Fuzzy testing method and device based on large model, electronic equipment and storage medium

By building a large language model for training in a domain-specific corpus, high-quality test cases that conform to syntax and semantic specifications are generated, the problem of poor adaptability of traditional fuzz testing tools in different database management systems is solved, and efficient and accurate fuzz testing is achieved.

CN120524488APending Publication Date: 2025-08-22GUANGZHOU UNIVERSITY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510506714.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

The SQL seeds generated by traditional fuzz testing tools are of low quality and are difficult to adapt across different database management systems, resulting in insufficient efficiency and accuracy of fuzz testing and ineffective vulnerabilities.

Method used

By building a large language model for training in domain-specific corpus, combining prompt generation strategies and sub-statement processing mechanisms, high-quality test cases that conform to syntax and semantic specifications are generated, and fuzzy testing across database management systems is realized.

Benefits of technology

Improves the efficiency and accuracy of fuzz testing, can discover more vulnerabilities, ensures the quality and compatibility of generated results, and is suitable for different database management systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120524488A_ABST
    Figure CN120524488A_ABST
Patent Text Reader

Abstract

The invention discloses a fuzzy testing method and device based on a large model, electronic equipment and a storage medium, and the method comprises the steps: preprocessing initial domain corpus data to obtain target domain corpus data, and constructing a domain specific corpus according to the target domain corpus data; inputting the domain-specific corpus into the to-be-trained large language model for training to obtain a target large language model; in combination with the first prompt generation strategy and a sub-statement processing mechanism, performing data processing on the to-be-converted test case to obtain a first prompt project; inputting the first prompt project into the target large language model to generate a target test case; and inputting the target test case into the target database management system for fuzzy test to obtain a fuzzy test result, and determining whether the target database management system is abnormal or not according to the fuzzy test result. The method can improve the efficiency and accuracy of fuzzy testing, thereby improving the efficiency and accuracy of finding abnormal problems such as vulnerabilities, and can be widely applied to the technical field of computers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a fuzzy testing method, device, electronic device, and storage medium based on a large model. Background Art

[0002] Currently, database management systems (DBMSs), as large-scale software, are prone to introducing vulnerabilities during development and maintenance due to their large code base and complex logic. These vulnerabilities can be exploited by malicious attackers, potentially posing threats and losses to database users. Furthermore, the complexity of DBMSs makes it difficult for developers to fully test them within a limited timeframe. Therefore, fuzz testing has been introduced to automate vulnerability discovery, significantly reducing labor costs and improving vulnerability detection efficiency.

[0003] However, the SQL (Structured Query Language) seeds generated by traditional fuzz testing tools are of low quality, which reduces the efficiency and accuracy of fuzz testing. In addition, the SQL inputs generated by traditional fuzz testing tools are usually limited to the functions of a specific database language, making it difficult to reveal errors related to other functions or new functions.

[0004] In summary, the technical problems existing in the relevant technologies need to be improved. Summary of the Invention

[0005] The embodiments of the present application are intended to at least partially address one of the technical issues in the related art. To this end, the main purpose of the embodiments of the present application is to propose a large-model-based fuzz testing method, apparatus, electronic device, and storage medium that can improve the efficiency and accuracy of fuzz testing, thereby improving the efficiency and accuracy of discovering abnormal issues such as vulnerabilities.

[0006] To achieve the above objectives, an embodiment of the present application provides a large model-based fuzzy testing method, which includes the following steps:

[0007] Obtain initial domain corpus data for the database management system;

[0008] Preprocessing the initial domain corpus data to obtain target domain corpus data, and constructing a domain-specific corpus based on the target domain corpus data;

[0009] Inputting the domain-specific corpus into the large language model to be trained for training to obtain a target large language model;

[0010] Combining the first prompt generation strategy and the statement processing mechanism, the test case to be converted is processed to obtain the first prompt project;

[0011] Inputting the first prompt project into the target large language model to generate a target test case;

[0012] The target test case is input into the target database management system for fuzz testing to obtain a fuzzy test result, so as to determine whether the target database management system has an abnormality according to the fuzzy test result.

[0013] In some embodiments, preprocessing the initial domain corpus data to obtain target domain corpus data, and constructing a domain-specific corpus based on the target domain corpus data includes:

[0014] Performing data deduplication processing on the initial domain corpus data to obtain deduplicated domain corpus data;

[0015] Performing data filtering on the deduplicated domain corpus data to obtain filtered domain corpus data;

[0016] Performing standard formatting on the filtering domain corpus data to obtain the target domain corpus data;

[0017] The domain-specific corpus is constructed based on the target domain corpus data.

[0018] In some embodiments, inputting the domain-specific corpus into the large language model to be trained for training to obtain a target large language model includes:

[0019] Inputting the domain-specific corpus into the large language model to be trained;

[0020] In the large language model to be trained, the large language model to be trained is trained according to the sequence mapping strategy and the domain-specific corpus to obtain the target large language model.

[0021] In some embodiments, combining the first prompt generation strategy and the statement segmentation processing mechanism to perform data processing on the test case to be converted to obtain the first prompt project includes:

[0022] Using state capture technology to perform data extraction processing on the test case to be converted to obtain database object state information corresponding to the test case to be converted;

[0023] In combination with the first prompt generation strategy and the statement segmentation processing mechanism, data processing is performed on the test case to be converted according to the database object state information to obtain the first prompt project.

[0024] In some embodiments, inputting the first prompt project into the target large language model to generate a target test case includes:

[0025] inputting the first prompt project into the target large language model, determining the target database management system for fuzz testing according to the first prompt project through the target large language model, and determining candidate test cases corresponding to the target database management system according to the first prompt project;

[0026] The target test case is generated by performing language conversion processing on the candidate test case through the target large language model according to the test case conversion strategy.

[0027] In some embodiments, after inputting the target test case into the target database management system for fuzz testing and obtaining the fuzz testing result, the method further includes:

[0028] Performing a quality assessment on the fuzzy test result to obtain a quality assessment result;

[0029] Performing data extraction processing on the quality assessment results to obtain coverage data and abnormal data;

[0030] A dynamic feedback mechanism is used to optimize the target large language model based on the coverage data and the abnormal data.

[0031] In some embodiments, the test cases to be converted include internal test cases and external test cases, the external test cases are obtained from an external database management system, and the method further includes the step of obtaining the internal test cases, wherein obtaining the internal test cases includes:

[0032] Obtaining test case state constraints of the target database management system;

[0033] Adopting a second prompt generation strategy to generate a second prompt project according to the test case state constraint condition;

[0034] The second prompt project is input into the target large language model to generate the internal test case.

[0035] To achieve the above objectives, another aspect of the present application provides a large model-based fuzzy testing device, which includes the following modules:

[0036] An initial domain corpus data acquisition module is used to acquire initial domain corpus data for the database management system;

[0037] An initial domain corpus data preprocessing module is used to preprocess the initial domain corpus data to obtain target domain corpus data, and to construct a domain-specific corpus based on the target domain corpus data;

[0038] A large language model training module is used to input the domain-specific corpus into the large language model to be trained to obtain a target large language model;

[0039] A first prompt project generation module is used to combine the first prompt generation strategy and the statement processing mechanism to perform data processing on the test case to be converted to obtain the first prompt project;

[0040] a target test case generation module, configured to input the first prompt project into the target large language model to generate a target test case;

[0041] The fuzzy testing module is used to input the target test case into the target database management system for fuzzy testing, obtain fuzzy testing results, and determine whether there is an abnormality in the target database management system based on the fuzzy testing results.

[0042] To achieve the above-mentioned purpose, another aspect of an embodiment of the present application provides an electronic device, which includes a memory and a processor, wherein the memory stores a computer program, and the processor implements the above-mentioned method when executing the computer program.

[0043] To achieve the above objectives, another aspect of an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described above is implemented.

[0044] The embodiments of the present application include at least the following beneficial effects: the present application provides a large model-based fuzz testing method, device, electronic device and storage medium, which obtains initial domain corpus data for a database management system; preprocesses the initial domain corpus data to obtain target domain corpus data, and constructs a domain-specific corpus based on the target domain corpus data; inputs the domain-specific corpus into the large language model to be trained for training to obtain a target large language model; combines the first prompt generation strategy and the sentence segmentation processing mechanism to process the test case to be converted to obtain a first prompt project; inputs the first prompt project into the target large language model to generate a target test case; inputs the target test case into the target database management system for fuzzy testing to obtain a fuzzy test result, so as to determine whether there is an abnormality in the target database management system based on the fuzzy test result. The embodiment of the present application constructs a domain-specific corpus to train a large language model, so that the trained target large language model has stronger domain understanding and generation capabilities. The target large language model can generate high-quality test cases that conform to grammatical and semantic specifications, thereby improving the efficiency and accuracy of fuzz testing, thereby improving the efficiency and accuracy of discovering abnormal problems such as vulnerabilities. At the same time, the target large language model can also understand and generate high-quality test cases compatible with different database management systems to achieve the generation and execution of test cases across different database management systems; in addition, the first prompt generation strategy and the statement processing mechanism are used to generate the first prompt project and submit it to the target large language model for processing, which not only improves the efficiency of task processing, but also ensures compatibility with the target large language model. Moreover, the statement processing mechanism is used to process the converted test cases to better control the quality of the generated results and avoid errors caused by input overload. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 This is a flowchart of a large model-based fuzzy testing method provided in an embodiment of the present application;

[0046] Figure 2 is a schematic diagram of a data pair example provided in an embodiment of the present application;

[0047] Figure 3 is a schematic diagram of an example of a prompt generation strategy provided in an embodiment of the present application;

[0048] Figure 4 This is a flow chart of the test case generation process based on a large model provided by an embodiment of the present application;

[0049] Figure 5 is a schematic diagram of an example of a sentence segmentation processing mechanism provided in an embodiment of the present application;

[0050] Figure 6 This is a schematic diagram of a language conversion principle provided by an embodiment of the present application;

[0051] Figure 7 This is a schematic diagram of a language conversion technology framework for a large language model across data management systems provided by an embodiment of the present application;

[0052] Figure 8 Schematic diagram of the structure of a large model-based fuzzy device provided in an embodiment of the present application;

[0053] Figure 9 This is a schematic diagram of the hardware structure of the electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0054] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application is further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the embodiments of the present application. They are merely examples of devices and methods consistent with some aspects of the embodiments of the present application as detailed in the appended claims.

[0055] It will be understood that the terms "first", "second", etc. used in this application may be used herein to describe various concepts, but unless otherwise specified, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the words "if" and "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0056] The terms "at least one", "plurality", "each", "any", etc. used in this application include "at least one", "two" or more, "plurality" or "each", "any" or "any one", "each" or "any one" as used herein.

[0057] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.

[0058] With the development and widespread use of the internet, database management systems (DBMSs) have become crucial in modern data-intensive applications, providing essential data storage and management capabilities. DBMSs are used worldwide in various industries, including finance (banking, securities), telecommunications, government affairs, manufacturing, and the internet. Common DBMSs include Oracle, MySQL, SQLite, and PostgreSQL. As large-scale software, DBMSs, due to their large code base and complex logic, inevitably introduce various vulnerabilities during development and maintenance. These vulnerabilities can be maliciously exploited by attackers, causing system crashes and potentially posing threats and losses to database users. Furthermore, the complexity of DBMSs makes it difficult for developers to fully test them within a limited timeframe. Therefore, a method is needed to detect potential vulnerabilities in DBMSs during the development phase to mitigate potential losses. Fuzz testing is currently the most popular vulnerability discovery technique in academia and industry. It can automate vulnerability discovery, significantly saving manpower and improving discovery efficiency. It has been widely used as a software testing technique for detecting memory error vulnerabilities. In recent years, many researchers have used fuzz testing technology to ensure the security of DBMSs and have successfully discovered a large number of memory vulnerabilities and logic vulnerabilities. The core idea of ​​fuzz testing is to generate random SQL query statements and input them into the DBMS to be tested to detect vulnerabilities and errors. However, directly using fuzz testing technology to test DBMSs is challenging because DBMSs have very strict requirements on the syntax and semantics of input data, and test cases that do not meet the specifications will be directly rejected. In summary, in fuzz testing of database management systems, current fuzz testing technology still has many shortcomings. For example, the shortcomings of current fuzz testing technology can include but are not limited to the following two points:

[0059] (1) The problem of poor test case generation quality due to the complexity of SQL syntax: The SQL seeds generated by traditional fuzz testing tools are of low quality. This is because the current DBMS fuzz testing tools based on syntax variation have insufficient semantic awareness of the code, resulting in a large number of grammatical and semantic errors in the generated SQL samples. Specifically, when the DBMS receives an SQL query statement, it first performs lexical analysis and grammatical analysis on it, that is, it cannot use keywords that are not in the specification; if there are any grammatical errors in the query, the DBMS will stop execution and prompt the user with an error message; when the syntax check passes, the DBMS will further check whether there are semantic errors in the SQL statement; after these two checks, the DBMS will optimize the SQL statement to generate the optimal execution plan for the executor to execute. That is, after the above two checks, the test case that is considered correct will be executed. However, the current fuzz testing tools for databases, such as Squirrel, may have relatively weak semantic understanding capabilities.

[0060] (2) Poor adaptability to different database languages: The inputs generated by current database fuzz testing tools are usually limited to the functions of a specific database language, making it difficult to reveal errors related to other functions or new functions. There are significant differences in SQL dialects between different DBMSs (such as the syntactic and semantic incompatibility between MySQL and PostgreSQL), which makes it difficult to directly apply high-quality seeds collected from one DBMS to other DBMSs. Current cross-DBMS seed reuse methods (such as rule-based conversion) have difficulty dealing with complex SQL statements and have high maintenance costs. In addition, since each DBMS implements an SQL dialect, this dialect may be almost identical to the official dialect or may have significant differences in many features, resulting in uneven performance of fuzz testing tools on different DBMSs. Different database systems may use completely different query languages ​​(such as SQL, NoSQL, etc.), further increasing the difficulty of cross-DBMS seed reuse.

[0061] In view of this, the embodiments of the present application provide a large model-based fuzz testing method, device, electronic device and storage medium. The scheme obtains initial domain corpus data for a database management system; preprocesses the initial domain corpus data to obtain target domain corpus data, and constructs a domain-specific corpus based on the target domain corpus data; inputs the domain-specific corpus into the large language model to be trained for training to obtain a target large language model; combines the first prompt generation strategy and the sentence segmentation processing mechanism to perform data processing on the test case to be converted to obtain a first prompt project; inputs the first prompt project into the target large language model to generate a target test case; inputs the target test case into the target database management system for fuzzy testing to obtain a fuzzy test result, so as to determine whether there is an abnormality in the target database management system based on the fuzzy test result. The embodiment of the present application constructs a domain-specific corpus to train a large language model, so that the trained target large language model has stronger domain understanding and generation capabilities. The target large language model can generate high-quality test cases that conform to grammatical and semantic specifications, thereby improving the efficiency and accuracy of fuzz testing, thereby improving the efficiency and accuracy of discovering abnormal problems such as vulnerabilities. At the same time, the target large language model can also understand and generate high-quality test cases compatible with different database management systems to achieve the generation and execution of test cases across different database management systems; in addition, the first prompt generation strategy and the statement processing mechanism are used to generate the first prompt project and submit it to the target large language model for processing, which not only improves the efficiency of task processing, but also ensures compatibility with the target large language model. Moreover, the statement processing mechanism is used to process the converted test cases to better control the quality of the generated results and avoid errors caused by input overload.

[0062] The embodiment of the present application provides a large model-based fuzz testing method, which relates to the field of computer technology. The embodiment of the present application provides a large model-based fuzz testing method that can be applied to a terminal, a server, or software running on a terminal or a server. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, and a car terminal, etc., but is not limited to this; the server side can be configured as an independent physical server, or as a server cluster or distributed system consisting of multiple physical servers, or as a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. The server can also be a node server in a blockchain network; the software can be an application that implements a large model-based fuzz testing method, etc., but is not limited to the above forms.

[0063] The present application can be used in numerous general or special computer system environments or configurations. For example: personal computers, server computers, handheld devices or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs (Personal Computers, personal computers), minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0064] See also Figure 1 , Figure 1 This is an optional flowchart of the large model-based fuzzy testing method provided in the embodiment of the present application. Figure 1 The method may include but is not limited to steps S101 to S106.

[0065] Step S101, obtaining initial domain corpus data for the database management system;

[0066] The initial domain corpus data refers to the original data set for the database management system (DBMS), which can be understood as the original training dataset. The initial domain corpus data is used to construct the domain-specific corpus as the final training dataset, and then to train the large language model with the domain-specific corpus. This enables the trained large language model to better understand the SQL language and its implementation in the target DBMS.

[0067] In order to build a high-quality corpus (domain-specific corpus) for the target DBMS (such as MySQL, PostgreSQL, Oracle, etc.), data can be obtained from official documents and specifications, open source projects and code bases, public datasets, etc.

[0068] For official documents and specifications, for example, you can refer to SQL standards (such as ANSI SQL, ISO SQL) and official documents of the target DBMS (such as official manuals of MySQL and PostgreSQL), which describe in detail how to use SQL syntax, keywords, functions, and operators.

[0069] For open source projects and code repositories, you can, for example, extract existing SQL test cases from the open source projects. For example, open source databases like MySQL and PostgreSQL often come with a large number of test scripts that cover various SQL query scenarios. Specifically, you can navigate to the corresponding test directory (such as mysql-test / or src / test / regress / sql / ) based on the database type.

[0070] Public datasets may include but are not limited to WikiSQL and Spider, each of which has different characteristics and applicable scenarios.

[0071] In addition, users' real query logs can be extracted from the actual running DBMS. These logs reflect the SQL usage patterns in real scenarios, including simple queries and complex queries. Specifically, the SQL statements in these logs are obtained as part of the training dataset source.

[0072] Step S102: preprocessing the initial domain corpus data to obtain target domain corpus data, and constructing a domain-specific corpus based on the target domain corpus data;

[0073] In some embodiments, step S102 may include: performing data deduplication processing on the initial domain corpus data to obtain deduplication domain corpus data; performing data filtering processing on the deduplication domain corpus data to obtain filtered domain corpus data; performing standard formatting processing on the filtered domain corpus data to obtain target domain corpus data; and constructing a domain-specific corpus based on the target domain corpus data.

[0074] In specific implementations, since raw data usually contains noise, redundancy, errors, or inconsistent information, direct use may lead to biased analysis results or decreased model performance. Therefore, it is necessary to systematically preprocess the initially acquired domain corpus data and build a high-quality domain-specific corpus based on the preprocessed data, providing a reliable data foundation for subsequent analysis, model training, or application development.

[0075] In an embodiment of the present application, a large language model is pre-trained by constructing a domain-specific corpus, enabling the large language model to adapt to SQL query generation tasks and ensuring that the generated SQL query statements (test cases) conform to the grammatical and semantic specifications of the target DBMS. In order for the large language model to better understand the SQL language and its implementation in the target DBMS, it is first necessary to construct a high-quality domain-specific corpus. This domain-specific corpus will serve as the basic data for training the large language model, ensuring that the large language model can learn the grammatical and semantic rules related to the target DBMS.

[0076] For example, in order to build a high-quality corpus for the target DBMS (such as MySQL, PostgreSQL, Oracle, etc.), initial domain corpus data can be collected from official documents and specifications, open source projects and code libraries, public data sets, etc.; after collecting the initial domain corpus data, the initial domain corpus data is preprocessed, and the preprocessing operations may specifically include but are not limited to: removing duplicate SQL statements, filtering out incomplete or syntactically incorrect SQL query statements, and unifying SQL query statements into a standard format (such as indentation, capitalization, quotation style, etc.); through preprocessing operations to reduce redundancy and improve consistency, the initial domain corpus data becomes high-quality target domain corpus data, and then the high-quality target domain corpus data is used to construct a domain-specific corpus.

[0077] Step S103: inputting the domain-specific corpus into the large language model to be trained to obtain a target large language model;

[0078] In some embodiments, step S103 may include: inputting the domain-specific corpus into the large language model to be trained; in the large language model to be trained, training the large language model to be trained according to the sequence mapping strategy and the domain-specific corpus to obtain a target large language model.

[0079] In order to reach the deep logic of DBMS, the embodiment of the present application uses a large language model to guide queries, capture the deeper semantic meaning of SQL query statements, and discover deeper vulnerabilities and problems, thereby improving the efficiency and effectiveness of fuzz testing.

[0080] Optionally, the domain-specific corpus is a training dataset for the large language model to be trained, which is used to guide the iterative training of the initial large language model to be trained. Training is stopped when the large language model meets the model convergence conditions, resulting in a trained target large language model. The target large language model has stronger domain understanding and generation capabilities. It can generate high-quality test cases that conform to grammatical and semantic specifications, thereby improving the efficiency and accuracy of fuzz testing, thereby improving the efficiency and accuracy of discovering abnormal problems such as vulnerabilities. At the same time, the target large language model can also understand and generate high-quality test cases compatible with different database management systems, thereby realizing the generation and execution of test cases across different database management systems.

[0081] The sequence mapping strategy refers to the sequence-to-sequence (seq2seq) method, see Figure 2 , Figure 2 This is a schematic diagram of a data pair example provided in an embodiment of the present application, such as Figure 2As shown in Figure 2, the core idea of ​​the sequence-to-sequence (seq2seq) method is to use natural language queries as input sequences and target SQL queries as output sequences, and learn the mapping relationship between the two through a large language model. Natural language queries describe query requirements in a human-readable way, and SQL query statements correspond to the SQL implementation of natural language queries. For example, Figure 2 As shown in the figure, assuming that the natural language query is "list all employees older than X years old", the corresponding SQL query statement is "SELECT name FROM employees WHERE age>X;", where Figure 2 The "X" in the example represents the age value.

[0082] In addition, in the process of training large language models, annotated datasets are also needed to participate in model training. The annotated datasets consist of natural language queries and their corresponding SQL query statements, which are used to train the model to understand natural language and generate correct SQL query statements.

[0083] Among them, the labeled dataset is the training basis for the sequence-to-sequence (seq2seq) method. The seq2seq model realizes the conversion capability from natural language to SQL by learning the mapping relationship between natural language queries and SQL queries in the labeled dataset.

[0084] The embodiment of the present application uses a sequence-to-sequence method to train a large language model in combination with a high-quality domain-specific corpus, so that the trained large language model can effectively realize the task of generating natural language queries into SQL query statements.

[0085] Step S104: combining the first prompt generation strategy and the statement processing mechanism, performing data processing on the test case to be converted to obtain a first prompt project;

[0086] Optionally, the number of test cases to be converted is several. The test cases to be converted include internal test cases and external test cases, the external test cases are obtained from the external database management system, and the internal test cases are generated by the target large language model. Among them, the external test cases introduced are different test cases generated by other different DBMSs, and the required external test cases are high-quality test cases selected after screening. Similarly, the internal test cases generated based on the target large language model in the embodiment of the present application are also high-quality test cases determined by quality screening.

[0087] It should be noted that, in the embodiments of the present application, the test cases to be converted for subsequent language conversion may include both internal test cases and external test cases, or may consist of only internal test cases, or may consist of only external test cases. Whether the test cases to be converted need to include both internal test cases and external test cases, or only one type of test case, can be selected based on actual conditions in specific applications. The embodiments of the present application do not impose any restrictions on this. However, it is necessary to ensure that the test cases to be converted are all high-quality test cases.

[0088] In some embodiments, the step of obtaining internal test cases may also be included. The step of obtaining internal test cases may include: obtaining the test case status constraints of the target database management system; adopting a second prompt generation strategy to generate a second prompt project based on the test case status constraints; inputting the second prompt project into the target large language model to generate internal test cases.

[0089] Among them, the target database management system refers to the database referenced by the test cases that need to be generated, and is also the database for fuzz testing.

[0090] For internal test cases, they can also be called initial high-quality test cases generated by the target large language model, which can be used for subsequent language conversion of the target large language model to generate higher-quality target high-quality test cases; similarly, external test cases can also be understood as different initial high-quality test cases obtained from other different database management systems. It can be understood that the entire test case to be converted can be regarded as an initial high-quality test case, which can be used for subsequent language conversion of the target large language model to generate higher-quality target high-quality test cases that are compatible with different database systems, so that the target high-quality test cases can be input into the target database management system for fuzz testing, thereby realizing the generation and execution of test cases across different database management systems, and solving the problem of incompatibility of the syntax of SQL dialects.

[0091] Test case status constraints are generation constraints for the test cases that need to be generated by the target database management system. These generation constraints correspond to the state information of the test cases (SQL queries) to be generated. This state information may include, but is not limited to, the state information of the target database management system referenced by the test cases to be generated and the structural information of the test cases to be generated, such as the sub-schema description referenced by the SQL queries: table structure, field types, primary keys, foreign keys, etc.

[0092] The test case state constraints are used to construct the second prompting project, which refers to the prompting strategy used to guide the target large language model to generate initial high-quality test cases (here, internal test cases) that conform to the grammatical and semantic specifications of the target database management system. Figure 3 , Figure 3 is a schematic diagram of an example of a prompt generation strategy provided by an embodiment of the present application, such as Figure 3 As shown, prompts for guiding the target large language model can be generated based on the SQL query statements to be generated and their corresponding schema information. These prompts provide necessary context-aware information, such as descriptions of sub-schemas referenced by statements: such as table structure, field type, primary key, foreign key, etc. The embodiment of the present application designs a specific prompt template to guide the LLM to generate a specific type of SQL query. For example, Figure 3 As shown, Figure 3 Is a prompt project template, such as Figure 3 The project template explicitly specifies the query type of the target DBMS, such as nested queries and JOIN operations, as well as the tables involved, thereby helping LLM generate SQL queries that meet the requirements.

[0093] In the specific implementation, after the prompt projects are built, they need to be submitted to the target large language model, and the responses of the target large language model need to be post-processed to generate test cases that meet the specifications of the target DBMS.

[0094] It should be noted that the initial high-quality test cases (here, internal test cases) generated by the target large language model based on the second prompt generation strategy and the test case state constraints can also be directly input into the target database management system for fuzz testing, because the internal test cases are high-quality test cases that conform to the syntax and semantic specifications of the target database management system. If the external test cases conform to the syntax and semantic specifications of the target database management system, fuzz testing can also be performed directly. This is because the subsequent language conversion operation processing can be understood as a process of optimizing the initial high-quality test cases to obtain high-quality target test cases, and the language conversion process can realize the generation and execution of test cases across different database management systems, solving the problem of incompatibility of the syntax of SQL dialects. It can be understood that in actual applications, if a more accurate target test case is not required in some cases, the initial high-quality test case (such as the internal test case) that conforms to the syntax and semantic specifications of the target database management system can be used as the target test case for subsequent fuzz testing. If a more accurate target test case needs to be generated, it is optimized through the subsequent language conversion technology in the embodiment of the present application to obtain a high-quality target test case that is compatible with different database systems.

[0095] In order to solve the problem of lack of high-quality initial seeds in DBMS fuzz testing, the embodiment of the present application uses the powerful semantic understanding and SQL query generation capabilities of LLM (Large Language Model) through carefully designed prompts (such as Figure 3 The second prompt project) guides LLM to generate high-quality initial seeds (internal test cases) that conform to the syntax and semantic specifications of the target DBMS, making them syntactically valid, semantically compliant, and diverse SQL query statements, thereby significantly improving the efficiency and effectiveness of fuzz testing. Figure 4 , Figure 4 This is a flow chart of the test case generation process based on the large model provided by the embodiment of the present application, such as Figure 4As shown in FIG, the overall implementation process of test case generation guided by a large model is as follows: first, three basic training data types are collected: open source projects, test cases corresponding to actual running DBMSs, and SQL standards. These three basic training data types are preprocessed, and then a high-quality domain-specific corpus is constructed based on the preprocessed basic training data. Second, the high-quality domain-specific corpus is input into the large language model to be trained for fine-tuning training to obtain a trained target large language model. Third, the state information of the target database management system referenced by the SQL query statement to be generated and the structural information of the test case to be generated are obtained. Fourth, a SQL query generation strategy (here, the second prompt generation strategy) is used to construct a second prompt project based on the state information of the target database management system referenced by the SQL query statement to be generated and the structural information of the test case to be generated. The second prompt project contains context-aware information corresponding to the SQL query statement to be generated. Fifth, the second prompt project is input into the trained target large language model, and the second prompt project is used to guide the target large language model to generate high-quality SQL query statements (internal test cases) that conform to the grammatical and semantic specifications of the target database management system. After obtaining high-quality SQL query statements, in actual applications, if a more precise target test case is not required in some cases, the high-quality SQL query statements generated here that conform to the syntax and semantic specifications of the target database management system can be used as target test cases for subsequent fuzz testing, that is, the diversified SQL query statements generated in the fifth step can be input into the target DBMS for fuzz testing, and the fuzzy test results can be obtained to determine whether the target DBMS has vulnerabilities based on the fuzzy test results; and if a more precise target test case needs to be generated, the diversified SQL query statements generated in the fifth step are optimized through the subsequent language conversion technology in the embodiment of the present application, and finally a high-quality target test case compatible with different database systems is obtained, and then the target test case is input into the target DBMS for fuzz testing to obtain the fuzzy test results to determine whether the target DBMS has vulnerabilities based on the fuzzy test results.

[0096] It can be understood that the method of generating internal test cases based on the target large language model according to the second prompt generation strategy and test case state constraints in the embodiment of the present application is mainly to solve the problem of lack of high-quality initial seeds in DBMS fuzz testing. It aims to utilize the large language model in deep learning technology to adapt it to the SQL query generation task to enhance the understanding of SQL query semantics and syntax, and with its powerful semantic understanding and SQL query statement generation capabilities, generate SQL query statements with grammatical validity and semantic correctness. During the generation process, the semantic specifications and data dependencies of the database system are taken into account to ensure that the generated SQL query statements conform to the expected semantics and behaviors, thereby improving the efficiency and effectiveness of database fuzz testing.

[0097] In some embodiments, step S104 may include: using state capture technology to perform data extraction processing on the test case to be converted to obtain database object state information corresponding to the test case to be converted; combining the first prompt generation strategy and the statement processing mechanism, performing data processing on the test case to be converted according to the database object state information to obtain the first prompt project.

[0098] Among them, state capture technology is a technology used to extract state information of test cases to be converted (mainly for external test cases). Since there are many mature technologies for state capture technology in the current information age, the embodiments of this application do not limit this. Those skilled in the art can select it according to actual conditions, and the embodiments of this application will not be elaborated here.

[0099] Optionally, the database object status information is status information (such as table structure, field type, constraint conditions, etc.) of the database object referenced by the SQL query statement in the test case to be converted.

[0100] The first prompt generation strategy is used to combine the statement processing mechanism and process the data of the test case to be converted according to the database object status information to obtain the first prompt project. Figure 5 , Figure 5 This is a schematic diagram of an example of a sentence processing mechanism provided by an embodiment of the present application. Figure 5 As shown, the function of the statement processing mechanism is to generate a prompt (first prompt project) containing a description part, an SQL statement part and a command part for each SQL query statement in the test case to be converted. It can be understood that the structured part of the first prompt project contains a description part, an SQL statement part and a command part, such as Figure 5 Example, Figure 5 This example is a hint example for converting a statement from MySQL syntax to DuckDB syntax. The first hint generation strategy differs from the second hint generation strategy.

[0101] In the specific implementation, in order to guide the target large language model to complete the complex SQL query statement conversion task, it is necessary to carefully design the prompts (here is the first prompt project). At present, the traditional method directly inputs the entire test case into the target large language model. This process may contain a large number of SQL query statements, but due to the context window limitation of the target large language model, such as the 8k Token of GPT-4, long text processing will cause truncation or performance degradation. Therefore, the embodiment of the present application supports large-scale cross-DBMS test case statement-by-statement conversion by designing an efficient large language model prompt template (here is the first prompt generation strategy), and solves the problem of the limitation of the input and output length of the large language model. In order to solve this limitation problem, the embodiment of the present application adopts a statement processing mechanism to split the test case to be converted into independent SQL query statements, and generates independent prompts for each SQL query statement (the prompt for each independent statement contains Figure 5 The structured portion of the example is then submitted to the target large language model for processing. This not only improves task processing efficiency but also ensures compatibility with the target large language model. The design of these prompts directly determines the output quality of the large language model. Furthermore, this step-by-step processing allows for better control over the quality of generated results and avoids errors caused by input overload.

[0102] In an embodiment of the present application, the process of step S104 is: first, using state capture technology to extract the state information (such as table structure, field type, constraints, etc.) of the database objects referenced by the test case to be converted (SQL query statement to be converted); then, combined with the first prompt generation strategy, according to the statement processing mechanism, a prompt including a description part, an SQL statement part and a command part is generated for each SQL query statement to avoid the limitations of the large language model when processing complex input.

[0103] Step S105: inputting the first prompt project into the target large language model to generate a target test case;

[0104] In some embodiments, step S105 may include: inputting the first prompt project into the target large language model, determining the target database management system for fuzz testing according to the first prompt project through the target large language model, and determining the candidate test cases corresponding to the target database management system according to the first prompt project; performing language conversion processing on the candidate test cases according to the test case conversion strategy through the target large language model to generate target test cases.

[0105] Optionally, since the target large language model has been fine-tuned with high-quality SQL query cases, it is able to understand and generate SQL query statements that are compatible with different database systems. Figure 6 , Figure 6 This is a schematic diagram of a language conversion principle provided by an embodiment of the present application. Figure 6 As shown in the language conversion stage in fuzz testing, first, high-quality SQL query cases generated from other different database management systems and high-quality SQL query cases generated by the target large model (test cases to be converted) are prepared; then, according to the database used in the fuzz testing environment, the SQL query generation strategy suitable for the database is dynamically selected, and the high-quality SQL query cases are converted into the grammatical form supported by the target database management system through the SQL language conversion technology of the target large language model, so as to obtain high-quality seeds (target test cases) that can explore deeper codes. This method helps to guide the generation of high-quality seeds (target test cases) and provides an effective solution for fuzz testing across multiple databases.

[0106] In its implementation, the powerful learning capabilities of large language models are leveraged to deeply understand the grammatical differences between various database languages ​​(such as PostgreSQL and MySQL). This allows for the translation of queries in one language into queries in another, ensuring that a seed covering the deep execution path in one DBMS is also applicable to other DBMSs. This language translation capability of large language models enables the generation and execution of test cases across diverse database systems, resolving the issue of grammatical incompatibilities between SQL dialects.

[0107] Step S106: input the target test case into the target database management system for fuzzy testing to obtain a fuzzy testing result, and determine whether the target database management system has an abnormality based on the fuzzy testing result.

[0108] In some embodiments, after the step of inputting the target test case into the target database management system for fuzz testing and obtaining the fuzz testing results, the method may also include: performing quality assessment on the fuzz testing results to obtain quality assessment results; performing data extraction processing on the quality assessment results to obtain coverage data and exception data; and using a dynamic feedback mechanism to optimize the target large language model based on the coverage data and exception data.

[0109] In order to address the problem of low quality of target seed generation in DBMS fuzz testing and the challenge of cross-DBMS seed reuse, the embodiment of this application proposes a SQL language conversion technology based on a large language model (LLM). The SQL language conversion technology based on a large language model (LLM) aims to achieve the generation and optimization of high-quality target seeds by fully utilizing the powerful generation capability of LLM, combining state capture technology, prompt engineering (here is the first prompt engineering) and dynamic feedback mechanism, thereby significantly improving the efficiency and depth of fuzz testing. Specifically, please refer to Figure 7 , Figure 7 It is a schematic diagram of the language conversion technology framework of the cross-data management system of the large language model provided by the embodiment of the present application. As Figure 7 shown, the SQL conversion process across DBMSs based on the large language model is as follows: The first step is data preparation and preprocessing: Collect three types of basic training data, namely open source projects, test cases corresponding to multiple mainstream DBMSs, and SQL standards, and preprocess these three types of basic training data. Then, based on the preprocessed basic training data, construct a high-quality domain-specific corpus, and use the domain-specific corpus as the training dataset to ensure the quality and diversity of the training dataset. The second step is to input the high-quality domain-specific corpus into the large language model to be trained for fine-tuning training to obtain the trained target large language model. The third step is to obtain high-quality test cases of multiple other different DBMSs (that is, Figure 7 the content corresponding to "execute test cases" in Figure 7 ), and at the same time, it is necessary to input the high-quality test cases generated by the target large model. The fourth step is to use the state capture technology to extract the state information of the database objects (such as table structure, field type, constraint conditions, etc.) referenced by the SQL query statements corresponding to the high-quality test cases, that is, to annotate the SQL query statements and obtain the state information of the database objects referenced by the SQL query statements. The fifth step is then to combine the first prompt generation strategy and generate prompts including a description part, an SQL statement part, and a command part for each SQL query statement according to the sub-statement processing mechanism to avoid the limitations of the large language model when processing complex inputs. The sixth step is to input the prompts generated in the fifth step into the target large language model, and guide the target large language model to generate target test cases (target SQL query statements) through the prompts generated in the fifth step. The seventh step is finally to input the target test cases into the target DBMS (such as

[0110] In specific implementations, the advantages of introducing a large language model in the embodiments of this application are: Large language models have significant advantages in understanding and generating natural language, thereby better understanding SQL syntax and semantic specifications. Through the generative capabilities of large language models, they can generate samples that better conform to SQL grammar rules, improving the effectiveness of fuzz testing. Furthermore, large language models can provide precise feedback strategies to guide sample generation during testing and optimize seed selection strategies, helping to uncover deeper potential vulnerabilities.

[0111] Steps S101 to S106 shown in the embodiment of the present application are as follows: obtaining initial domain corpus data for a database management system; preprocessing the initial domain corpus data to obtain target domain corpus data, and constructing a domain-specific corpus based on the target domain corpus data; inputting the domain-specific corpus into the large language model to be trained to obtain a target large language model; combining the first prompt generation strategy and the sentence segmentation processing mechanism to process the test case to be converted to obtain a first prompt project; inputting the first prompt project into the target large language model to generate a target test case; inputting the target test case into the target database management system for fuzzy testing to obtain a fuzzy test result, so as to determine whether there is an abnormality in the target database management system based on the fuzzy test result. The embodiment of the present application constructs a domain-specific corpus to train a large language model, so that the trained target large language model has stronger domain understanding and generation capabilities. The target large language model can generate high-quality test cases that conform to grammatical and semantic specifications, thereby improving the efficiency and accuracy of fuzz testing, thereby improving the efficiency and accuracy of discovering abnormal problems such as vulnerabilities. At the same time, the target large language model can also understand and generate high-quality test cases compatible with different database management systems to achieve the generation and execution of test cases across different database management systems; in addition, the first prompt generation strategy and the statement processing mechanism are used to generate the first prompt project and submit it to the target large language model for processing, which not only improves the efficiency of task processing, but also ensures compatibility with the target large language model. Moreover, the statement processing mechanism is used to process the converted test cases to better control the quality of the generated results and avoid errors caused by input overload.

[0112] In summary, the problems to be solved by the embodiments of the present application and their corresponding solutions are as follows:

[0113] (1) To solve the problem of lack of high-quality initial seeds in DBMS fuzz testing. The embodiment of the present application utilizes the powerful semantic understanding and SQL query statement generation capabilities of LLM, and through carefully designed prompts (second prompt engineering), guides LLM to generate high-quality initial seeds that conform to the syntax and semantic specifications of the target DBMS, so that the high-quality initial seeds become syntactically valid, semantically compliant, and diversified SQL queries, thereby significantly improving the efficiency and effectiveness of fuzz testing. Compared with traditional vulnerability discovery technologies, the method provided by the embodiment of the present application covers the code of the database management system more deeply and can more efficiently mine system vulnerabilities. Specifically, information about the given DBMS status and input structure can be directly asked to LLM (such as ChatGPT), and LLM can generate input that conforms to syntax and semantic specifications, thereby improving the ability to discover deep DBMS code vulnerabilities. The method of guiding SQL query statement generation based on a large language model can not only improve the efficiency and accuracy of vulnerability discovery, but also better adapt to complex DBMS structures and logic.

[0114] (2) To solve the challenge of cross-DBMS seed reuse in DBMS fuzz testing. The embodiment of the present application proposes a SQL language conversion technology based on a large language model (LLM), which aims to achieve the generation and optimization of high-quality target seeds by making full use of the powerful generation capability of LLM, combined with state capture, first prompt engineering and dynamic feedback mechanism, thereby significantly improving the efficiency and depth of fuzz testing. Specifically, by utilizing the powerful learning ability of large language models, we can deeply understand the grammatical differences between various database languages ​​​​(such as PostgreSQL and MySQL), and then master how to convert queries in one language into queries in another language, so that a seed that covers a deep execution path in a DBMS is also applicable to other DBMS. Through the language conversion capability of the large language model, the generation and execution of test cases across different database systems are realized, solving the problem of incompatibility of the grammars of SQL dialects.

[0115] The general process of the large model-based fuzz testing method provided by the embodiment of the present application is as follows: First, a large language model (LLM) is used as an input generation engine. In practical applications, the state information and input structure information about the target database management system can be directly provided to the large language model; then, based on the state information and input structure information of the target database management system, the target test input that conforms to the grammatical and semantic specifications is generated based on the large language model; finally, the target test input is applied to the target database management system to trigger the execution of deep code paths, thereby discovering potential vulnerabilities. Through the learning ability of the large language model, the adaptability to the logic and structure of complex database management systems is improved, and the efficiency and accuracy of vulnerability mining are enhanced.

[0116] The key points of the embodiments of this application include the following two points:

[0117] (1) Intelligent seed generation method based on large language model (LLM): Using large language model (LLM) as input generation engine, it aims to overcome the challenges faced by traditional fuzzers in discovering vulnerabilities in database management systems. Compared with traditional vulnerability discovery technology, the intelligent seed generation method based on large language model provided by the embodiment of the present application covers the code of database management system more deeply and can more efficiently mine system vulnerabilities. Specifically, through carefully designed prompts, the LLM is guided to generate high-quality initial seeds that conform to the syntax and semantic specifications of the test target DBMS, making it a syntactically valid, semantically compliant, and diversified SQL query, thereby improving the ability to discover deep code vulnerabilities of DBMS, thereby significantly improving the efficiency and accuracy of fuzz testing.

[0118] (2) SQL language conversion technology based on large language model (LLM): aims to achieve high-quality target seed generation across DBMSs. SQL language conversion technology based on large language model (LLM) aims to fully utilize the powerful generation capability of LLM, combined with pattern capture, prompt engineering and dynamic feedback mechanism to achieve the generation and optimization of high-quality target seeds. It can deeply understand the grammatical and semantic differences between different DBMSs, convert high-quality seeds in one DBMS into compatible seeds of the target DBMS, realize the generation and execution of test cases across different database systems, solve the problem of grammatical incompatibility of SQL dialects, and thus significantly improve the efficiency and depth of fuzz testing.

[0119] The embodiments of this application are intended to provide a method for effectively improving the effectiveness of SQL query sample generation and resolving compatibility issues between different database versions. Specifically, the method aims to address the problems associated with applying fuzz testing technology to DBMS testing, achieve simultaneous improvements in the security of the database management system, and ultimately implement security testing of the DBMS in an intelligent, verifiable, and efficient manner. The embodiments of this application provide a large-scale model-based fuzz testing method that can accurately and efficiently discover memory-based security threats in database management systems, thereby minimizing, reducing, and recovering losses to the greatest extent possible. Furthermore, the method can promote and strengthen the formation and technological innovation of intelligent network vulnerability mining systems, establish a relatively comprehensive technical system and plan, and provide strong support for the construction of cyberspace security strategies and defense capabilities.

[0120] See also Figure 8 The embodiment of the present application further provides a large model-based fuzzy testing device 800, which can implement the above-mentioned large model-based fuzzy testing method. The device includes the following modules:

[0121] Initial domain corpus data acquisition module 801, used to acquire initial domain corpus data for the database management system;

[0122] An initial domain corpus data preprocessing module 802 is configured to preprocess the initial domain corpus data to obtain target domain corpus data, and to construct a domain-specific corpus based on the target domain corpus data;

[0123] A large language model training module 803 is configured to input the domain-specific corpus into the large language model to be trained to obtain a target large language model;

[0124] A first prompt project generating module 804 is configured to combine the first prompt generating strategy and the statement processing mechanism to process the test case to be converted and obtain a first prompt project;

[0125] A target test case generating module 805 is configured to input the first prompt project into the target large language model to generate a target test case;

[0126] The fuzzy testing module 806 is used to input the target test case into the target database management system for fuzzy testing, obtain a fuzzy testing result, and determine whether there is an abnormality in the target database management system based on the fuzzy testing result.

[0127] It can be understood that the contents of the above method embodiments are all applicable to the present device embodiments, the functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0128] The present application also provides an electronic device comprising a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the large model-based fuzz testing method. The electronic device can be any smart terminal, such as a tablet computer or an in-vehicle computer.

[0129] It can be understood that the contents of the above method embodiments are applicable to the present device embodiments, the functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0130] See also Figure 9 , Figure 9 The hardware structure of an electronic device according to another embodiment is shown. The electronic device includes:

[0131] The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.

[0132] The memory 902 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 902 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called by the processor 901 to execute the large model-based fuzz testing method of the embodiments of this application.

[0133] Input / output interface 903, used to implement information input and output;

[0134] Communication interface 904, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);

[0135] Bus 905 , which transmits information between various components of the device (e.g., processor 901 , memory 902 , input / output interface 903 , and communication interface 904 );

[0136] The processor 901 , the memory 902 , the input / output interface 903 and the communication interface 904 are connected to each other in communication within the device via a bus 905 .

[0137] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned large model-based fuzzy testing method.

[0138] It can be understood that the contents of the above method embodiments are all applicable to the present storage medium embodiment, the functions specifically implemented by the present storage medium embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0139] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0140] The embodiments of the present application provide a large-model-based fuzz testing method, a large-model-based fuzz testing device, an electronic device, and a storage medium, which obtain initial domain corpus data for a database management system; preprocess the initial domain corpus data to obtain target domain corpus data, and construct a domain-specific corpus based on the target domain corpus data; input the domain-specific corpus into a large language model to be trained for training to obtain a target large language model; combine a first prompt generation strategy and a sentence segmentation processing mechanism to perform data processing on the test case to be converted to obtain a first prompt project; input the first prompt project into the target large language model to generate a target test case; input the target test case into a target database management system for fuzzy testing to obtain a fuzzy test result, so as to determine whether there is an abnormality in the target database management system based on the fuzzy test result. The embodiment of the present application constructs a domain-specific corpus to train a large language model, so that the trained target large language model has stronger domain understanding and generation capabilities. The target large language model can generate high-quality test cases that conform to grammatical and semantic specifications, thereby improving the efficiency and accuracy of fuzz testing, thereby improving the efficiency and accuracy of discovering abnormal problems such as vulnerabilities. At the same time, the target large language model can also understand and generate high-quality test cases compatible with different database management systems to achieve the generation and execution of test cases across different database management systems; in addition, the first prompt generation strategy and the statement processing mechanism are used to generate the first prompt project and submit it to the target large language model for processing, which not only improves the efficiency of task processing, but also ensures compatibility with the target large language model. Moreover, the statement processing mechanism is used to process the converted test cases to better control the quality of the generated results and avoid errors caused by input overload.

[0141] The embodiments described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0142] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.

[0143] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.

[0144] Those skilled in the art will appreciate that all or some of the steps in the methods, systems, and functional modules / units in the devices disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.

[0145] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0146] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0147] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the above-mentioned units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0148] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0149] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0150] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes various media that can store programs, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0151] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention should be within the scope of the present invention.

Claims

1. A fuzzy testing method based on a large model, characterized in that: The method comprises the following steps: Obtain initial domain corpus data for the database management system; Preprocessing the initial domain corpus data to obtain target domain corpus data, and constructing a domain-specific corpus based on the target domain corpus data; Inputting the domain-specific corpus into the large language model to be trained for training to obtain a target large language model; Combining the first prompt generation strategy and the statement processing mechanism, the test case to be converted is processed to obtain the first prompt project; Inputting the first prompt project into the target large language model to generate a target test case; The target test case is input into the target database management system for fuzz testing to obtain a fuzzy test result, so as to determine whether the target database management system has an abnormality according to the fuzzy test result.

2. The method according to claim 1, characterized in that The preprocessing of the initial domain corpus data to obtain target domain corpus data, and constructing a domain-specific corpus based on the target domain corpus data, includes: Performing data deduplication processing on the initial domain corpus data to obtain deduplicated domain corpus data; Performing data filtering on the deduplicated domain corpus data to obtain filtered domain corpus data; Performing standard formatting on the filtering domain corpus data to obtain the target domain corpus data; The domain-specific corpus is constructed based on the target domain corpus data.

3. The method according to claim 1, characterized in that The step of inputting the domain-specific corpus into the large language model to be trained to obtain a target large language model comprises: Inputting the domain-specific corpus into the large language model to be trained; In the large language model to be trained, the large language model to be trained is trained according to the sequence mapping strategy and the domain-specific corpus to obtain the target large language model.

4. The method according to claim 1, wherein The first prompt generation strategy and the statement processing mechanism are combined to perform data processing on the test case to be converted to obtain the first prompt project, including: Using state capture technology to perform data extraction processing on the test case to be converted to obtain database object state information corresponding to the test case to be converted; In combination with the first prompt generation strategy and the statement segmentation processing mechanism, data processing is performed on the test case to be converted according to the database object state information to obtain the first prompt project.

5. The method according to claim 1, wherein The step of inputting the first prompt project into the target large language model to generate a target test case includes: inputting the first prompt project into the target large language model, determining the target database management system for fuzz testing according to the first prompt project through the target large language model, and determining candidate test cases corresponding to the target database management system according to the first prompt project; The target test case is generated by performing language conversion processing on the candidate test case through the target large language model according to the test case conversion strategy.

6. The method according to claim 1, characterized in that After inputting the target test case into the target database management system for fuzz testing and obtaining the fuzz testing result, the method further includes: Performing a quality assessment on the fuzzy test result to obtain a quality assessment result; Performing data extraction processing on the quality assessment results to obtain coverage data and abnormal data; A dynamic feedback mechanism is used to optimize the target large language model based on the coverage data and the abnormal data.

7. The method according to claim 1, characterized in that The test cases to be converted include internal test cases and external test cases, the external test cases are obtained from an external database management system, and the method further includes a step of obtaining the internal test cases, wherein obtaining the internal test cases includes: Obtaining test case state constraints of the target database management system; Adopting a second prompt generation strategy to generate a second prompt project according to the test case state constraint condition; The second prompt project is input into the target large language model to generate the internal test case.

8. A fuzzy testing device based on a large model, characterized in that: The device comprises the following modules: An initial domain corpus data acquisition module is used to acquire initial domain corpus data for the database management system; An initial domain corpus data preprocessing module is used to preprocess the initial domain corpus data to obtain target domain corpus data, and to construct a domain-specific corpus based on the target domain corpus data; A large language model training module is used to input the domain-specific corpus into the large language model to be trained to obtain a target large language model; A first prompt project generation module is used to combine the first prompt generation strategy and the statement processing mechanism to perform data processing on the test case to be converted to obtain the first prompt project; a target test case generation module, configured to input the first prompt project into the target large language model to generate a target test case; The fuzzy testing module is used to input the target test case into the target database management system for fuzzy testing, obtain fuzzy testing results, and determine whether there is an abnormality in the target database management system based on the fuzzy testing results.

9. An electronic device, characterized in that: The electronic device includes a memory and a processor, the memory stores a computer program, and the processor implements the method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • Test data preservation method and device based on large model, storage medium and equipment

    CN120743796A