arXiv:2512.05383cs.SEcs.AI2025-12被引 2

用自动化测试发现神经刺激模型中的安全隐患

Fuzzing the brain: Automated stress testing for the safety of ML-driven neurostimulation

  • 将软件模糊测试引入神经刺激,通过扰动输入检测越界输出
  • 在视网膜和皮层模型中发现多种超出安全限值的刺激模式
  • 适合神经接口研发、安全评估及监管机构使用

机器学习模型正被用于生成视网膜和皮层神经假体中的电刺激方案。尽管能实现精准个性化控制,但直接向神经组织输出模型结果可能带来新安全风险。本文提出一种系统化、量化的安全检测方法,将覆盖引导的模糊测试(coverage-guided fuzzing)应用于神经刺激场景。该方法对模型输入进行扰动,监测生成的刺激是否违反电荷密度、瞬时电流或电极共激活等生物物理限制。框架将编码器视为黑盒,利用覆盖度指标衡量测试用例在输出空间和违规类型上的探索广度。在深度刺激编码器上应用该方法,系统揭示了多种超出安全阈值的刺激模式。两个违规覆盖度指标能识别出最多且最多样化的不安全输出,支持不同架构与训练策略间的可解释比较。该方法将安全评估转变为可重复的实证过程,使安全从训练启发式变为可测量的部署模型属性,为下一代神经接口的证据基准、监管合规与伦理保障奠定基础。

原文摘要 · Abstract (English)

Objective: Machine learning (ML) models are increasingly used to generate electrical stimulation patterns in neuroprosthetic devices such as visual prostheses. While these models promise precise and personalized control, they also introduce new safety risks when model outputs are delivered directly to neural tissue. We propose a systematic, quantitative approach to detect and characterize unsafe stimulation patterns in ML-driven neurostimulation systems. Approach: We adapt an automated software testing technique known as coverage-guided fuzzing to the domain of neural stimulation. Here, fuzzing performs stress testing by perturbing model inputs and tracking whether resulting stimulation violates biophysical limits on charge density, instantaneous current, or electrode co-activation. The framework treats encoders as black boxes and steers exploration with coverage metrics that quantify how broadly test cases span the space of possible outputs and violation types. Main results: Applied to deep stimulus encoders for the retina and cortex, the method systematically reveals diverse stimulation regimes that exceed established safety limits. Two violation-output coverage metrics identify the highest number and diversity of unsafe outputs, enabling interpretable comparisons across architectures and training strategies. Significance: Violation-focused fuzzing reframes safety assessment as an empirical, reproducible process. By transforming safety from a training heuristic into a measurable property of the deployed model, it establishes a foundation for evidence-based benchmarking, regulatory readiness, and ethical assurance in next-generation neural interfaces.

神经接口安全测试机器学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。