Adversarial Robustness in Software Analytics: Bridging the Gap between Machine Learning Explainability and Adversarial Attack
Description
In recent years, machine learning (ML) models have been extensively used in software analytics, such as code completion, malware detection, code clone detection, code authorship attribution, code search, API recommendation, and code comment generation. However, studies show that state-of-the-art ML models are vulnerable to adversarial attacks when we add minimal perturbations to the original input. As a result, the ML models' robustness against adversarial examples must be assessed before they are deployed in software analytics. ML explainability has recently gained popularity and gives us insight into the reasoning behind the ML models' predictions. This study aims to investigate the relationship between ML explainability and adversarial attacks. Furthermore, we are interested in generating adversarial examples based on the explanation provided by the ML explainability techniques to measure the robustness of the ML models. In this paper, we select four datasets, three ML explainability techniques, and six state-of-the-art ML models to conduct our study. Our large-scale experimental results demonstrate a positive correlation between ML explainability techniques and adversarial attacks. Furthermore, modifying the feature values of the top-$k$ important features identified by ML explainability can generate effective adversarial examples. Thus, the generated adversarial examples could reduce the accuracy of the ML models by up to 75.68\%, indicating the models' low robustness against adversarial attacks.
Files
Adversarial_Attack_ICSME_2023.zip
Files
(77.6 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:9bcf237e14488f640568d033d6a00fb4
|
77.6 MB | Preview Download |
|
md5:44a9829a6c0f4bc6147e06b43b969c16
|
853 Bytes | Preview Download |