Semantic Robustness of Models of Source Code
arXiv:2002.03043 · doi:10.1109/SANER53432.2022.00070
Abstract
Deep neural networks are vulnerable to adversarial examples - small input perturbations that result in incorrect predictions. We study this problem for models of source code, where we want the network to be robust to source-code modifications that preserve code functionality. (1) We define a powerful adversary that can employ sequences of parametric, semantics-preserving program transformations; (2) we show how to perform adversarial training to learn models robust to such adversaries; (3) we conduct an evaluation on different languages and architectures, demonstrating significant quantitative gains in robustness.
References in corpus (11)
- Explaining and Harnessing Adversarial Examples
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Evasion Attacks against Machine Learning at Test Time
- BAE: BERT-based Adversarial Examples for Text Classification
- Fast is better than free: Revisiting adversarial training
- Adversarial Attacks on Deep Learning Models in Natural Language Processing: A Survey
- Learning and Evaluating Contextual Embedding of Source Code
- Typilus: Neural Type Hints
- Neural Program Repair by Jointly Learning to Localize and Repair
- Adversarial Robustness for Code
- COSET: A Benchmark for Evaluating Neural Program Embeddings
Cited by in corpus (10)
- On the Generalizability of Neural Program Models with respect to Semantic-Preserving Program Transformations
- RoPGen: Towards Robust Code Authorship Attribution via Automatic Coding Style Transformation
- Unveiling Memorization in Code Models
- Self-Supervised Bug Detection and Repair
- Understanding Neural Code Intelligence Through Program Simplification
- Code Prediction by Feeding Trees to Transformers
- TreeCaps: Tree-Based Capsule Networks for Source Code Processing
- Enhancing Robustness of AI Offensive Code Generators via Data Augmentation
- STRATA: Simple, Gradient-Free Attacks for Models of Code
- Generating Adversarial Computer Programs using Optimized Obfuscations