US20210365797A1 - Systems and Methods for Debugging Neural Networks with Coverage Guided Fuzzing - Google Patents
Systems and Methods for Debugging Neural Networks with Coverage Guided Fuzzing Download PDFInfo
- Publication number
- US20210365797A1 US20210365797A1 US17/392,937 US202117392937A US2021365797A1 US 20210365797 A1 US20210365797 A1 US 20210365797A1 US 202117392937 A US202117392937 A US 202117392937A US 2021365797 A1 US2021365797 A1 US 2021365797A1
- Authority
- US
- United States
- Prior art keywords
- inputs
- neural network
- mutated
- coverage
- arrays
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Abandoned
Links
- 238000013528 artificial neural network Methods 0.000 title claims abstract description 135
- 238000000034 method Methods 0.000 title claims abstract description 42
- 238000003491 array Methods 0.000 claims abstract description 44
- 238000012545 processing Methods 0.000 claims abstract description 27
- 230000004913 activation Effects 0.000 claims description 22
- 239000013598 vector Substances 0.000 claims description 19
- 238000012360 testing method Methods 0.000 claims description 14
- 210000002569 neuron Anatomy 0.000 claims description 10
- 230000008569 process Effects 0.000 claims description 10
- 230000006870 function Effects 0.000 description 29
- 230000015654 memory Effects 0.000 description 15
- 238000012549 training Methods 0.000 description 15
- 238000001994 activation Methods 0.000 description 14
- 230000004048 modification Effects 0.000 description 10
- 238000012986 modification Methods 0.000 description 10
- 230000035772 mutation Effects 0.000 description 10
- 239000003471 mutagenic agent Substances 0.000 description 9
- 230000006399 behavior Effects 0.000 description 7
- 238000010586 diagram Methods 0.000 description 6
- 238000010801 machine learning Methods 0.000 description 6
- 230000003287 optical effect Effects 0.000 description 4
- 230000008901 benefit Effects 0.000 description 3
- 238000004891 communication Methods 0.000 description 3
- 230000000306 recurrent effect Effects 0.000 description 3
- 230000004075 alteration Effects 0.000 description 2
- 238000013527 convolutional neural network Methods 0.000 description 2
- 230000003044 adaptive effect Effects 0.000 description 1
- 238000007792 addition Methods 0.000 description 1
- 230000001419 dependent effect Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 230000003993 interaction Effects 0.000 description 1
- 238000003062 neural network model Methods 0.000 description 1
- 230000006403 short-term memory Effects 0.000 description 1
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N3/00—Computing arrangements based on biological models
- G06N3/02—Neural networks
- G06N3/10—Interfaces, programming languages or software development kits, e.g. for simulating neural networks
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N3/00—Computing arrangements based on biological models
- G06N3/02—Neural networks
- G06N3/08—Learning methods
- G06N3/084—Backpropagation, e.g. using gradient descent
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F11/00—Error detection; Error correction; Monitoring
- G06F11/36—Preventing errors by testing or debugging software
- G06F11/362—Software debugging
- G06F11/366—Software debugging using diagnostics
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N3/00—Computing arrangements based on biological models
- G06N3/02—Neural networks
- G06N3/04—Architecture, e.g. interconnection topology
- G06N3/048—Activation functions
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N3/00—Computing arrangements based on biological models
- G06N3/02—Neural networks
- G06N3/08—Learning methods
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06N—COMPUTING ARRANGEMENTS BASED ON SPECIFIC COMPUTATIONAL MODELS
- G06N5/00—Computing arrangements using knowledge-based models
- G06N5/01—Dynamic search techniques; Heuristics; Dynamic trees; Branch-and-bound
Definitions
- the present disclosure relates generally to machine learned models. More particularly, the present disclosure relates to finding undesirable behavior in neural networks.
- machine learning models such as neural networks
- neural networks are becoming more important in solving a variety of tasks that have traditionally been difficult for a computing system.
- machine learning models are generally difficult to interpret and debug.
- machine learning models like neural networks become more prevalent, it becomes more desirable to test neural networks to discover bugs and/or other undesirable behavior before a neural network is implemented in the “real world.”
- One example aspect of the present disclosure is directed to debugging a neural network.
- the method can include obtaining, by one or more computing devices, one or more inputs from an input corpus.
- the method can further include mutating, by the one or more computing devices, the one or more inputs.
- the method can further include providing, by the one or more computing devices, the one or more mutated inputs to a neural network.
- the method can further include obtaining, by the one or more computing devices as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network.
- the method can further include determining, by the one or more computing devices based at least in part on the set of coverage arrays, whether the one or more mutated inputs provide new coverage.
- the method can further include upon determining that the one or more mutated inputs provide new coverage, adding, by the one or more computing devices, the one or more mutated inputs to the input corpus.
- the method can further include obtaining, by the one or more computing devices as a result of the neural network processing the one or more mutated inputs, a set of metadata arrays that describe metadata associated with execution of the neural network to process the one or more mutated inputs; determining, by the one or more computing devices based at least in part on the set of metadata arrays, whether an objective function is satisfied; and upon determining that the objective function is satisfied, adding, by the one or more computing devices, the one or more mutated inputs to a list of test cases.
- the computing device can include one or more processors and one or more non-transitory computer-readable media that store instructions that, when executed by the one or more processors, cause the computing device to perform operations.
- the instructions when executed, can cause the computing device to obtain one or more inputs from an input corpus.
- the instructions when executed, can further cause the computing device to mutate the one or more inputs.
- the instructions when executed, can further cause the computing device to provide the one or more mutated inputs to a neural network.
- the instructions when executed, can further cause the computing device to obtain as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network.
- the instructions when executed, can further cause the computing device to determine based at least in part on the set of coverage arrays, whether the one or more mutated inputs provide new coverage.
- the instructions when executed, can further cause the computing device to, upon determining that the one or more mutated inputs provide new coverage, add the one or more mutated inputs to the input corpus.
- the computing device can further include instructions, that when executed, cause the computing device to obtain as a result of the neural network processing the one or more mutated inputs, a set of metadata arrays that describe metadata associated with execution of the neural network to process the one or more mutated inputs; determine based at least in part on the set of metadata arrays, whether an objective function is satisfied; and upon determining that the objective function is satisfied, add the one or more mutated inputs to a list of test cases.
- Another example aspect of the present disclosure is directed to one or more non-transitory computer-readable media that store instructions that, when executed by one or more processors of a computing system, cause the computing system to perform operations.
- the operations include obtaining one or more inputs from an input corpus.
- the operations further include mutating the one or more inputs.
- the operations further include providing the one or more mutated inputs to a neural network.
- the operations further include obtaining, as a result of the neural network processing the one or more mutated inputs, a set of metadata arrays that describe metadata associated with execution of the neural network to process the one or more mutated inputs.
- the operations further include determining, based at least in part on the set of metadata arrays, whether an objective function is satisfied.
- the operations further include upon determining that the objective function is satisfied, add the one or more mutated inputs to a list of test cases.
- the one or more non-transitory computer-readable media can store instructions that, when executed by one or more processors of a computing system, cause the computing system to obtain, as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network; determine, based at least in part on the set of coverage arrays, whether the one or more mutated inputs provide new coverage; and upon determining that the one or more mutated inputs provide new coverage, add the one or more mutated inputs to the input corpus.
- FIG. 1 depicts a block diagram of an example computing system that can be used with machine learning models according to example embodiments of the present disclosure.
- FIG. 2 depicts a block diagram of an example coverage guided fuzzing system according to example embodiments of the present disclosure.
- FIG. 3 depicts a flow chart diagram of example operations to perform neural network debugging according to example embodiments of the present disclosure.
- the present disclosure is directed to machine-learned models, such as neural networks.
- the systems and methods of the present disclosure can provide for testing neural networks to find bugs and/or other undesirable behavior, for example, before a neural network is deployed.
- coverage guided fuzzing can be applied to neural networks to allow for debugging of the neural networks.
- coverage guided fuzzing can be applied to neural networks to provide for finding numerical errors in trained neural networks, generating disagreements between neural networks and quantized versions of those networks, surfacing undesirable behavior in models (e.g., character level language models, etc.), and/or the like.
- Machine learning models can be difficult to debug or interpret for a variety of reasons, ranging from the conceptual difficulty of specifying what the user wishes to know about the model in formal terms to statistical and computational difficulties in obtaining answers to formally specified questions.
- Neural networks can be particularly difficult to debug because even relatively straightforward formal questions about them can be computationally expensive to answer and because software implementations of neural networks can deviate significantly from theoretical models.
- coverage guided fuzzing provides for maintaining an input corpus comprising inputs to a program under consideration. Random changes are made to those inputs according to some mutation procedure, and the mutated inputs are added to an input corpus when they exercise new coverage (e.g., causing code to execute in a different way than previously seen, etc.).
- the systems and methods of the present disclosure provide for inputting random mutations of inputs to a neural network where the mutations are guided by a coverage metric toward the goal of satisfying user-specified constraints.
- coverage can be measured by analyzing the activation vectors of the neural network coverage graph. For example, in some implementations, new coverage can be determined based on whether the neural network has resulted in a state that the neural network has not reached previously, such that the new coverage helps to provide incremental progress in debugging.
- fast approximate nearest neighbor algorithms can be used to determine if two sets of neural network ‘activations’ are meaningfully different from each other. This provides a coverage metric producing useful results for neural networks, even when the underlying implementation of the neural network does not make use of many data-dependent branches.
- the activations (or some subset of them) associated with each input can be stored and checked to determine whether coverage has increased on a given input by using an approximate nearest neighbors algorithm to see whether there are any other sets of activations within a pre-specified distance.
- coverage guided fuzzing of a neural network can start with a seed corpus containing at least one set of inputs for the computation graph.
- the inputs can be restricted to those inputs that are in some sense valid neural network inputs. For example, if the inputs are images, the inputs can be restricted to those inputs that have the correct size and shape, and that lie in the same interval as the input pixels of the dataset under consideration. As another example, if the inputs are sequences of characters, inputs can be restricted to characters that are in the vocabulary extracted from the training set.
- the neural network debugging system can choose elements from the input corpus according to some heuristic (e.g., uniform random selection, some defined probability heuristic, etc.). Given this input, the neural network debugging system can perform some sort of modification to that input. For example, the modification can be as simple as just flipping the sign of an input pixel in an image. Additionally or alternatively, it can also be restricted to follow some kind of constraint on the total modification made to a corpus element over time. The mutated inputs can then be fed to the neural network.
- some heuristic e.g., uniform random selection, some defined probability heuristic, etc.
- two things can be extracted from the neural network: a set of coverage arrays, from which the actual coverage can be computed, and a set of metadata arrays, from which the result of the objective function can be computed.
- the coverage arrays can describe which neurons of the neural network were activated during processing of the input, and therefore may be referred to as or used to generate an “activation vector.”
- the metadata array can describe a behavior, output, result, prediction, outcome, timings, statistics, run times, memory consumption, processor usage, and/or other metadata associated with execution of the neural network to process the input.
- an objective function can be used to assess whether some particular state (e.g., an erroneous state, etc.) has been reached.
- the objective function can be applied to the metadata arrays and inputs that caused the objective to be satisfied can be flagged.
- the neural network debugging system can determine whether the coverage provided by the mutated input is new coverage (e.g., whether the neural network has reached a state that it has not reached previously, etc.) based on the coverage arrays. For example, in some implementations, when a new activation vector is received, its nearest neighbor can be determined (e.g., through performance of an approximate nearest neighbors algorithm) and checked for how far away the nearest neighbor is (e.g., in Euclidean distance). The input can be added to the corpus if the distance is greater than some defined amount.
- the input mutations can be performed as a batch and the batch of inputs can be fed to the computation graph.
- the coverage and objective function can then be checked on a batch of output arrays.
- FIG. 1 depicts a block diagram of an example computing system 100 that provides for the use of machine learning according to example embodiments of the present disclosure.
- the system 100 includes a user computing device 102 , a server computing system 130 , and a training computing system 150 that are communicatively coupled over a network 180 .
- the user computing device 102 can be any type of computing device, such as, for example, a personal computing device (e.g., laptop or desktop), a mobile computing device (e.g., smartphone or tablet), a gaming console or controller, a wearable computing device, an embedded computing device, or any other type of computing device.
- a personal computing device e.g., laptop or desktop
- a mobile computing device e.g., smartphone or tablet
- a gaming console or controller e.g., a gaming console or controller
- a wearable computing device e.g., an embedded computing device, or any other type of computing device.
- the user computing device 102 includes one or more processors 112 and a memory 114 .
- the one or more processors 112 can be any suitable processing device (e.g., a processor core, a microprocessor, an ASIC, a FPGA, a controller, a microcontroller, etc.) and can be one processor or a plurality of processors that are operatively connected.
- the memory 114 can include one or more non-transitory computer-readable storage mediums, such as RAM, ROM, EEPROM, EPROM, flash memory devices, magnetic disks, etc., and combinations thereof.
- the memory 114 can store data 116 and instructions 118 which are executed by the processor 112 to cause the user computing device 102 to perform operations.
- the user computing device 102 can store or include one or more machine-learned models 120 .
- the machine-learned models 120 can be or can otherwise include various machine-learned models such as neural networks (e.g., deep neural networks) or other types of machine-learned models, including non-linear models and/or linear models.
- Neural networks can include feed-forward neural networks, recurrent neural networks (e.g., long short-term memory recurrent neural networks), convolutional neural networks or other forms of neural networks.
- the one or more machine-learned models 120 can be received from the server computing system 130 over network 180 , stored in the user computing device memory 114 , and then used or otherwise implemented by the one or more processors 112 .
- the user computing device 102 can implement multiple parallel instances of a single machine-learned model 120 .
- one or more machine-learned models 140 can be included in or otherwise stored and implemented by the server computing system 130 that communicates with the user computing device 102 according to a client-server relationship.
- the machine-learned models 140 can be implemented by the server computing system 140 as a portion of a cloud based service.
- one or more models 120 can be stored and implemented at the user computing device 102 and/or one or more models 140 can be stored and implemented at the server computing system 130 .
- the user computing device 102 can also include one or more user input component 122 that receives user input.
- the user input component 122 can be a touch-sensitive component (e.g., a touch-sensitive display screen or a touch pad) that is sensitive to the touch of a user input object (e.g., a finger or a stylus).
- the touch-sensitive component can serve to implement a virtual keyboard.
- Other example user input components include a microphone, a traditional keyboard, or other means by which a user can provide user input.
- the server computing system 130 includes one or more processors 132 and a memory 134 .
- the one or more processors 132 can be any suitable processing device (e.g., a processor core, a microprocessor, an ASIC, a FPGA, a controller, a microcontroller, etc.) and can be one processor or a plurality of processors that are operatively connected.
- the memory 134 can include one or more non-transitory computer-readable storage mediums, such as RAM, ROM, EEPROM, EPROM, flash memory devices, magnetic disks, etc., and combinations thereof.
- the memory 134 can store data 136 and instructions 138 which are executed by the processor 132 to cause the server computing system 130 to perform operations.
- the server computing system 130 includes or is otherwise implemented by one or more server computing devices. In instances in which the server computing system 130 includes plural server computing devices, such server computing devices can operate according to sequential computing architectures, parallel computing architectures, or some combination thereof.
- the server computing system 130 can store or otherwise include one or more machine-learned models 140 .
- the models 140 can be or can otherwise include various machine-learned models.
- Example machine-learned models include neural networks or other multi-layer non-linear models.
- Example neural networks include feed forward neural networks, deep neural networks, recurrent neural networks, and convolutional neural networks.
- the server computing system 130 can further include a neural network debugging system 142 , such as described herein with regard to FIG. 2 .
- the neural network debugging system 142 can provide for performing coverage guided fuzzing using a corpus of inputs, for instance, to provide for testing neural networks, such as to discover errors which may occur for rare inputs.
- the user computing device 102 and/or the server computing system 130 can train the models 120 and/or 140 via interaction with the training computing system 150 that is communicatively coupled over the network 180 .
- the training computing system 150 can be separate from the server computing system 130 or can be a portion of the server computing system 130 .
- the training computing system 150 includes one or more processors 152 and a memory 154 .
- the one or more processors 152 can be any suitable processing device (e.g., a processor core, a microprocessor, an ASIC, a FPGA, a controller, a microcontroller, etc.) and can be one processor or a plurality of processors that are operatively connected.
- the memory 154 can include one or more non-transitory computer-readable storage mediums, such as RAM, ROM, EEPROM, EPROM, flash memory devices, magnetic disks, etc., and combinations thereof.
- the memory 154 can store data 156 and instructions 158 which are executed by the processor 152 to cause the training computing system 150 to perform operations.
- the training computing system 150 includes or is otherwise implemented by one or more server computing devices.
- the training computing system 150 can include a model trainer 160 that trains the machine-learned models 120 and/or 140 stored at the user computing device 102 and/or the server computing system 130 using various training or learning techniques, such as, for example, backwards propagation of errors.
- performing backwards propagation of errors can include performing truncated backpropagation through time.
- the model trainer 160 can perform a number of generalization techniques (e.g., weight decays, dropouts, etc.) to improve the generalization capability of the models being trained.
- the model trainer 160 can train the machine-learned models 120 and/or 140 based on a set of training data 162 .
- the training examples can be provided by the user computing device 102 .
- the model 120 provided to the user computing device 102 can be trained by the training computing system 150 on user-specific data received from the user computing device 102 . In some instances, this process can be referred to as personalizing the model.
- the model trainer 160 includes computer logic utilized to provide desired functionality.
- the model trainer 160 can be implemented in hardware, firmware, and/or software controlling a general purpose processor.
- the model trainer 160 includes program files stored on a storage device, loaded into a memory and executed by one or more processors.
- the model trainer 160 includes one or more sets of computer-executable instructions that are stored in a tangible computer-readable storage medium such as RAM hard disk or optical or magnetic media.
- the network 180 can be any type of communications network, such as a local area network (e.g., intranet), wide area network (e.g., Internet), or some combination thereof and can include any number of wired or wireless links.
- communication over the network 180 can be carried via any type of wired and/or wireless connection, using a wide variety of communication protocols (e.g., TCP/IP, HTTP, SMTP, FTP), encodings or formats (e.g., HTML, XML), and/or protection schemes (e.g., VPN, secure HTTP, SSL).
- FIG. 1 illustrates one example computing system that can be used to implement the present disclosure.
- the user computing device 102 can include the model trainer 160 and the training dataset 162 .
- the models 120 can be both trained and used locally at the user computing device 102 .
- the user computing device 102 can implement the model trainer 160 to personalize the models 120 based on user-specific data.
- FIG. 2 depicts a block diagram of an example neural network debugging system 200 using coverage guided fuzzing according to example embodiments of the present disclosure.
- the neural network debugging system 200 can provide for performing coverage guided fuzzing using a corpus of inputs, for example, to provide for testing neural networks, such as to discover errors which may occur for rare inputs.
- the neural network debugging system 200 can allow for guiding mutations to corpus inputs by a coverage metric to work toward a goal of satisfying user-specified constraints (e.g., random changes are made to inputs according to some mutation procedure and the mutated inputs are added to an input corpus when they exercise new coverage).
- coverage can be measured by analyzing the activation vectors of the neural network coverage graph.
- new coverage can be determined based on whether the neural network has resulted in a state that the neural network has not reached previously, such that the new coverage helps to provide incremental progress in debugging of the neural network model.
- coverage guided fuzzing can be applied to neural networks to provide for finding numerical errors in trained neural networks, generating disagreements between neural networks and quantized versions of those networks, surfacing undesirable behavior in models, and/or the like.
- a neural network debugging system 200 can include a coverage guided fuzzer 202 and a seed corpus 220 (e.g., containing at least one set of inputs for the computation graph) which can provide for an initial set of inputs to a coverage guided fuzzer 202 to test a neural network.
- a coverage guided fuzzer 202 e.g., containing at least one set of inputs for the computation graph
- seed corpus 220 e.g., containing at least one set of inputs for the computation graph
- the coverage guided fuzzer 202 can obtain (e.g., select) a set of inputs from the seed corpus 220 to provide an input corpus 204 , which may comprise all or some subset of inputs included in the seed corpus 220 .
- the inputs can be restricted to some type of valid neural network inputs (e.g., images having a correct size and shape, characters that are in a vocabulary extracted from a training set, etc.).
- the seed corpus 220 can be supplied by a user and/or can be selected from a set of available seed corpuses.
- the inputs can be textual inputs, image inputs, audio data inputs, sensor data inputs, and/or various other types of inputs.
- the coverage guided fuzzer 202 can include an input chooser 206 that can select input(s) from the input corpus 204 to use during a particular iteration of the coverage guided fuzzing.
- the input chooser 206 can select inputs using uniform random selection.
- the input chooser 206 can be biased towards selecting inputs that were more recently added to the input corpus 204 .
- the input chooser 206 can select inputs using a heuristic such as
- the input chooser 206 can provide the selected input(s) to a mutator 208 .
- the mutator 208 can apply modifications (e.g., mutations) to the selected input(s) before the inputs are provided to the neural network.
- the mutator 208 can add white noise of a user-configurable variance to input(s) (e.g., image inputs, etc.).
- the mutator 208 can add white noise of a user-configurable variance to the one or more inputs (e.g., image inputs, etc.), wherein a difference between the mutated input and an original input from which the mutated input is descended is constrained to have a user-configurable L ⁇ norm.
- This type of constrained mutation can be useful to find inputs that satisfy some objective function, but are still plausibly of the same “class” as the original input that was used as a seed.
- the image can be clipped after mutation so that it lies in the same range as the inputs used to train the neural network being debugged.
- one of a set of operations can be uniformly performed at random, including operations such as deleting a character at a random location, adding a character at a random location, substituting a random character at a random location, and/or the like.
- the input chooser 206 includes computer logic utilized to provide desired functionality.
- the input chooser 206 can be implemented in hardware, firmware, and/or software controlling a general purpose processor.
- the input chooser 206 includes program files stored on a storage device, loaded into a memory and executed by one or more processors.
- the input chooser 206 includes one or more sets of computer-executable instructions that are stored in a tangible computer-readable storage medium such as RAM hard disk or optical or magnetic media.
- the mutator 208 can then provide the mutated input(s) to the neural network 210 .
- the neural network 210 can provide outputs which can include a set of coverage arrays, for which coverage can be computed, and a set of metadata arrays, from which a result of an objective function can be computed. For example, when the mutated inputs are fed into a computation graph, both coverage arrays and metadata arrays are returned as output.
- the mutator 208 includes computer logic utilized to provide desired functionality.
- the mutator 208 can be implemented in hardware, firmware, and/or software controlling a general purpose processor.
- the mutator 208 includes program files stored on a storage device, loaded into a memory and executed by one or more processors.
- the mutator 208 includes one or more sets of computer-executable instructions that are stored in a tangible computer-readable storage medium such as RAM hard disk or optical or magnetic media.
- the objective function 212 can assess whether the neural network has reached some particular state, for example, a state which may be regarded as erroneous, based on the metadata array(s).
- An erroneous state may include an incorrect prediction, an execution time greater than a maximum execution time, a processor usage greater than a maximum processor usage, a failure of the neural network to execute, and/or other the existence of other errors or undesirable behavior or performance.
- the objective function 212 can be specified by a user and/or selected from a set of available objective functions. Generally, the objective function 212 used to assess whether the neural network has reached some particular state can be separate and distinct from some other objective or loss function used to train the neural network.
- the mutated input(s) provided to the neural network can be flagged, such as being added to a list of test cases (e.g., for future debugging, etc.).
- the objective function can be applied to the metadata arrays and any mutated inputs that caused the objective function to be satisfied can be flagged.
- the coverage analyzer 214 can determine whether the coverage provided by the mutated input(s) is new coverage (e.g., whether the neural network has reached a state that it has not reached previously, etc.) based on the coverage array(s). For example, in some implementations, coverage analyzer 214 can determine whether new coverage is provided based on whether an activation vector is approximately close to a previous activation vector. If the coverage analyzer 214 determines that the mutated input(s) provide new coverage, the mutated input(s) can be added to the input corpus 204 , for example, to be used as input(s) in future iterations of debugging and/or the like.
- an approximate nearest neighbor can be computed for a new activation vector and checked to determine how far away the nearest neighbor is in Euclidean distance from the activation vector.
- the input can be added to the corpus if the distance is greater than some defined amount (e.g., which can be a user-configurable hyperparameter, an adaptive hyperparameter to adapts over time, and/or a dynamic hyperparameter that changes over time, for example, according to a predetermined schedule).
- some defined amount e.g., which can be a user-configurable hyperparameter, an adaptive hyperparameter to adapts over time, and/or a dynamic hyperparameter that changes over time, for example, according to a predetermined schedule.
- the coverage guided fuzzer 202 can continue to select, mutate, and analyze inputs included in the input corpus 204 until instructed to stop and/or some other stopping criterion in met.
- the coverage analyzer 214 includes computer logic utilized to provide desired functionality.
- the coverage analyzer 214 can be implemented in hardware, firmware, and/or software controlling a general purpose processor.
- the coverage analyzer 214 includes program files stored on a storage device, loaded into a memory and executed by one or more processors.
- the coverage analyzer 214 includes one or more sets of computer-executable instructions that are stored in a tangible computer-readable storage medium such as RAM hard disk or optical or magnetic media.
- the coverage arrays and/or associated activation vectors may describe whether some or all of the neurons of the neural network were activated during processing of an input.
- a coverage array and/or associated activation vector may be limited to describing only whether the logits of the neural network and/or neurons of a layer of the network prior to the logits were activated.
- the system 200 can be applied (e.g., in parallel) to two or more different (but potentially related) models to identify disagreements between the models.
- the two or more different models can be two or more different versions of a base model such as a base model and a quantized version of the base model.
- the same input e.g., a mutated input
- the two or more different outputs of the two or more different models can be analyzed (e.g., according to the objective function 212 and/or the coverage analyzer 214 ) to detect disagreements or otherwise measure a divergence in the outputs.
- FIG. 3 depicts a flow chart diagram of example operations to perform neural network debugging according to example embodiments of the present disclosure.
- FIG. 3 depicts steps performed in a particular order for purposes of illustration and discussion, the methods of the present disclosure are not limited to the particularly illustrated order or arrangement. The various steps of the method 300 can be omitted, rearranged, combined, and/or adapted in various ways without deviating from the scope of the present disclosure.
- a computing system can obtain an input corpus, for example from a seed corpus comprising one or more sets of inputs.
- a seed corpus can contain at least one set of inputs for the computation graph.
- the inputs can be restricted to those inputs that are in some sense valid neural network inputs. For example, if the inputs are images, the inputs can be restricted to those inputs that have the correct size and shape, and that lie in the same interval as the input pixels of the dataset under consideration. As another example, if the inputs are sequences of characters, inputs can be restricted to characters that are in the vocabulary extracted from the training set.
- the computing system can select one or more inputs from the input corpus for use in debugging a neural network. For example, the computing system can select one or more inputs from the input corpus based on uniform random selection, based on one or more heuristics (e.g.,
- the computing system can modify the selected input(s) prior to input to the neural network by performing some type of mutation on the selected input(s). For example, in some implementations, the computing system can perform a simple modification of the input such as flipping a sign of an input. As another example, in some implementations, computing system can restrict the modifications to follow a constraint on the total modification made to a corpus element over time.
- the computing system feed the modified input(s) to the neural network that is to be debugged.
- the computing system can obtain, as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays (e.g., that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network) which can be used to compute the actual coverage exercised by the modified input(s).
- a set of coverage arrays e.g., that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network
- the computing system can determine whether the mutated input(s) provide new coverage at least in part on the coverage array(s). For example, the computing system can determine that new coverage is provided is the neural network results in a state that it has not been in before. If the mutated input(s) provide new coverage, operation continues to 314 . If the mutated input(s) do not provide new coverage, operations continue to 322 , where a next input can be analyzed. For example, in some implementations, when a new activation vector is received, its nearest neighbor can be determined and checked for how far away the nearest neighbor is in Euclidean distance. The input can be added to the corpus if the distance is greater than some defined amount.
- the computing system can add the mutated input(s) to the input corpus.
- the computing system as a result of the neural network processing the one or more mutated inputs, a set of metadata arrays (e.g., that describe metadata associated with execution of the neural network to process the one or more mutated inputs) for use in computing the objective function.
- a set of metadata arrays e.g., that describe metadata associated with execution of the neural network to process the one or more mutated inputs
- the computing system can determine whether the objective function is satisfied based at least in part on the metadata array(s). For example, the objective function can assess whether the neural network has reached a particular state, such as state that is regarded as erroneous. For example, the objective function can be applied to the metadata arrays and inputs that cause the objective to be satisfied can be flagged. If the objective function is satisfied, operation continues to 320 . If the objective function is not satisfied, operation continues to 322 .
- the computing system can add the mutated input to a list of test cases.
- the technology discussed herein makes reference to servers, databases, software applications, and other computer-based systems, as well as actions taken and information sent to and from such systems.
- the inherent flexibility of computer-based systems allows for a great variety of possible configurations, combinations, and divisions of tasks and functionality between and among components.
- processes discussed herein can be implemented using a single device or component or multiple devices or components working in combination.
- Databases and applications can be implemented on a single system or distributed across multiple systems. Distributed components can operate sequentially or in parallel.
Abstract
The present disclosure provides systems and methods for debugging neural networks. In one example, a computer-implemented method is provided, which includes obtaining, by one or more computing devices, one or more inputs from an input corpus. The method further includes mutating, by the one or more computing devices, the one or more inputs and providing the one or more mutated inputs to a neural network; obtaining, by the one or more computing devices as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays; determining, by the one or more computing devices based at least in part on the set of coverage arrays, whether the one or more mutated inputs provide new coverage; and upon determining that the one or more mutated inputs provide new coverage, adding the one or more mutated inputs to the input corpus.
Description
- The present application is based on and claims the benefit of U.S. Provisional Application No. 62/673,751 having a filing date of May 18, 2018, which is incorporated by reference herein in its entirety for all purposes.
- The present disclosure relates generally to machine learned models. More particularly, the present disclosure relates to finding undesirable behavior in neural networks.
- The use of machine learning models, such as neural networks, is becoming more important in solving a variety of tasks that have traditionally been difficult for a computing system. However, machine learning models are generally difficult to interpret and debug. As machine learning models like neural networks become more prevalent, it becomes more desirable to test neural networks to discover bugs and/or other undesirable behavior before a neural network is implemented in the “real world.”
- Aspects and advantages of embodiments of the present disclosure will be set forth in part in the following description, or can be learned from the description, or can be learned through practice of the embodiments.
- One example aspect of the present disclosure is directed to debugging a neural network. The method can include obtaining, by one or more computing devices, one or more inputs from an input corpus. The method can further include mutating, by the one or more computing devices, the one or more inputs. The method can further include providing, by the one or more computing devices, the one or more mutated inputs to a neural network. The method can further include obtaining, by the one or more computing devices as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network. The method can further include determining, by the one or more computing devices based at least in part on the set of coverage arrays, whether the one or more mutated inputs provide new coverage. The method can further include upon determining that the one or more mutated inputs provide new coverage, adding, by the one or more computing devices, the one or more mutated inputs to the input corpus.
- In some implementations, the method can further include obtaining, by the one or more computing devices as a result of the neural network processing the one or more mutated inputs, a set of metadata arrays that describe metadata associated with execution of the neural network to process the one or more mutated inputs; determining, by the one or more computing devices based at least in part on the set of metadata arrays, whether an objective function is satisfied; and upon determining that the objective function is satisfied, adding, by the one or more computing devices, the one or more mutated inputs to a list of test cases.
- Another example aspect of the present disclosure is directed to a computing device. The computing device can include one or more processors and one or more non-transitory computer-readable media that store instructions that, when executed by the one or more processors, cause the computing device to perform operations. The instructions, when executed, can cause the computing device to obtain one or more inputs from an input corpus. The instructions, when executed, can further cause the computing device to mutate the one or more inputs. The instructions, when executed, can further cause the computing device to provide the one or more mutated inputs to a neural network. The instructions, when executed, can further cause the computing device to obtain as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network. The instructions, when executed, can further cause the computing device to determine based at least in part on the set of coverage arrays, whether the one or more mutated inputs provide new coverage. The instructions, when executed, can further cause the computing device to, upon determining that the one or more mutated inputs provide new coverage, add the one or more mutated inputs to the input corpus.
- In some implementations, the computing device can further include instructions, that when executed, cause the computing device to obtain as a result of the neural network processing the one or more mutated inputs, a set of metadata arrays that describe metadata associated with execution of the neural network to process the one or more mutated inputs; determine based at least in part on the set of metadata arrays, whether an objective function is satisfied; and upon determining that the objective function is satisfied, add the one or more mutated inputs to a list of test cases.
- Another example aspect of the present disclosure is directed to one or more non-transitory computer-readable media that store instructions that, when executed by one or more processors of a computing system, cause the computing system to perform operations. The operations include obtaining one or more inputs from an input corpus. The operations further include mutating the one or more inputs. The operations further include providing the one or more mutated inputs to a neural network. The operations further include obtaining, as a result of the neural network processing the one or more mutated inputs, a set of metadata arrays that describe metadata associated with execution of the neural network to process the one or more mutated inputs. The operations further include determining, based at least in part on the set of metadata arrays, whether an objective function is satisfied. The operations further include upon determining that the objective function is satisfied, add the one or more mutated inputs to a list of test cases.
- In some implementations, the one or more non-transitory computer-readable media can store instructions that, when executed by one or more processors of a computing system, cause the computing system to obtain, as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network; determine, based at least in part on the set of coverage arrays, whether the one or more mutated inputs provide new coverage; and upon determining that the one or more mutated inputs provide new coverage, add the one or more mutated inputs to the input corpus.
- Detailed discussion of embodiments directed to one of ordinary skill in the art is set forth in the specification, which makes reference to the appended figures, in which:
-
FIG. 1 depicts a block diagram of an example computing system that can be used with machine learning models according to example embodiments of the present disclosure. -
FIG. 2 depicts a block diagram of an example coverage guided fuzzing system according to example embodiments of the present disclosure. -
FIG. 3 depicts a flow chart diagram of example operations to perform neural network debugging according to example embodiments of the present disclosure. - Reference numerals that are repeated across plural figures are intended to identify the same features in various implementations.
- Overview
- Generally, the present disclosure is directed to machine-learned models, such as neural networks. In particular, the systems and methods of the present disclosure can provide for testing neural networks to find bugs and/or other undesirable behavior, for example, before a neural network is deployed. According to an aspect of the present disclosure, coverage guided fuzzing can be applied to neural networks to allow for debugging of the neural networks. For example, in some implementations, coverage guided fuzzing can be applied to neural networks to provide for finding numerical errors in trained neural networks, generating disagreements between neural networks and quantized versions of those networks, surfacing undesirable behavior in models (e.g., character level language models, etc.), and/or the like.
- Machine learning models can be difficult to debug or interpret for a variety of reasons, ranging from the conceptual difficulty of specifying what the user wishes to know about the model in formal terms to statistical and computational difficulties in obtaining answers to formally specified questions. Neural networks can be particularly difficult to debug because even relatively straightforward formal questions about them can be computationally expensive to answer and because software implementations of neural networks can deviate significantly from theoretical models.
- In general, coverage guided fuzzing provides for maintaining an input corpus comprising inputs to a program under consideration. Random changes are made to those inputs according to some mutation procedure, and the mutated inputs are added to an input corpus when they exercise new coverage (e.g., causing code to execute in a different way than previously seen, etc.).
- The systems and methods of the present disclosure provide for inputting random mutations of inputs to a neural network where the mutations are guided by a coverage metric toward the goal of satisfying user-specified constraints. According to an aspect of the present disclosure, coverage can be measured by analyzing the activation vectors of the neural network coverage graph. For example, in some implementations, new coverage can be determined based on whether the neural network has resulted in a state that the neural network has not reached previously, such that the new coverage helps to provide incremental progress in debugging.
- As one example, fast approximate nearest neighbor algorithms can be used to determine if two sets of neural network ‘activations’ are meaningfully different from each other. This provides a coverage metric producing useful results for neural networks, even when the underlying implementation of the neural network does not make use of many data-dependent branches. For example, in some implementations, the activations (or some subset of them) associated with each input can be stored and checked to determine whether coverage has increased on a given input by using an approximate nearest neighbors algorithm to see whether there are any other sets of activations within a pre-specified distance.
- According to an aspect of the present disclosure, in some implementations, coverage guided fuzzing of a neural network can start with a seed corpus containing at least one set of inputs for the computation graph. The inputs can be restricted to those inputs that are in some sense valid neural network inputs. For example, if the inputs are images, the inputs can be restricted to those inputs that have the correct size and shape, and that lie in the same interval as the input pixels of the dataset under consideration. As another example, if the inputs are sequences of characters, inputs can be restricted to characters that are in the vocabulary extracted from the training set.
- Given this seed corpus, until instructed to stop or some other stopping criterion in met, the neural network debugging system can choose elements from the input corpus according to some heuristic (e.g., uniform random selection, some defined probability heuristic, etc.). Given this input, the neural network debugging system can perform some sort of modification to that input. For example, the modification can be as simple as just flipping the sign of an input pixel in an image. Additionally or alternatively, it can also be restricted to follow some kind of constraint on the total modification made to a corpus element over time. The mutated inputs can then be fed to the neural network. In some implementations, two things can be extracted from the neural network: a set of coverage arrays, from which the actual coverage can be computed, and a set of metadata arrays, from which the result of the objective function can be computed. For example, the coverage arrays can describe which neurons of the neural network were activated during processing of the input, and therefore may be referred to as or used to generate an “activation vector.” As another example, the metadata array can describe a behavior, output, result, prediction, outcome, timings, statistics, run times, memory consumption, processor usage, and/or other metadata associated with execution of the neural network to process the input. Once the coverage and/or objective is computed, the mutated input can be added to the corpus if it exercises new coverage, and/or it can be added to a list of test cases if it causes the objective function the be satisfied.
- For example, an objective function can be used to assess whether some particular state (e.g., an erroneous state, etc.) has been reached. The objective function can be applied to the metadata arrays and inputs that caused the objective to be satisfied can be flagged. The neural network debugging system can determine whether the coverage provided by the mutated input is new coverage (e.g., whether the neural network has reached a state that it has not reached previously, etc.) based on the coverage arrays. For example, in some implementations, when a new activation vector is received, its nearest neighbor can be determined (e.g., through performance of an approximate nearest neighbors algorithm) and checked for how far away the nearest neighbor is (e.g., in Euclidean distance). The input can be added to the corpus if the distance is greater than some defined amount.
- In some implementations, the input mutations can be performed as a batch and the batch of inputs can be fed to the computation graph. The coverage and objective function can then be checked on a batch of output arrays.
- Reference now will be made in detail to embodiments, one or more examples of which are illustrated in the drawings. Each example is provided by way of explanation of the embodiments, not limitation of the present disclosure. In fact, it will be apparent to those skilled in the art that various modifications and variations can be made to the embodiments without departing from the scope or spirit of the present disclosure. For instance, features illustrated or described as part of one embodiment can be used with another embodiment to yield a still further embodiment. Thus, it is intended that aspects of the present disclosure cover such modifications and variations.
-
FIG. 1 depicts a block diagram of anexample computing system 100 that provides for the use of machine learning according to example embodiments of the present disclosure. Thesystem 100 includes auser computing device 102, aserver computing system 130, and atraining computing system 150 that are communicatively coupled over anetwork 180. - The
user computing device 102 can be any type of computing device, such as, for example, a personal computing device (e.g., laptop or desktop), a mobile computing device (e.g., smartphone or tablet), a gaming console or controller, a wearable computing device, an embedded computing device, or any other type of computing device. - The
user computing device 102 includes one ormore processors 112 and amemory 114. The one ormore processors 112 can be any suitable processing device (e.g., a processor core, a microprocessor, an ASIC, a FPGA, a controller, a microcontroller, etc.) and can be one processor or a plurality of processors that are operatively connected. Thememory 114 can include one or more non-transitory computer-readable storage mediums, such as RAM, ROM, EEPROM, EPROM, flash memory devices, magnetic disks, etc., and combinations thereof. Thememory 114 can storedata 116 andinstructions 118 which are executed by theprocessor 112 to cause theuser computing device 102 to perform operations. - In some implementations, the
user computing device 102 can store or include one or more machine-learnedmodels 120. For example, the machine-learnedmodels 120 can be or can otherwise include various machine-learned models such as neural networks (e.g., deep neural networks) or other types of machine-learned models, including non-linear models and/or linear models. Neural networks can include feed-forward neural networks, recurrent neural networks (e.g., long short-term memory recurrent neural networks), convolutional neural networks or other forms of neural networks. - In some implementations, the one or more machine-learned
models 120 can be received from theserver computing system 130 overnetwork 180, stored in the usercomputing device memory 114, and then used or otherwise implemented by the one ormore processors 112. In some implementations, theuser computing device 102 can implement multiple parallel instances of a single machine-learnedmodel 120. - Additionally or alternatively, one or more machine-learned
models 140 can be included in or otherwise stored and implemented by theserver computing system 130 that communicates with theuser computing device 102 according to a client-server relationship. For example, the machine-learnedmodels 140 can be implemented by theserver computing system 140 as a portion of a cloud based service. Thus, one ormore models 120 can be stored and implemented at theuser computing device 102 and/or one ormore models 140 can be stored and implemented at theserver computing system 130. - The
user computing device 102 can also include one or moreuser input component 122 that receives user input. For example, theuser input component 122 can be a touch-sensitive component (e.g., a touch-sensitive display screen or a touch pad) that is sensitive to the touch of a user input object (e.g., a finger or a stylus). The touch-sensitive component can serve to implement a virtual keyboard. Other example user input components include a microphone, a traditional keyboard, or other means by which a user can provide user input. - The
server computing system 130 includes one ormore processors 132 and amemory 134. The one ormore processors 132 can be any suitable processing device (e.g., a processor core, a microprocessor, an ASIC, a FPGA, a controller, a microcontroller, etc.) and can be one processor or a plurality of processors that are operatively connected. Thememory 134 can include one or more non-transitory computer-readable storage mediums, such as RAM, ROM, EEPROM, EPROM, flash memory devices, magnetic disks, etc., and combinations thereof. Thememory 134 can storedata 136 andinstructions 138 which are executed by theprocessor 132 to cause theserver computing system 130 to perform operations. - In some implementations, the
server computing system 130 includes or is otherwise implemented by one or more server computing devices. In instances in which theserver computing system 130 includes plural server computing devices, such server computing devices can operate according to sequential computing architectures, parallel computing architectures, or some combination thereof. - As described above, the
server computing system 130 can store or otherwise include one or more machine-learnedmodels 140. For example, themodels 140 can be or can otherwise include various machine-learned models. Example machine-learned models include neural networks or other multi-layer non-linear models. Example neural networks include feed forward neural networks, deep neural networks, recurrent neural networks, and convolutional neural networks. - In some implementations, the
server computing system 130 can further include a neuralnetwork debugging system 142, such as described herein with regard toFIG. 2 . For example, the neuralnetwork debugging system 142 can provide for performing coverage guided fuzzing using a corpus of inputs, for instance, to provide for testing neural networks, such as to discover errors which may occur for rare inputs. - The
user computing device 102 and/or theserver computing system 130 can train themodels 120 and/or 140 via interaction with thetraining computing system 150 that is communicatively coupled over thenetwork 180. Thetraining computing system 150 can be separate from theserver computing system 130 or can be a portion of theserver computing system 130. - The
training computing system 150 includes one ormore processors 152 and amemory 154. The one ormore processors 152 can be any suitable processing device (e.g., a processor core, a microprocessor, an ASIC, a FPGA, a controller, a microcontroller, etc.) and can be one processor or a plurality of processors that are operatively connected. Thememory 154 can include one or more non-transitory computer-readable storage mediums, such as RAM, ROM, EEPROM, EPROM, flash memory devices, magnetic disks, etc., and combinations thereof. Thememory 154 can storedata 156 andinstructions 158 which are executed by theprocessor 152 to cause thetraining computing system 150 to perform operations. In some implementations, thetraining computing system 150 includes or is otherwise implemented by one or more server computing devices. - The
training computing system 150 can include amodel trainer 160 that trains the machine-learnedmodels 120 and/or 140 stored at theuser computing device 102 and/or theserver computing system 130 using various training or learning techniques, such as, for example, backwards propagation of errors. In some implementations, performing backwards propagation of errors can include performing truncated backpropagation through time. Themodel trainer 160 can perform a number of generalization techniques (e.g., weight decays, dropouts, etc.) to improve the generalization capability of the models being trained. In particular, themodel trainer 160 can train the machine-learnedmodels 120 and/or 140 based on a set oftraining data 162. - In some implementations, if the user has provided consent, the training examples can be provided by the
user computing device 102. Thus, in such implementations, themodel 120 provided to theuser computing device 102 can be trained by thetraining computing system 150 on user-specific data received from theuser computing device 102. In some instances, this process can be referred to as personalizing the model. - The
model trainer 160 includes computer logic utilized to provide desired functionality. Themodel trainer 160 can be implemented in hardware, firmware, and/or software controlling a general purpose processor. For example, in some implementations, themodel trainer 160 includes program files stored on a storage device, loaded into a memory and executed by one or more processors. In other implementations, themodel trainer 160 includes one or more sets of computer-executable instructions that are stored in a tangible computer-readable storage medium such as RAM hard disk or optical or magnetic media. - The
network 180 can be any type of communications network, such as a local area network (e.g., intranet), wide area network (e.g., Internet), or some combination thereof and can include any number of wired or wireless links. In general, communication over thenetwork 180 can be carried via any type of wired and/or wireless connection, using a wide variety of communication protocols (e.g., TCP/IP, HTTP, SMTP, FTP), encodings or formats (e.g., HTML, XML), and/or protection schemes (e.g., VPN, secure HTTP, SSL). -
FIG. 1 illustrates one example computing system that can be used to implement the present disclosure. Other computing systems can be used as well. For example, in some implementations, theuser computing device 102 can include themodel trainer 160 and thetraining dataset 162. In such implementations, themodels 120 can be both trained and used locally at theuser computing device 102. In some of such implementations, theuser computing device 102 can implement themodel trainer 160 to personalize themodels 120 based on user-specific data. -
FIG. 2 depicts a block diagram of an example neuralnetwork debugging system 200 using coverage guided fuzzing according to example embodiments of the present disclosure. In some implementations, the neuralnetwork debugging system 200 can provide for performing coverage guided fuzzing using a corpus of inputs, for example, to provide for testing neural networks, such as to discover errors which may occur for rare inputs. The neuralnetwork debugging system 200 can allow for guiding mutations to corpus inputs by a coverage metric to work toward a goal of satisfying user-specified constraints (e.g., random changes are made to inputs according to some mutation procedure and the mutated inputs are added to an input corpus when they exercise new coverage). As an example, coverage can be measured by analyzing the activation vectors of the neural network coverage graph. For instance, in some implementations, new coverage can be determined based on whether the neural network has resulted in a state that the neural network has not reached previously, such that the new coverage helps to provide incremental progress in debugging of the neural network model. For example, in some implementations, coverage guided fuzzing can be applied to neural networks to provide for finding numerical errors in trained neural networks, generating disagreements between neural networks and quantized versions of those networks, surfacing undesirable behavior in models, and/or the like. - As illustrated in
FIG. 2 , a neuralnetwork debugging system 200 can include a coverage guidedfuzzer 202 and a seed corpus 220 (e.g., containing at least one set of inputs for the computation graph) which can provide for an initial set of inputs to a coverage guidedfuzzer 202 to test a neural network. - The coverage guided
fuzzer 202 can obtain (e.g., select) a set of inputs from theseed corpus 220 to provide aninput corpus 204, which may comprise all or some subset of inputs included in theseed corpus 220. In some implementations, the inputs can be restricted to some type of valid neural network inputs (e.g., images having a correct size and shape, characters that are in a vocabulary extracted from a training set, etc.). In some implementations, theseed corpus 220 can be supplied by a user and/or can be selected from a set of available seed corpuses. The inputs can be textual inputs, image inputs, audio data inputs, sensor data inputs, and/or various other types of inputs. - The coverage guided
fuzzer 202 can include aninput chooser 206 that can select input(s) from theinput corpus 204 to use during a particular iteration of the coverage guided fuzzing. For example, in some implementations, theinput chooser 206 can select inputs using uniform random selection. For example, in some implementations, theinput chooser 206 can be biased towards selecting inputs that were more recently added to theinput corpus 204. As one example, theinput chooser 206 can select inputs using a heuristic such as -
- wherein p(ck, t) gives a probability of choosing an input corpus element ck at time t where tk is the time when element ck was added to the input corpus. The intuition behind this is that recently sampled inputs are more likely to yield useful new coverage when mutated, but that this advantage decays as time progresses, and thus inputs can be selected as a function of their age.
- The
input chooser 206 can provide the selected input(s) to amutator 208. Themutator 208 can apply modifications (e.g., mutations) to the selected input(s) before the inputs are provided to the neural network. For example, in some implementations, themutator 208 can add white noise of a user-configurable variance to input(s) (e.g., image inputs, etc.). As another example, in some implementations, themutator 208 can add white noise of a user-configurable variance to the one or more inputs (e.g., image inputs, etc.), wherein a difference between the mutated input and an original input from which the mutated input is descended is constrained to have a user-configurable L∞ norm. This type of constrained mutation can be useful to find inputs that satisfy some objective function, but are still plausibly of the same “class” as the original input that was used as a seed. In some implementations, the image can be clipped after mutation so that it lies in the same range as the inputs used to train the neural network being debugged. - As another example, in some implementations, such as with text string inputs, one of a set of operations can be uniformly performed at random, including operations such as deleting a character at a random location, adding a character at a random location, substituting a random character at a random location, and/or the like.
- The
input chooser 206 includes computer logic utilized to provide desired functionality. Theinput chooser 206 can be implemented in hardware, firmware, and/or software controlling a general purpose processor. For example, in some implementations, theinput chooser 206 includes program files stored on a storage device, loaded into a memory and executed by one or more processors. In other implementations, theinput chooser 206 includes one or more sets of computer-executable instructions that are stored in a tangible computer-readable storage medium such as RAM hard disk or optical or magnetic media. - The
mutator 208 can then provide the mutated input(s) to theneural network 210. Theneural network 210 can provide outputs which can include a set of coverage arrays, for which coverage can be computed, and a set of metadata arrays, from which a result of an objective function can be computed. For example, when the mutated inputs are fed into a computation graph, both coverage arrays and metadata arrays are returned as output. - The
mutator 208 includes computer logic utilized to provide desired functionality. Themutator 208 can be implemented in hardware, firmware, and/or software controlling a general purpose processor. For example, in some implementations, themutator 208 includes program files stored on a storage device, loaded into a memory and executed by one or more processors. In other implementations, themutator 208 includes one or more sets of computer-executable instructions that are stored in a tangible computer-readable storage medium such as RAM hard disk or optical or magnetic media. - The
objective function 212 can assess whether the neural network has reached some particular state, for example, a state which may be regarded as erroneous, based on the metadata array(s). An erroneous state may include an incorrect prediction, an execution time greater than a maximum execution time, a processor usage greater than a maximum processor usage, a failure of the neural network to execute, and/or other the existence of other errors or undesirable behavior or performance. In some implementations, theobjective function 212 can be specified by a user and/or selected from a set of available objective functions. Generally, theobjective function 212 used to assess whether the neural network has reached some particular state can be separate and distinct from some other objective or loss function used to train the neural network. If theobjective function 212 is satisfied, the mutated input(s) provided to the neural network can be flagged, such as being added to a list of test cases (e.g., for future debugging, etc.). As an example, when the mutated inputs are fed into a computation graph and metadata arrays are returned as output, the objective function can be applied to the metadata arrays and any mutated inputs that caused the objective function to be satisfied can be flagged. - The
coverage analyzer 214 can determine whether the coverage provided by the mutated input(s) is new coverage (e.g., whether the neural network has reached a state that it has not reached previously, etc.) based on the coverage array(s). For example, in some implementations,coverage analyzer 214 can determine whether new coverage is provided based on whether an activation vector is approximately close to a previous activation vector. If thecoverage analyzer 214 determines that the mutated input(s) provide new coverage, the mutated input(s) can be added to theinput corpus 204, for example, to be used as input(s) in future iterations of debugging and/or the like. For example, an approximate nearest neighbor can be computed for a new activation vector and checked to determine how far away the nearest neighbor is in Euclidean distance from the activation vector. The input can be added to the corpus if the distance is greater than some defined amount (e.g., which can be a user-configurable hyperparameter, an adaptive hyperparameter to adapts over time, and/or a dynamic hyperparameter that changes over time, for example, according to a predetermined schedule). In some implementations, the coverage guidedfuzzer 202 can continue to select, mutate, and analyze inputs included in theinput corpus 204 until instructed to stop and/or some other stopping criterion in met. - The
coverage analyzer 214 includes computer logic utilized to provide desired functionality. Thecoverage analyzer 214 can be implemented in hardware, firmware, and/or software controlling a general purpose processor. For example, in some implementations, thecoverage analyzer 214 includes program files stored on a storage device, loaded into a memory and executed by one or more processors. In other implementations, thecoverage analyzer 214 includes one or more sets of computer-executable instructions that are stored in a tangible computer-readable storage medium such as RAM hard disk or optical or magnetic media. - The coverage arrays and/or associated activation vectors may describe whether some or all of the neurons of the neural network were activated during processing of an input. As one example, a coverage array and/or associated activation vector may be limited to describing only whether the logits of the neural network and/or neurons of a layer of the network prior to the logits were activated.
- In some implementations, the
system 200 can be applied (e.g., in parallel) to two or more different (but potentially related) models to identify disagreements between the models. For example, the two or more different models can be two or more different versions of a base model such as a base model and a quantized version of the base model. To identify disagreements, the same input (e.g., a mutated input) can be provided to the two or more different models and the two or more different outputs of the two or more different models can be analyzed (e.g., according to theobjective function 212 and/or the coverage analyzer 214) to detect disagreements or otherwise measure a divergence in the outputs. -
FIG. 3 depicts a flow chart diagram of example operations to perform neural network debugging according to example embodiments of the present disclosure. AlthoughFIG. 3 depicts steps performed in a particular order for purposes of illustration and discussion, the methods of the present disclosure are not limited to the particularly illustrated order or arrangement. The various steps of themethod 300 can be omitted, rearranged, combined, and/or adapted in various ways without deviating from the scope of the present disclosure. - At 302, a computing system can obtain an input corpus, for example from a seed corpus comprising one or more sets of inputs. For example, a seed corpus can contain at least one set of inputs for the computation graph. The inputs can be restricted to those inputs that are in some sense valid neural network inputs. For example, if the inputs are images, the inputs can be restricted to those inputs that have the correct size and shape, and that lie in the same interval as the input pixels of the dataset under consideration. As another example, if the inputs are sequences of characters, inputs can be restricted to characters that are in the vocabulary extracted from the training set.
- At 304, the computing system can select one or more inputs from the input corpus for use in debugging a neural network. For example, the computing system can select one or more inputs from the input corpus based on uniform random selection, based on one or more heuristics (e.g.,
-
- giving a probability of choosing an input corpus element ck at time t where tk is the time when element ck was added to the input corpus, etc.), and/or the like.
- At 306, the computing system can modify the selected input(s) prior to input to the neural network by performing some type of mutation on the selected input(s). For example, in some implementations, the computing system can perform a simple modification of the input such as flipping a sign of an input. As another example, in some implementations, computing system can restrict the modifications to follow a constraint on the total modification made to a corpus element over time.
- At 308, the computing system feed the modified input(s) to the neural network that is to be debugged.
- At 310, the computing system can obtain, as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays (e.g., that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network) which can be used to compute the actual coverage exercised by the modified input(s).
- At 312, the computing system the computing system can determine whether the mutated input(s) provide new coverage at least in part on the coverage array(s). For example, the computing system can determine that new coverage is provided is the neural network results in a state that it has not been in before. If the mutated input(s) provide new coverage, operation continues to 314. If the mutated input(s) do not provide new coverage, operations continue to 322, where a next input can be analyzed. For example, in some implementations, when a new activation vector is received, its nearest neighbor can be determined and checked for how far away the nearest neighbor is in Euclidean distance. The input can be added to the corpus if the distance is greater than some defined amount.
- At 314, the computing system can add the mutated input(s) to the input corpus.
- At 316, the computing system, as a result of the neural network processing the one or more mutated inputs, a set of metadata arrays (e.g., that describe metadata associated with execution of the neural network to process the one or more mutated inputs) for use in computing the objective function.
- At 318, the computing system can determine whether the objective function is satisfied based at least in part on the metadata array(s). For example, the objective function can assess whether the neural network has reached a particular state, such as state that is regarded as erroneous. For example, the objective function can be applied to the metadata arrays and inputs that cause the objective to be satisfied can be flagged. If the objective function is satisfied, operation continues to 320. If the objective function is not satisfied, operation continues to 322.
- At 320, the computing system can add the mutated input to a list of test cases.
- The technology discussed herein makes reference to servers, databases, software applications, and other computer-based systems, as well as actions taken and information sent to and from such systems. The inherent flexibility of computer-based systems allows for a great variety of possible configurations, combinations, and divisions of tasks and functionality between and among components. For instance, processes discussed herein can be implemented using a single device or component or multiple devices or components working in combination. Databases and applications can be implemented on a single system or distributed across multiple systems. Distributed components can operate sequentially or in parallel.
- While the present subject matter has been described in detail with respect to various specific example embodiments thereof, each example is provided by way of explanation, not limitation of the disclosure. Those skilled in the art, upon attaining an understanding of the foregoing, can readily produce alterations to, variations of, and equivalents to such embodiments. Accordingly, the subject disclosure does not preclude inclusion of such modifications, variations and/or additions to the present subject matter as would be readily apparent to one of ordinary skill in the art. For instance, features illustrated or described as part of one embodiment can be used with another embodiment to yield a still further embodiment. Thus, it is intended that the present disclosure cover such alterations, variations, and equivalents.
Claims (21)
1.-20. (canceled)
21. A computer-implemented method for debugging a neural network, the method comprising:
obtaining, by one or more computing devices, one or more inputs from an input corpus;
mutating, by the one or more computing devices, the one or more inputs to generate one or more mutated inputs, wherein the one or more mutated inputs are constrained to have a same class as the one or more inputs;
providing, by the one or more computing devices, the one or more mutated inputs to a neural network;
obtaining, by the one or more computing devices as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network;
determining, by the one or more computing devices based at least in part on the set of coverage arrays, whether the one or more mutated inputs provide new coverage; and
upon determining that the one or more mutated inputs provide new coverage, adding, by the one or more computing devices, the one or more mutated inputs to the input corpus.
22. The method of claim 21 , further comprising:
obtaining, by the one or more computing devices as a result of the neural network processing the one or more mutated inputs, a set of metadata arrays that describe metadata associated with execution of the neural network to process the one or more mutated inputs;
determining, by the one or more computing devices based at least in part on the set of metadata arrays, whether an objective function is satisfied; and
upon determining that the objective function is satisfied, adding, by the one or more computing devices, the one or more mutated inputs to a list of test cases.
23. The method of claim 21 , wherein determining, by the one or more computing devices based at least in part on the set of coverage arrays, whether the one or more mutated inputs provide new coverage comprises:
generating, by the one or more computing devices, an activation vector based at least in part on the set of coverage arrays;
performing, by the one or more computing devices, an approximate nearest neighbors algorithm to identify a previous activation vector;
determining, by the one or more computing devices, a distance between the activation vector and the previous activation vector identified by the approximate nearest neighbors algorithm; and
comparing, by the one or more computing devices, the distance to a threshold distance;
wherein the one or more mutated inputs provide new coverage when the distance is greater than the threshold distance.
24. The method of claim 21 , wherein obtaining one or more inputs from the input corpus comprises using uniform random selection to select the one or more inputs from the input corpus.
25. The method of claim 21 , wherein obtaining one or more inputs from the input corpus comprises selecting the one or more inputs from the input corpus using a heuristic of
wherein p(ck, t) gives a probability of choosing input corpus element ck at time t where tk is the time when element ck was added to the input corpus.
26. The method of claim 21 , wherein mutating the one or more inputs comprises mutating the one or more inputs subject to a constraint, wherein the constraint comprises a L∞ norm.
27. The method of claim 26 , wherein the L∞ norm is specified by a user.
28. The method of claim 21 , wherein determining whether the one or more mutated inputs provide new coverage comprises determining whether the neural network has reached a new state that it has not previously reached.
29. The method of claim 28 , wherein determining whether the neural network has reached a new state that it has not previously reached comprises determining whether an activation vector is approximately close to a previous activation vector.
30. The method of claim 22 , wherein determining whether the objective function is satisfied comprises determining whether the neural network has reached a desired state.
31. The method of claim 30 , wherein the desired state is an erroneous state for the neural network.
32. A computing device comprising:
one or more processors; and
one or more non-transitory computer-readable media that store instructions that, when executed by the one or more processors, cause the computing device to:
obtain one or more inputs from an input corpus;
mutate the one or more inputs to generate one or more mutated inputs, wherein the one or more mutated inputs are constrained to have a same class as the one or more inputs;
provide the one or more mutated inputs to a neural network;
obtain as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network;
determine based at least in part on the set of coverage arrays, whether the one or more mutated inputs provide new coverage; and
upon determining that the one or more mutated inputs provide new coverage, add the one or more mutated inputs to the input corpus.
33. The computing device of claim 32 , further comprising instructions, that when executed, cause the computing device to:
obtain as a result of the neural network processing the one or more mutated inputs, a set of metadata arrays that describe metadata associated with execution of the neural network to process the one or more mutated inputs;
determine based at least in part on the set of metadata arrays, whether an objective function is satisfied; and
upon determining that the objective function is satisfied, add the one or more mutated inputs to a list of test cases.
34. The computing device of claim 32 , further comprising instructions, that when executed, cause the computing device to:
obtain the input corpus from a seed corpus, the seed corpus containing at least one set of inputs.
35. The computing device of claim 32 , wherein obtaining one or more inputs from the input corpus comprises:
using uniform random selection to select the one or more inputs from the input corpus; or
selecting the one or more inputs from the input corpus using a heuristic of
wherein p(ck, t) gives a probability of choosing input corpus element ck at time t where tk is the time when element ck was added to the input corpus.
36. The computing device of claim 32 , wherein a difference between the one or more mutated inputs and the one or more inputs from which the one or more mutated inputs are descended is constrained to have a L∞ norm.
37. The computing device of claim 32 , wherein determining whether the one or more mutated inputs provide new coverage comprises determining whether the neural network has reached a new state that it has not previously reached; and
wherein determining whether the neural network has reached a new state that it has not previously reached comprises determining whether an activation vector is approximately close to a previous activation vector.
38. The computing device of claim 33 , wherein determining whether the objective function is satisfied comprises determining whether the neural network has reached a desired state, wherein the desired state is an erroneous state for the neural network.
39. One or more non-transitory computer-readable media that store instructions that, when executed by one or more processors of a computing system, cause the computing system to perform operations, the operations comprising:
obtaining one or more inputs from an input corpus;
mutating the one or more inputs to generate one or more mutated inputs, wherein a difference between the one or more mutated inputs and the one or more inputs from which the one or more mutated inputs are descended is constrained to have a L∞ norm;
providing the one or more mutated inputs to a neural network;
obtaining, as a result of the neural network processing the one or more mutated inputs, a set of metadata arrays that describe metadata associated with execution of the neural network to process the one or more mutated inputs;
determining, based at least in part on the set of metadata arrays, whether an objective function is satisfied; and
upon determining that the objective function is satisfied, adding the one or more mutated inputs to a list of test cases.
40. The one or more non-transitory computer-readable media of claim 39 , wherein the operations further comprise:
obtaining, as a result of the neural network processing the one or more mutated inputs, a set of coverage arrays that describe whether one or more neurons of the neural network were activated during processing of the one or more mutated inputs by the neural network;
determining, based at least in part on the set of coverage arrays, whether the one or more mutated inputs provide new coverage; and
upon determining that the one or more mutated inputs provide new coverage, adding the one or more mutated inputs to the input corpus.
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US17/392,937 US20210365797A1 (en) | 2018-05-18 | 2021-08-03 | Systems and Methods for Debugging Neural Networks with Coverage Guided Fuzzing |
Applications Claiming Priority (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US201862673751P | 2018-05-18 | 2018-05-18 | |
US16/415,693 US11080603B2 (en) | 2018-05-18 | 2019-05-17 | Systems and methods for debugging neural networks with coverage guided fuzzing |
US17/392,937 US20210365797A1 (en) | 2018-05-18 | 2021-08-03 | Systems and Methods for Debugging Neural Networks with Coverage Guided Fuzzing |
Related Parent Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US16/415,693 Continuation US11080603B2 (en) | 2018-05-18 | 2019-05-17 | Systems and methods for debugging neural networks with coverage guided fuzzing |
Publications (1)
Publication Number | Publication Date |
---|---|
US20210365797A1 true US20210365797A1 (en) | 2021-11-25 |
Family
ID=66770589
Family Applications (2)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US16/415,693 Active US11080603B2 (en) | 2018-05-18 | 2019-05-17 | Systems and methods for debugging neural networks with coverage guided fuzzing |
US17/392,937 Abandoned US20210365797A1 (en) | 2018-05-18 | 2021-08-03 | Systems and Methods for Debugging Neural Networks with Coverage Guided Fuzzing |
Family Applications Before (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US16/415,693 Active US11080603B2 (en) | 2018-05-18 | 2019-05-17 | Systems and methods for debugging neural networks with coverage guided fuzzing |
Country Status (4)
Country | Link |
---|---|
US (2) | US11080603B2 (en) |
EP (1) | EP3782082A1 (en) |
CN (1) | CN112119410A (en) |
WO (1) | WO2019222656A1 (en) |
Families Citing this family (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US11768912B2 (en) * | 2019-07-12 | 2023-09-26 | International Business Machines Corporation | Performing multivariate time series prediction with three-dimensional transformations |
CN111026664B (en) * | 2019-12-09 | 2020-12-22 | 遵义职业技术学院 | Program detection method and detection system based on ANN and application |
CN111897729B (en) * | 2020-08-03 | 2022-08-19 | 北京理工大学 | TensorFuzz-based deep neural network fuzzy test framework and test method |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5819226A (en) * | 1992-09-08 | 1998-10-06 | Hnc Software Inc. | Fraud detection using predictive modeling |
US20190324759A1 (en) * | 2017-04-07 | 2019-10-24 | Intel Corporation | Methods and apparatus for deep learning network execution pipeline on multi-processor platform |
Family Cites Families (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US9727436B2 (en) * | 2008-01-02 | 2017-08-08 | International Business Machines Corporation | Adding a profiling agent to a virtual machine to permit performance and memory consumption analysis within unit tests |
US9612942B2 (en) * | 2010-11-18 | 2017-04-04 | International Business Machines Corporation | Verification of a computer program in respect to an unexpected response to an access request |
US8464219B1 (en) * | 2011-04-27 | 2013-06-11 | Spirent Communications, Inc. | Scalable control system for test execution and monitoring utilizing multiple processors |
US10831827B2 (en) * | 2016-04-01 | 2020-11-10 | International Business Machines Corporation | Automatic extraction of user mobility behaviors and interaction preferences using spatio-temporal data |
US9977729B1 (en) * | 2016-11-23 | 2018-05-22 | Google Llc | Testing applications with a defined input format |
US10983853B2 (en) * | 2017-03-31 | 2021-04-20 | Microsoft Technology Licensing, Llc | Machine learning for input fuzzing |
US10839291B2 (en) * | 2017-07-01 | 2020-11-17 | Intel Corporation | Hardened deep neural networks through training from adversarial misclassified data |
US11645493B2 (en) * | 2018-05-04 | 2023-05-09 | Microsoft Technology Licensing, Llc | Flow for quantized neural networks |
-
2019
- 2019-05-17 EP EP19728824.4A patent/EP3782082A1/en active Pending
- 2019-05-17 US US16/415,693 patent/US11080603B2/en active Active
- 2019-05-17 CN CN201980032675.5A patent/CN112119410A/en active Pending
- 2019-05-17 WO PCT/US2019/032913 patent/WO2019222656A1/en unknown
-
2021
- 2021-08-03 US US17/392,937 patent/US20210365797A1/en not_active Abandoned
Patent Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5819226A (en) * | 1992-09-08 | 1998-10-06 | Hnc Software Inc. | Fraud detection using predictive modeling |
US20190324759A1 (en) * | 2017-04-07 | 2019-10-24 | Intel Corporation | Methods and apparatus for deep learning network execution pipeline on multi-processor platform |
Also Published As
Publication number | Publication date |
---|---|
WO2019222656A1 (en) | 2019-11-21 |
US11080603B2 (en) | 2021-08-03 |
CN112119410A (en) | 2020-12-22 |
US20190354870A1 (en) | 2019-11-21 |
EP3782082A1 (en) | 2021-02-24 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US20210365797A1 (en) | Systems and Methods for Debugging Neural Networks with Coverage Guided Fuzzing | |
Lueckmann et al. | Benchmarking simulation-based inference | |
KR102532658B1 (en) | Neural architecture search | |
Molnar et al. | Pitfalls to avoid when interpreting machine learning models | |
US11449684B2 (en) | Contrastive pre-training for language tasks | |
US9098621B2 (en) | Modeling software behavior using learned predicates | |
Hodnett et al. | R Deep Learning Essentials: A step-by-step guide to building deep learning models using TensorFlow, Keras, and MXNet | |
US11556773B1 (en) | Machine learning analysis of incremental event causality towards a target outcome | |
JP7245961B2 (en) | interactive machine learning | |
KR20200049273A (en) | A method and apparatus of data configuring learning data set for machine learning | |
US11630758B2 (en) | Artificial intelligence enabled output space exploration for guided test case generation | |
WO2021055442A1 (en) | Small and fast video processing networks via neural architecture search | |
Melis et al. | Evaluating the impact of test‐first programming and pair programming through software process simulation | |
EP3735636B1 (en) | Artificial intelligence enabled output space exploration for guided test case generation | |
Sadia et al. | Bayesian change-point modeling with segmented ARMA model | |
Wang et al. | Using history matching for prior choice | |
KR102192461B1 (en) | Apparatus and method for learning neural network capable of modeling uncerrainty | |
US20230281310A1 (en) | Systems and methods of uncertainty-aware self-supervised-learning for malware and threat detection | |
Chaparro et al. | Learning Analytics in Computer Programming Courses. | |
Zimmermann et al. | Evaluating the Effectiveness of Neuroevolution for Automated GUI-Based Software Testing | |
Munley et al. | LLM4VV: Developing LLM-Driven Testsuite for Compiler Validation | |
Omri | Quality-Aware Learning to Prioritize Test Cases | |
Polyn | Assessing neurocognitive hypotheses in a likelihood-based model of the free-recall task | |
US20240135152A1 (en) | Automated, Constraints-Dependent Machine Learning Model Thresholding Mechanisms | |
CN117290856B (en) | Intelligent test management system based on software automation test technology |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
STPP | Information on status: patent application and granting procedure in general |
Free format text: DOCKETED NEW CASE - READY FOR EXAMINATION |
|
AS | Assignment |
Owner name: GOOGLE LLC, CALIFORNIA Free format text: ASSIGNMENT OF ASSIGNORS INTEREST;ASSIGNOR:ODENA, AUGUSTUS QUADROZZI;REEL/FRAME:057428/0032 Effective date: 20180522 |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: NON FINAL ACTION MAILED |
|
STPP | Information on status: patent application and granting procedure in general |
Free format text: FINAL REJECTION MAILED |
|
STCB | Information on status: application discontinuation |
Free format text: ABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTION |