Page 207 - 《软件学报》2026年第3期
P. 207

软件学报 ISSN 1000-9825, CODEN RUXUEW                                        E-mail: jos@iscas.ac.cn
                 2026,37(3):1170−1196 [doi: 10.13328/j.cnki.jos.007425] [CSTR: 32375.14.jos.007425]  http://www.jos.org.cn
                 ©中国科学院软件研究所版权所有.                                                          Tel: +86-10-62562563



                                                                                       *
                 CoDefense: 面向对抗性攻击的多粒度代码归一化防御方法

                 田    朝,    邝仕琦,    闫    明,    王海弛,    陈俊洁


                 (天津大学 智能与计算学部, 天津 300350)
                 通信作者: 陈俊洁, E-mail: junjiechen@tju.edu.cn

                 摘 要: 近年来, 以代码为输入的预训练模型在许多基于代码的关键任务中取得了显著的性能优势, 但这类模型可
                 能容易受到通过保留语义的代码转换实现的对抗性攻击, 这种攻击会显著降低模型鲁棒性并可能进一步引发严重
                 的安全问题. 尽管已有对抗性训练方法通过生成对抗性样本作为增强数据来提升模型鲁棒性, 但其有效性和效率
                 在面对不同粒度和策略的未知对抗性攻击时仍显不足. 为了克服这一局限性, 提出一种基于代码归一化的预训练
                 代码模型对抗性防御方法         CoDefense. 该方法的核心思想是作为代码模型的一个前置数据处理模块, 通过多粒度代
                 码归一化技术, 对训练阶段的原始训练集和推理阶段的代码输入进行归一化预处理, 以避免潜在对抗性样本对代
                 码模型的影响. 这种策略能够高效地防御不同粒度和策略的对抗性攻击. 为验证                         CoDefense 的有效性和效率, 针对

                 3  种先进的对抗性攻击方法、3        种流行的预训练代码模型以及           3  个基于代码的分类和生成任务, 共设计了            27  个实
                 验场景进行全面的实证研究. 实验结果表明, CoDefense 相较于最先进的对抗性训练方法, 在防御对抗性攻击方面
                 显著提升了有效性和效率. 具体而言, CoDefense           平均成功防御了      95.33%  的对抗性攻击. 同时, 在时间效率上,
                 CoDefense 相对于对抗性训练方法平均提升了           85.86%.
                 关键词: 对抗性防御; 预训练代码模型; 深度学习
                 中图法分类号: TP311

                 中文引用格式: 田朝, 邝仕琦, 闫明, 王海弛, 陈俊洁. CoDefense: 面向对抗性攻击的多粒度代码归一化防御方法. 软件学报, 2026,
                 37(3): 1170–1196. http://www.jos.org.cn/1000-9825/7425.htm
                 英文引用格式: Tian Z, Kuang SQ, Yan M, Wang HC, Chen JJ. CoDefense: Defending Method Against Adversarial Attacks with Multi-
                 granularity Code Normalization. Ruan Jian Xue Bao/Journal of Software, 2026, 37(3): 1170–1196 (in Chinese). http://www.jos.org.cn/
                 1000-9825/7425.htm

                 CoDefense: Defending Method Against Adversarial Attacks with Multi-granularity Code
                 Normalization
                 TIAN Zhao, KUANG Shi-Qi, YAN Ming, WANG Hai-Chi, CHEN Jun-Jie
                 (College of Intelligence and Computing, Tianjin University, Tianjin 300350, China)
                 Abstract:  In  recent  years,  pre-trained  models  that  take  code  as  input  have  achieved  significant  performance  gains  in  various  critical  code-
                 based  tasks.  However,  these  models  remain  susceptible  to  adversarial  attacks  implemented  through  semantic-preserving  code
                 transformations,  which  can  severely  compromise  model  robustness  and  pose  serious  security  issues.  Although  adversarial  training,
                 leveraging  adversarial  examples  as  augmented  data,  has  been  employed  to  enhance  robustness,  its  effectiveness  and  efficiency  often  fall
                 short  when  facing  unseen  attacks  with  varying  granularities  and  strategies.  To  address  these  limitations,  a  novel  adversarial  defense
                 technique  based  on  code  normalization,  named  CoDefense,  is  proposed.  This  method  integrates  a  multi-granularity  code  normalization
                 approach  as  a  preprocessing  module,  which  normalizes  both  the  original  training  data  during  training  and  the  inputcode  during  inference.
                 By  doing  so,  the  proposed  method  mitigates  the  impact  of  potential  adversarial  examples  and  effectively  defends  against  attacks  of  diverse


                 *    基金项目: 国家自然科学基金  (62322208, 62232001, 12411530122)
                  收稿时间: 2024-09-05; 修改时间: 2024-10-17; 采用时间: 2025-02-19; jos 在线出版时间: 2025-08-20
                  CNKI 网络首发时间: 2025-08-20
   202   203   204   205   206   207   208   209   210   211   212