There is a newer version of the record available.

Published April 25, 2023 | Version v1

Adversarial Robustness in Software Analytics: Bridging the Gap between Machine Learning Explainability and Adversarial Attack

Authors/Creators

  • 1. Student

Description

In recent years, machine learning (ML) models have been extensively used in software analytics, such as code completion, malware detection, code clone detection, code authorship attribution, code search, API recommendation, and code comment generation. However, studies show that state-of-the-art ML models are vulnerable to adversarial attacks when we add minimal perturbations to the original input. As a result, the ML models' robustness against adversarial examples must be assessed before they are deployed in software analytics. ML explainability has recently gained popularity and gives us insight into the reasoning behind the ML models' predictions. This study aims to investigate the relationship between ML explainability and adversarial attacks. Furthermore, we are interested in generating adversarial examples based on the explanation provided by the ML explainability techniques to measure the robustness of the ML models. In this paper, we select four datasets, three ML explainability techniques, and six state-of-the-art ML models to conduct our study. Our large-scale experimental results demonstrate a positive correlation between ML explainability techniques and adversarial attacks. Furthermore, modifying the feature values of the top-$k$ important features identified by ML explainability can generate effective adversarial examples. Thus, the generated adversarial examples could reduce the accuracy of the ML models by up to 75.68\%, indicating the models' low robustness against adversarial attacks.

Files

Adversarial_Attack_ICSME_2023.zip

Files (77.6 MB)

Name Size Download all
md5:9bcf237e14488f640568d033d6a00fb4
77.6 MB Preview Download
md5:44a9829a6c0f4bc6147e06b43b969c16
853 Bytes Preview Download