.
[0029] S4. Convert the natural language test cases into executable test code through reverse semantic mapping to complete the code-based reconstruction of the test logic;
[0030] The test code conversion based on the large language model is achieved through the following methods:
[0031] S4.1. Construct a JSON interface knowledge base for the specific function call functions of the drone, and provide a standardized interface description including function name, parameter type and semantic constraints, return value structure, and exception handling strategy to the large language model. The parameter semantic constraints include explicit annotations of value range definition (such as height threshold 0 - 500 meters), data type (such as three-dimensional coordinate system floating-point number array), and state dependency relationship (such as the landing instruction needs to be executed in the hovering state);
[0032] S4.2. Map the natural language to an executable Python script, and automatically complete the standardized code templates for test framework initialization, assertion verification, and exception capture;
[0033] S4.3. Implement dynamic semantic verification during code generation: Based on the JSON interface description, perform static checks on the generated function call parameters, including parameter type matching (such as whether the waypoint coordinates are List[float]), enumeration value legality (such as flight modes limited to ["GPS", "ATTI", "Manual"]), and state machine consistency (such as sensor calibration needs to be completed before takeoff). Trigger the iterative correction process of the large language model for the generated results with verification failures.
[0034] S4.4. Generate a test scaffold with adaptive expansion capabilities: Automatically construct the initialization and cleanup code for the test environment (such as arming the drone, resetting flight parameters) based on the JSON interface description, and generate transactional test sequences according to the timing dependencies of test cases (such as the atomic operation chain of "upload waypoints → start mission → emergency braking").
[0035] S5. Execute the test code in the drone simulation environment and capture the runtime logs, and use the large language model to extract vulnerability features and locate the root cause.
[0036] Specifically include:
[0037] S5.1. Build a drone simulation sandbox, integrating a physics engine, a sensor noise model, and a communication delay simulation module.
[0038] S5.2. Synchronously record the system logs, perform root cause analysis based on the logs and the test case goals by the large language model, and generate a diagnostic report.
[0039] Furthermore, the method achieves innovative breakthroughs through the following technologies:
[0040] 1. Multimodal test framework design: Integrate static data flow analysis (accurately extract code modules) and LLM dynamic reasoning (semantic understanding and scenario generation), build a three-layer data pipeline of "code - natural language - executable script", and break through the limitations of traditional single analysis methods.
[0041] 2. Natural language intermediate representation technology: Use the LLM to uniformly transform code semantics and test logic into natural language descriptions, solve the semantic gap between domain knowledge (such as flight state machines, interface constraints) and test requirements, and achieve accurate expression and automated verification of test intentions.
[0042] 3. Closed-loop verification mechanism: Through the reverse semantic mapping and dynamic verification of the code conversion module, form a closed-loop process of "test case generation → script execution → vulnerability diagnosis → test case optimization", and support iterative enhancement of test coverage capabilities.
[0043] Furthermore, the core architecture of the system includes:
[0044] Operation Code Slicing Extraction Module: Generate an operation-code mapping relationship library based on data flow analysis;
[0045] Multi-stage LLM Processing Framework: Complete semantic parsing, test scenario generation, and log analysis tasks in sequence;
[0046] Code Transformer: Integrate the JSON interface knowledge base and semantic verification rules to ensure the domain adaptability of test scripts;
[0047] Simulation Sandbox: Support high-fidelity UAV behavior simulation and multi-dimensional log collection;
[0048] Vulnerability Diagnosis Module: Combine the anomaly pattern recognition and root cause reasoning capabilities of the LLM to output a diagnosis.
[0049] It also includes a three-layer data pipeline: a code semantic intermediate representation layer, a natural language test case description layer, and an executable test case layer.
[0050] After adopting the above technical solutions, the present invention has the following advantages:
[0051] 1. Enhanced depth of logical vulnerability detection: By combining static code analysis and dynamic behavior simulation, it can identify continuous call-triggered vulnerabilities such as "navigation state not reset after emergency braking" and "concurrent execution of waypoint tasks in no-fly zones" that are difficult to detect by traditional tools.
[0052] 2. Automated closed-loop verification: The entire process from use case generation to vulnerability diagnosis is automated, reducing manual intervention.
[0053] 3. Deep integration of domain knowledge: By injecting the JSON interface knowledge base and semantic constraints, it solves the adaptability problem of test scripts generated by the LLM to the UAV flight control system interface.
[0054] 4. Scalability advantage: It supports quickly adapting to the flight control systems of different UAV manufacturers by updating the interface knowledge base and semantic templates, and has cross-platform migration capabilities. Brief Description of the Drawings
[0055] To more clearly illustrate the technical solutions of the present invention, the technical solutions in the embodiments of the present invention will be fully described below in conjunction with the accompanying drawings in the embodiments of the present invention. It should be understood that the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative efforts fall within the protection scope of the present invention.
[0056] Figure 1 It is the overall architecture diagram of the UAV flight control vulnerability detection system in the embodiments of the present invention; Detailed Embodiments
[0057] The technical solution of the present invention will be described in detail with reference to the accompanying drawings. In the following embodiments, the method steps involved correspond one by one to the technical features in the claims, and the drawings are used to visually display the interaction relationships of each module and the core algorithm flow.
[0058] A method for detecting vulnerabilities in a UAV flight control system based on data flow analysis and LLM includes the following steps:
[0059] S1. Extract the code function modules associated with user operations in the UAV flight control system through data flow analysis methods, and establish an operation-code mapping relationship library;
[0060] Including:
[0061] S1.1. Establish a user operation type library covering user standard operations such as takeoff instructions, landing instructions, waypoint upload, emergency braking, and mode switching;
[0062] S1.2. Locate the entry functions corresponding to each operation based on control flow graph analysis, and use backward slicing technology to extract the code fragments related to the operation execution;
[0063] S1.3. Construct a data dependence graph to identify three types of key data nodes involved in the code fragments: state variables, sensor inputs, and user instruction inputs;
[0064] S1.4. Cluster and fuse the code fragments with data intersections to generate operation function modules containing complete control chains;
[0065] S1.5. Add metadata tags to each module, including operation type, code line range, input / output parameter set, and associated hardware device list.
[0066] S2. Use a large language model to generate a structured natural language semantic description for each function module code, forming a multi-dimensional semantic feature vector;
[0067] The following steps are used to generate the semantic description:
[0068] S2.1. Design a structured description template, including five fields: function intention, input parameter constraints, output behavior expectations, exception handling mechanisms, and hardware interaction interfaces;
[0069] S2.2. Input the code fragments and context annotations into the large language model together, and use chain-of-thought prompting engineering to generate an initial description;
[0070] S2.3. Design a reflection mechanism in the large language model framework to verify the description integrity, and trigger iterative correction instructions for descriptions missing required fields;
[0071] S3. Based on the relevance analysis of multi-module semantic features, construct a combined test scenario and generate natural language test cases;
[0072] It includes the following test case generation mechanisms:
[0073] S3.1. Use a large language model to construct a cross-module association graph, and analyze the timing dependence relationship and the possibility of state conflicts between operations;
[0074] S3.2. Generate a combined test strategy to cover three types of scenarios: single-operation boundary value test, double-operation timing interference test, and multi-operation concurrent pressure test;
[0075] S3.3. Construct a test step chain that includes precondition triggering, execution process interruption, and post-state verification;
[0076] S3.4. Attach the expected state results of the drone to each test case to facilitate subsequent nodes to understand the task objectives and further generate test script code and verify whether vulnerabilities are triggered.
[0077] S4. Convert the natural language test cases into executable test code through reverse semantic mapping to complete the code-based reconstruction of the test logic;
[0078] The test code conversion based on the large language model is achieved through the following methods:
[0079] S4.1. Construct a JSON interface knowledge base for the specific function call functions of the drone, and provide a standardized interface description including function names, parameter types and semantic constraints, return value structures, and exception handling strategies to the large language model. The parameter semantic constraints include explicit annotations of value range definitions (such as altitude threshold 0 - 500 meters), data types (such as three-dimensional coordinate system floating-point number arrays), and state dependence relationships (such as the landing instruction needs to be executed in the hovering state);
[0080] S4.2. Map the natural language to an executable Python script and automatically complete the standardized code templates for test framework initialization, assertion verification, and exception capture;
[0081] S4.3. Implement dynamic semantic verification during the code generation process: perform static checks on the generated function call parameters based on the JSON interface description, including parameter type matching (such as whether the waypoint coordinates are List[float]), enumeration value legality (such as flight mode limited to ["GPS", "ATTI", "Manual"]), and state machine consistency (such as sensor calibration needs to be completed before takeoff). Trigger the iterative correction process of the large language model for the generated results that fail the verification;
[0082] S4.4. Generate a test scaffold with adaptive expansion capabilities: Automatically construct the initialization and cleanup code of the test environment (such as drone ARM, flight parameter reset) based on the JSON interface description, and generate transactional test sequences according to the timing dependencies of the test cases (such as the atomic operation chain of "upload waypoints → start mission → emergency braking").
[0083] S5. Execute the test code in the drone simulation environment and capture the runtime log, and use the large language model to extract vulnerability features and locate the root cause.
[0084] Specifically include:
[0085] S5.1. Build a UAV simulation sandbox, integrating the physics engine, sensor noise model, and communication delay simulation module;
[0086] S5.2. Synchronously record system logs, perform root cause analysis based on the logs and the test case target large language model, and generate a diagnostic report.
[0087] Figure 1 The overall architecture of the present invention is shown:
[0088] 1. Operation code slicing extraction module: extracts the code snippets associated with user operations based on data flow analysis technology (such as control flow graph and data dependency graph) and generates an operation-code mapping relationship library (for S1);
[0089] 2. Code semantic analysis module: Use structured templates to guide the large language model to generate code semantic descriptions, and use reflection mechanisms to iteratively correct them (corresponding to S2);
[0090] 3. Test strategy generation module: Generates combined test scenarios based on cross-module association graphs, covering single operation boundary values, timing interference, and concurrent stress testing (corresponding to S3);
[0091] 4. Code conversion module: Integrate JSON interface knowledge base and dynamic semantic verification rules to achieve the mapping of natural language use cases to Python scripts (corresponding to S4);
[0092] 5. Logical vulnerability diagnosis module: locates the root cause of the vulnerability through multi-dimensional feature matching (for S5.2).
[0093] The above embodiments are only used to explain the technical solutions of the present invention. Any equivalent replacement or improvement based on the core idea of the present invention belongs to the protection scope of the present invention.
[0094] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit them; although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that it is still possible to modify the specific implementation manners of the present invention or perform equivalent replacements on some technical features; without departing from the spirit of the technical solutions of the present invention, they should all be covered within the scope of the technical solutions claimed by the present invention.
Claims
1. A method for detecting vulnerabilities in an unmanned aerial vehicle flight control system based on data flow analysis and LLM, characterized in that, It includes the following steps: S1. Extract the code function modules associated with user operations in the UAV flight control system through data flow analysis methods, and establish an operation-code mapping relationship library; S2. Use the large language model LLM to generate structured natural language semantic descriptions for the code of each function module, forming multi-dimensional semantic feature vectors; S3. Based on the correlation analysis of multi-module semantic features, construct combined test scenarios and generate natural language test cases; S4. Convert the natural language test cases into executable test code through reverse semantic mapping to complete the code-based reconstruction of the test logic; S5. Execute the test code in the UAV simulation environment and capture the runtime logs, and use the large language model to extract vulnerability features and locate the root cause.
2. The method for detecting vulnerabilities in the UAV flight control system based on data flow analysis and LLM according to claim 1, wherein, The S1 includes the following sub-steps: S1.
1. Establish a user operation type library, covering takeoff instructions, landing instructions, waypoint uploads, emergency braking, and mode switching user standard operations; S1.
2. Based on control flow graph analysis, locate the entry functions corresponding to each operation, and use backward slicing technology to extract the code segments related to operation execution; S1.
3. Construct a data dependence graph to identify three types of key data nodes involved in the code segments: state variables, sensor inputs, and user instruction inputs; S1.
4. Cluster and fuse the code segments with data intersections to generate operation function modules containing complete control chains; S1.
5. Add metadata tags to each module, including operation type, code line range, input and output parameter sets, and associated hardware device lists.
3. The method for detecting vulnerabilities in a drone flight control system based on data flow analysis and LLM according to claim 1, wherein The S2 uses the following steps to generate semantic descriptions: S2.
1. Design a structured description template, including five fields: function intention, input parameter constraints, output behavior expectations, exception handling mechanisms, and hardware interaction interfaces; S2.
2. Input the code segments and context annotations into the large language model together, and use chain-of-thought prompting engineering to generate initial descriptions; S2.
3. Design a reflection mechanism in the large language model framework to verify the integrity of the description, and trigger iterative correction instructions for descriptions missing required fields.
4. The method for detecting vulnerabilities in the UAV flight control system based on data flow analysis and LLM according to claim 1, characterized in that, The S3 includes the following test case generation mechanisms: S3.
1. Use the large language model to construct a cross-module association graph, and analyze the timing dependence relationship and the possibility of state conflicts between operations; S3.
2. Generate combined test strategies to cover three types of scenarios: single-operation boundary value tests, double-operation timing interference tests, and multi-operation concurrent stress tests; S3.
3. Construct a test step chain including precondition triggers, execution process interruptions, and post-state verifications; S3.
4. Attach the expected UAV state results to each test case to facilitate subsequent nodes to understand the task objectives and further generate test script code and verify whether vulnerabilities are triggered.
5. The method for detecting vulnerabilities in an unmanned aerial vehicle flight control system based on data flow analysis and LLM according to claim 1, wherein The S4 realizes the test code conversion based on the large language model through the following methods: S4.
1. Construct a JSON interface knowledge base for specific UAV function call functions, and provide a standardized interface description for the large language model, including function names, parameter types and semantic constraints, return value structures, and exception handling strategies. The parameter semantic constraints include explicit annotations of value ranges, data types, and state dependence relationships; S4.
2. Map the planned natural language to an executable Python script, and automatically complete the standardized code templates for test framework initialization, assertion verification, and exception capture; S4.
3. Implement dynamic semantic verification during code generation: perform static checks on the generated function call parameters based on the JSON interface description, including parameter type matching, enumeration value legality, and state machine consistency, and trigger the iterative correction process of the large language model for the generated results with verification failures; S4.
4. Generate a test scaffolding with adaptive expansion capabilities: automatically construct the initialization and cleanup code for the test environment based on the JSON interface description, and generate transactional test sequences according to the temporal dependencies of test cases.
6. The method for detecting vulnerabilities in an unmanned aerial vehicle flight control system based on data flow analysis and LLM according to claim 1, wherein, The specific content of S5 includes: S5.
1. Build a drone simulation sandbox, integrating a physics engine, a sensor noise model, and a communication delay simulation module; S5.
2. Synchronously record system logs, perform root cause analysis based on the logs and the test case target large language model, and generate a diagnostic report.
7. The method for detecting vulnerabilities in the UAV flight control system based on data flow analysis and LLM according to claim 1, characterized in that, The overall architecture of the method includes: Five core processing modules: Operation code slice extraction module: Generate an operation-code mapping relationship library based on data flow analysis; Multi-stage LLM processing framework: Complete semantic parsing, test scenario generation, and log analysis tasks in sequence; Code converter: Integrate the JSON interface knowledge base and semantic verification rules to ensure the domain adaptability of test scripts; Simulation sandbox: Support high-fidelity drone behavior simulation and multi-dimensional log collection; Vulnerability diagnosis module: Combine the anomaly pattern recognition and root cause reasoning capabilities of the LLM to output a diagnosis; It also includes three layers of data pipelines: code semantic intermediate representation layer, natural language test case description layer, and executable test case layer.
Citation Information
Cited By
Database custom function generation and test method and system
CN120540643A
A method and system for generating and testing custom functions of a database
CN120540643B
AI-based security vulnerability automatic repair suggestion generation method and system
CN120632894A
Code vulnerability detection method and device, computer equipment, storage medium and product
CN121435244A
Code business logic vulnerability static analysis method based on large language model
CN121765725A