Fuzzing the brain: automated stress testing for the safety of ML-driven neurostimulation.
The 5 matches
- [1] § Methods ↔ exp_code_and_data/corticalcovcomp_base1/main.py, lines 51–79 · score 0.52 · pulse duration, charge density, instantaneous, amplitude, electrodes, violation
- [2] § Methods ↔ exp_code_and_data/corticalcovcomp_nc/main.py, lines 51–79 · score 0.52 · pulse duration, charge density, instantaneous, amplitude, electrodes, violation
- [3] § Methods › Safety constraints for electrode-based neurostimulation ↔ exp_code_and_data/corticalcovcomp_base1/main.py, lines 51–79 · score 0.51 · pulse duration, Charge density, amplitude, threshold, electrochemical, violation
- [4] § Methods › Safety constraints for electrode-based neurostimulation ↔ exp_code_and_data/corticalcovcomp_nc/main.py, lines 51–79 · score 0.51 · pulse duration, Charge density, amplitude, threshold, electrochemical, violation
- [5] § Methods › Models under test › Retinal stimulus encoders ↔ exp_code_and_data/retinalcovcomp_phi1/main.py, lines 47–75 · score 0.50 · pulse duration, active electrodes, charge, instantaneous, thresholds, retinal
Paper
Loaded from Europe PMC by your browser, not stored by OSCR: doi.org · Europe PMC
The paper is loaded when this pane is shown.
The authors' code
Python · 491 lines · 21 KB · BSD-3-Clause · 2 matches
- import sys
- import os
- import re
- import time
- import random
- import math
- import numpy as np
- import copy
- from boundslist import *
- from network import *
- from parseinputs import *
- from deephuntermutators import *
- def get_covprop_helper(grid):
- #recursive: for each elem in grid, if it is a number then check 1 or 0, otherwise recursively descend
- numcovered = 0
- numtotal = 0
- for i in range(len(grid)):
- if isinstance(grid[i], list):
- (a,b) = get_covprop_helper(grid[i])
- numcovered += a
- numtotal += b
- else:
- if(grid[i] == 1):
- numcovered += 1
- numtotal += 1
- else:
- numtotal += 1
- return (numcovered, numtotal)
- def get_covprop(grid):
- (numcovered, numtotal) = get_covprop_helper(grid)
- return float(numcovered)/float(numtotal)
- def invert_colors(sample, boundslist):
- for i in range(len(sample)):
- sample[i] = boundslist[i][1] - sample[i] + boundslist[i][0]
- return sample
- def generate_random(boundslist):
- sample = []
- for elem in boundslist:
- sample += [random.uniform(elem[0],elem[1])]
- return sample
- def check_violations(networkoutput, n, e1, e2, e3): #currently this expects thresholds already applied, I think that is best
- violations = [0,0,0,0,0,0] #will be one-hot encoding, first is frequency violation, third is charge density, fifth is instantaneous current, sixth is active electrodes
- #second and fourth are proportions out of n
- #elec[0] = freq
- #elec[1] = amplitude
- #elec[2] = pulse duration
- active_electrodes = 0
- instantaneous_current = 0
- assert(len(networkoutput) == n)
- for elec in networkoutput: #expect this to have 225 electrodes
- if(elec[0] == 0):
- if(elec[2] > 0):
- violations[0] = 1
- violations[1] += 1
- elif(2 * elec[2] > 1000/elec[0]):
- violations[0] = 1
- violations[1] += 1
- if(elec[2] * elec[1] > e1):
- violations[2] = 1
- violations[3] += 1
- instantaneous_current += elec[1]
- if(elec[1] > 20):
- active_electrodes += 1
- if(instantaneous_current > e2):
- violations[4] = 1
- # print(active_electrodes)
- if(active_electrodes > e3):
- violations[5] = 1
- return violations
- # def check_v_prop(networkoutput, n, e1, e2, e3):
- # vprops = []
- # active_electrodes = 0
- # instantaneous_current = 0
- # assert(len(networkoutput) == n)
- # for elec in networkoutput: #expect this to have 225 electrodes
- # if(elec[0] == 0):
- # if(elec[2] > 0):
- # vprops += [2]#200%
- # else:
- # vprops += [0]#0%
- # else:
- # vprops += [2 * elec[2] / (1000/elec[0])]
- # # print(len(vprops))
- # for elec in networkoutput:
- # vprops += [elec[2] * elec[1] / e1]
- # instantaneous_current += elec[1]
- # if(elec[1] > 0):
- # active_electrodes += 1
- # # print(len(vprops))
- # vprops += [instantaneous_current/e2]
- # vprops += [active_electrodes]
- # # print(str(2*n+2))
- # # print(len(vprops))
- # assert(len(vprops) == 2*n+2)
- # return vprops
- #initialize variables from cmd line input
- countlimit = int(sys.argv[1])
- n = int(sys.argv[2])
- e1 = float(sys.argv[3])
- e2 = float(sys.argv[4])
- e3 = int(sys.argv[5])
- seedsfile = sys.argv[6]
- mutation_specs_file = sys.argv[7]
- fuzzing_coverage_strat = "KVPV"
- fuzzing_coverage_strat_param = 0 #update this with best found default
- fuzzing_coverage_strat_param2 = 0 #update this with best found default
- training_profile_tests_file = ""
- for i in range(8,len(sys.argv)):
- if(sys.argv[i] == "-fuzz_coverage"):
- fuzzing_coverage_strat = sys.argv[i+1] #current options are NC, KMNC, NBC, SNAC, TKNC, KVPA, KVPV, KMOC, R0, RA, KVPO, Local, KMIC, Div-Approx
- j = 1
- if "K" in fuzzing_coverage_strat or fuzzing_coverage_strat == "Div-Approx":
- j += 1
- fuzzing_coverage_strat_param = int(sys.argv[i+j]) #KVPA and KVPV: K; KMNC: K; TKNC: K
- if(fuzzing_coverage_strat == "KVPA" or fuzzing_coverage_strat == "KVPV" or fuzzing_coverage_strat == "KVPO"):
- j += 1
- fuzzing_coverage_strat_param2 = float(sys.argv[i+j])
- else:
- fuzzing_coverage_strat_param = 0
- if fuzzing_coverage_strat == "KMNC" or fuzzing_coverage_strat == "NBC" or fuzzing_coverage_strat == "SNAC" or fuzzing_coverage_strat == "KMOC" or fuzzing_coverage_strat == "Div-Approx":
- j += 1
- training_profile_tests_file = sys.argv[i+j]
- i += j
- outputdirname = "output_" + sys.argv[1] + "_" + sys.argv[2] + "_" + sys.argv[3] + "_" + sys.argv[4] + "_" + sys.argv[5] + "_" + (sys.argv[6].split("/")[-1]).split(".")[0] + "_" + (sys.argv[7].split("/")[-1]).split(".")[0] + "_" + fuzzing_coverage_strat
- if(fuzzing_coverage_strat_param != 0):
- outputdirname += str(fuzzing_coverage_strat_param)
- if(fuzzing_coverage_strat_param2 != 0):
- outputdirname += "_" + str(fuzzing_coverage_strat_param2)
- if(training_profile_tests_file != ""):
- outputdirname += (training_profile_tests_file.split("/")[-1]).split(".")[0]
- #check if folder exists, otherwise create
- if not os.path.isdir(outputdirname):
- os.mkdir(outputdirname)
- outfileinstances = open(outputdirname + "/instances.txt", "w")
- progresstimes = open(outputdirname + "/progress.txt", "w")
- if "K" in fuzzing_coverage_strat:
- assert(fuzzing_coverage_strat_param != 0)
- if fuzzing_coverage_strat == "KMNC" or fuzzing_coverage_strat == "NBC" or fuzzing_coverage_strat == "SNAC":
- assert(training_profile_tests_file != "")
- starttime = time.time()
- #if seeds file present, read it in
- seedlist = parse_inputs(seedsfile)
- random.shuffle(seedlist) #makes sure elements are in random order to start
- violations = [0,0,0,0,0,0]
- progresslogstep = 50
- #read in allowed mutations and put into list
- infile = open(mutation_specs_file, "r")
- data = infile.readlines()
- infile.close()
- allowed_mutations = []
- for line in data:
- if line[-1] == "\n":
- line = line[:-1]
- if line == "" or line[0] == "#":
- continue
- allowed_mutations += [line]
- print(allowed_mutations)
- #if we have a training_profile... file, read it in and run all those tests.
- high_n = []
- low_n = []
- #create low_n and high_n but do not add coverage or log violations based on these tests.
- if(fuzzing_coverage_strat == "KMNC" or fuzzing_coverage_strat == "NBC" or fuzzing_coverage_strat == "SNAC"):
- for i in range(len(model.layers)-1):
- if "dense" in model.layers[i].name:
- high_n += [[-9999999] * model.layers[i].units]
- low_n += [[9999999] * model.layers[i].units]
- preplist = parse_inputs(training_profile_tests_file)
- for item in preplist:
- test = (np.array([np.reshape(item, (49,49,1)),]),np.array([phi,]))
- layer_outs = [func([test]) for func in functors]
- row = 0
- for i in range(len(layer_outs)):
- if "dense" in model.layers[i].name:
- assert(len(high_n[row]) == len(layer_outs[i][0][0]))
- for j in range(len(layer_outs[i][0][0])):
- if(high_n[row][j] < layer_outs[i][0][0][j]):
- high_n[row][j] = layer_outs[i][0][0][j]
- if(low_n[row][j] > layer_outs[i][0][0][j]):
- low_n[row][j] = layer_outs[i][0][0][j]
- row += 1
- print("done with preprocess")
- elif(fuzzing_coverage_strat == "KMOC"):
- high_n = [-9999999] * 3
- low_n = [9999999] * 3
- preplist = parse_inputs(training_profile_tests_file)
- for item in preplist:
- input2d = []
- singlerow = []
- for i in range(len(item)):
- singlerow += [item[i]]
- if(len(singlerow) == 128):
- input2d += [singlerow]
- singlerow = []
- singleinput = torch.tensor(input2d).float()
- singleinput = singleinput.to('cuda:0')
- singleinput = torch.unsqueeze(singleinput, 0)
- singleinput = torch.unsqueeze(singleinput, 0)
- stimulation = encoder(singleinput)
- stimulation1d = stimulation[0].tolist()
- result = []
- for elem in stimulation1d:
- result += [[300,elem*1000000,0.17]]
- for i in range(len(result)):
- for j in range(len(result[i])):#3 things
- if(high_n[j] < result[i][j]):
- high_n[j] = result[i][j]
- if(low_n[j] > result[i][j]):
- low_n[j] = result[i][j]
- print("done with preprocess")
- elif(fuzzing_coverage_strat == "Div-Approx"):
- high_n = [-9999999] * 4608
- low_n = [9999999] * 4608
- preplist = parse_inputs(training_profile_tests_file)
- singletest = preplist[0][:]
- singletest = [x * 255 for x in singletest]
- singletest = np.array(singletest)
- x_test = np.reshape(singletest, (1,128,128))
- preplist = preplist[1:]
- for item in preplist:
- singletest = item[:]
- singletest = [x * 255 for x in singletest]
- singletest = np.array(singletest)
- singletest = np.reshape(singletest, (1,128,128))
- x_test = np.append(x_test, singletest, axis=0)
- x_test1=np.dstack([x_test]*3)
- x_test1= x_test1.reshape(-1,128,128,3)
- x_test1 = np.asarray([img_to_array(array_to_img(im, scale=False).resize((48,48))) for im in x_test1])
- x_test1 = x_test1.astype("float32")
- x_test1 = (x_test1 / 255.0) - (1.0 - CLIP_MAX)
- input_layer=layers.Input(shape=(48,48,3))
- model_vgg16=VGG16(weights='imagenet',input_tensor=input_layer,include_top=False)
- # model_vgg16.summary()
- base_model = model_vgg16
- # You can select another layer of VGG16 that you want to test.
- name_layer = 'block5_conv3'
- intermediate_layer_model = Model(inputs=base_model.input, outputs=base_model.get_layer(name_layer).output)
- FF = intermediate_layer_model.predict(x_test1)
- features= FF.reshape((len(x_test1),9*512))
- print(features.shape)
- # print("rank of feature matrix", np.linalg.matrix_rank(features))
- # nom = (features-features.min(axis=0))*(1-0)
- # print(nom.shape)
- # denom = features.max(axis=0) - features.min(axis=0)
- # denom[denom==0] = 1
- # print(denom.shape)
- # X_scf = nom/denom
- # print(X_scf.shape)
- for outerindex in range(len(features)):
- for index in range(len(features[outerindex])):
- # print(index)
- # print(type(X_scf[0][index].item()))
- if(features[outerindex][index].item() > high_n[index]):
- high_n[index] = features[outerindex][index].item()
- elif(features[outerindex][index].item() < low_n[index]):
- low_n[index] = features[outerindex][index].item()
- print("done with preprocess")
- #initialize seed list tracking
- seedprobslist = [0.8]*len(seedlist)
- seedntimesused = [0]*len(seedlist)
- #initialize grid for coverage here based on coverage data, fill with zeroes
- coveragegrid = []
- # coveragedims = [] #auxilliary variable used to track how coveragegrid is used by some fuzzing strategies
- if(fuzzing_coverage_strat == "NC"):
- for i in range(len(model.layers)-1):
- if "dense" in model.layers[i].name:
- coveragegrid += [[0] * model.layers[i].units]
- # print(coveragegrid)
- # for elem in coveragegrid:
- # print(len(elem))
- elif(fuzzing_coverage_strat == "KMNC"):
- for i in range(len(model.layers)-1):
- if "dense" in model.layers[i].name:
- layergrid = []
- for j in range(model.layers[i].units):
- layergrid += [[0]*fuzzing_coverage_strat_param]
- coveragegrid += [layergrid]
- elif(fuzzing_coverage_strat == "NBC"):
- for i in range(len(model.layers)-1):
- if "dense" in model.layers[i].name:
- layergrid = []
- for j in range(model.layers[i].units):
- layergrid += [[0,0]]
- coveragegrid += [layergrid]
- elif(fuzzing_coverage_strat == "SNAC"):
- #same code as NC
- for i in range(len(model.layers)-1):
- if "dense" in model.layers[i].name:
- coveragegrid += [[0] * model.layers[i].units]
- elif(fuzzing_coverage_strat == "TKNC"):
- for i in range(len(model.layers)-1):
- if "dense" in model.layers[i].name:
- coveragegrid += [[0] * model.layers[i].units]
- elif(fuzzing_coverage_strat == "KVPA" or fuzzing_coverage_strat == "KVPV" or fuzzing_coverage_strat == "KVPO"):
- #first 225 (n) entries for frequency violations, each one with K splits (per neuron)
- for i in range(n):
- coveragegrid += [[0]*fuzzing_coverage_strat_param]
- #next n entries for charge density violations, each one with K splits
- for i in range(n):
- coveragegrid += [[0]*fuzzing_coverage_strat_param]
- #next 1 entry for total amplitude with K splits
- coveragegrid += [[0]*fuzzing_coverage_strat_param]
- #finally 1 entry for active electrodes with K splits
- coveragegrid += [[0]*fuzzing_coverage_strat_param]
- elif(fuzzing_coverage_strat == "KMOC"):
- for i in range(n):
- singleelecgrid = []
- for j in range(3):
- singleelecgrid += [[0]*fuzzing_coverage_strat_param]
- coveragegrid += [singleelecgrid]
- elif(fuzzing_coverage_strat == "KMIC"):
- for i in range(128*128):
- coveragegrid += [[0]*fuzzing_coverage_strat_param]
- elif(fuzzing_coverage_strat == "Div-Approx"):
- for i in range(4608):
- coveragegrid += [[0]*fuzzing_coverage_strat_param]
- elif(fuzzing_coverage_strat == "R0" or fuzzing_coverage_strat == "RA" or fuzzing_coverage_strat == "Local"):
- coveragegrid = [0]
- else:
- print("Not a valid fuzzing coverage metric")
- exit()
- is_local = False
- if(fuzzing_coverage_strat == "Local"):
- fuzzing_coverage_strat = "R0"
- is_local = True
- most_v = [0,0,0,0,0,0]
- seed_index = 0
- #go through seedlist and check off any boxes filled by existing seeds, remove seeds that don't fill a new box. Check time during.
- count = 0
- for seed in seedlist:
- count += 1
- (res,new_coverage) = run_network(seed, fuzzing_coverage_strat, fuzzing_coverage_strat_param, fuzzing_coverage_strat_param2, coveragegrid, high_n, low_n, n, e1, e2, e3)
- v_array = check_violations(res, n, e1, e2, e3)
- if sum(v_array) > 0:
- # print("Violation found: " + str(v_array))
- violations = [x + y for x, y in zip(violations, v_array)]
- for elem in seed:
- outfileinstances.write(str(elem) + ",")
- outfileinstances.write(str(v_array) + "\n")
- if(is_local and v_array[1] + v_array[3] + v_array[5] + v_array[5] > most_v[1] + most_v[3] + most_v[4] + most_v[5]):
- most_v = v_array[:]
- seed_index = count - 1
- if(count % progresslogstep == 0):
- progresstimes.write(str(time.time() - starttime) + "," + str(violations[0]) + "," + str(violations[1]) + "," + str(violations[2]) + "," + str(violations[3]) + "," + str(violations[4]) + "," + str(violations[5]) + ",")
- covprop = get_covprop(coveragegrid)
- progresstimes.write(str(covprop) + "\n")
- #if(time.time() - starttime >= timelimit):
- # progresstimes.write(str(time.time() - starttime) + "," + str(violations[0]) + "," + str(violations[1]) + "," + str(violations[2]) + "," + str(violations[3]) + "," + str(violations[4]) + "," + str(violations[5]) + ",")
- # covprop = get_covprop(coveragegrid)
- ## progresstimes.write(str(covprop) + ",TIMEOUTINSEEDS\n")
- # print("Timeout")
- # outfileinstances.close()
- # progresstimes.close()
- # exit()
- #log the time, coverage, and violations at the end of the provided seedset
- progresstimes.write(str(time.time() - starttime) + "," + str(violations[0]) + "," + str(violations[1]) + "," + str(violations[2]) + "," + str(violations[3]) + "," + str(violations[4]) + "," + str(violations[5]) + ",")
- covprop = get_covprop(coveragegrid)
- progresstimes.write(str(covprop) + ",ENDOFSEEDS\n")
- if(is_local):
- seedlist = [seedlist[seed_index]]
- seedprobslist = [0.8]*len(seedlist)
- seedntimesused = [0]*len(seedlist)
- seedchoicecount = 0
- leninitialseedlist = len(seedlist)
- ntwkrunavgtime = 0
- ntwkruncount = 0
- #main loop: choose a seed, create 50 mutations, check each mutation and update seedlist if necessary, check time, repeat.
- while(count < countlimit):
- # print(len(seedlist))
- # print(len(seedprobslist))
- baseseedindex = 0
- if(seedchoicecount < leninitialseedlist):
- baseseedindex = seedchoicecount
- else:
- baseseedindex = random.choices(range(len(seedlist)), weights=seedprobslist, k=1)[0]#select randomly weighted by seedprobslist
- seedchoicecount += 1
- for iter in range(10):
- mutation = random.choice(allowed_mutations)
- count += 1
- seedntimesused[baseseedindex] += 1
- sample = []#use mutation on seed elem to get sample
- if mutation == "random_u":
- sample = generate_random(boundslist)
- elif mutation == "invert":
- sample = invert_colors(copy.deepcopy(seedlist[baseseedindex]), boundslist)
- else:
- # print("Here")
- # print(mutation)
- to_mutate = copy.deepcopy(seedlist[baseseedindex])
- to_mutate = [x * 255 for x in to_mutate]
- numpysample = np.reshape(to_mutate, (128,128,1))
- if mutation == "translate":
- sample = image_translation(copy.deepcopy(numpysample))
- elif mutation == "scale":
- sample = image_scale(copy.deepcopy(numpysample))
- elif mutation == "shear":
- sample = image_shear(copy.deepcopy(numpysample))
- elif mutation == "rotate":
- sample = image_rotation(copy.deepcopy(numpysample))
- elif mutation == "contrast":
- sample = image_contrast(copy.deepcopy(numpysample))
- elif mutation == "brightness":
- sample = image_brightness(copy.deepcopy(numpysample))
- elif mutation == "blur":
- sample = image_blur(copy.deepcopy(numpysample))
- elif mutation == "pixel_change":
- sample = image_pixel_change(copy.deepcopy(numpysample))
- elif mutation == "noise":
- sample = image_noise(copy.deepcopy(numpysample))
- else:
- print("mutation type not yet implemented: " + mutation)
- exit()
- if(numpysample.shape != sample.shape):
- sample = sample.reshape(numpysample.shape)
- singleinput = []
- for row in sample:
- for col in row:
- singleinput += [col[0]]
- sample = singleinput
- assert(len(sample) == 128*128)
- sample = [x / 255.0 for x in sample]
- for i in range(len(sample)):
- if sample[i] > boundslist[i][1]:
- sample[i] = boundslist[i][1]
- elif sample[i] < boundslist[i][0]:
- sample[i] = boundslist[i][0]
- ntwkrunstarttime = time.time()
- (res, new_coverage) = run_network(sample, fuzzing_coverage_strat, fuzzing_coverage_strat_param, fuzzing_coverage_strat_param2, coveragegrid, high_n, low_n, n, e1, e2, e3)
- ntwkrunavgtime += time.time() - ntwkrunstarttime
- ntwkruncount += 1
- v_array = check_violations(res, n, e1, e2, e3)
- if sum(v_array) > 0:
- # print("Violation found: " + str(v_array))
- violations = [x + y for x, y in zip(violations, v_array)]
- for elem in sample:
- outfileinstances.write(str(elem) + ",")
- outfileinstances.write(str(v_array) + "\n")
- if(fuzzing_coverage_strat == "KVPV"):
- if(new_coverage and sum(v_array) > 0):
- seedlist += [sample]
- seedprobslist += [0.8]
- seedntimesused += [0]
- else:
- if(new_coverage):
- seedlist += [sample]
- seedprobslist += [0.8]
- seedntimesused += [0]
- if(count % progresslogstep == 0):
- progresstimes.write(str(time.time() - starttime) + "," + str(violations[0]) + "," + str(violations[1]) + "," + str(violations[2]) + "," + str(violations[3]) + "," + str(violations[4]) + "," + str(violations[5]) + "," + str(count) + ",")
- covprop = get_covprop(coveragegrid)
- progresstimes.write(str(covprop) + "\n")
- #update seed at baseseedindex probabliity
- if(seedntimesused[baseseedindex] < (0.8-0.3)*5):
- seedprobslist[baseseedindex] = 0.8 - seedntimesused[baseseedindex]/5
- else:
- seedprobslist[baseseedindex] = 0.3
- progresstimes.write(str(time.time() - starttime) + "," + str(violations[0]) + "," + str(violations[1]) + "," + str(violations[2]) + "," + str(violations[3]) + "," + str(violations[4]) + "," + str(violations[5]) + "," + str(count) + ",")
- covprop = get_covprop(coveragegrid)
- progresstimes.write(str(covprop) + ",NTESTSFINISHED\n")
- print("N Tests Finished")
- print(ntwkrunavgtime/ntwkruncount)
- outfileinstances.close()
- progresstimes.close()
main.py at commit 5783f98, under BSD-3-Clause · at the source
Overview
- Department of Computer Science, University of California, Santa Barbara, CA, United States of America
- Department of Psychological & Brain Sciences, University of California, Santa Barbara, CA, United States of America
Abstract
Objective. Machine learning (ML) models are increasingly used to generate electrical stimulation patterns in neuroprosthetic devices such as visual prostheses. While these models promise precise and personalized control, they also introduce new safety risks when model outputs are delivered directly to neural tissue. We propose a systematic, quantitative approach to detect and characterize unsafe stimulation patterns in ML-driven neurostimulation systems. Approach. We adapt an automated software testing technique known as coverage-guided fuzzing to the domain of neural stimulation. Here, fuzzing performs stress testing by perturbing model inputs and tracking whether resulting stimulation violates biophysical limits on charge density, instantaneous current, or electrode co-activation. The framework treats encoders as black boxes and steers exploration with coverage metrics that quantify how broadly test cases span the space of possible outputs and violation types. Main results. Applied to deep stimulus encoders for the retina and cortex, the method systematically reveals diverse stimulation regimes that exceed established safety limits. Two violation-output coverage metrics identify the highest number and diversity of unsafe outputs, enabling interpretable comparisons across architectures and training strategies. Significance. Violation-focused fuzzing reframes safety assessment as an empirical, reproducible process. By transforming safety from a training heuristic into a measurable property of the deployed model, it establishes a foundation for evidence-based benchmarking, regulatory readiness, and ethical assurance in next-generation neural interfaces.
Reproduced under the paper's license (CC BY), from the paper cited above.
Repository
Its files are read in the Code ↔ Paper reader above, with 5 matches between paragraphs and lines of code.
mara-downing/safety_violation_fuzzing_visual_prostheses
5783f985635f4bc0ae5e41685f9654f2264816f2, 13 November 2025Availability: 1 check, the latest on 30 September 2026: the link answers
- 30 September 2026: the link answers
65 files
- boundslist.py, Python, 5 lines
- deephuntermutators.py, Python, 150 lines
- exp_code_and_data/
corticalcovcomp_base1/ , Python, 7 linesboundslist.py - exp_code_and_data/
corticalcovcomp_base1/ , Python, 225 linesdeephuntermutators.py - exp_code_and_data/
corticalcovcomp_base1/ , Python, 31 linesdownsample_vdg.py - exp_code_and_data/
corticalcovcomp_base1/ , Python, 44 linesextract_specific_mutants .py - exp_code_and_data/
corticalcovcomp_base1/ , Python, 20 linesgettotal.py - exp_code_and_data/
corticalcovcomp_base1/ , Python, 385 lineslocal_datasets.py - exp_code_and_data/
corticalcovcomp_base1/ , Python, 491 lines, 2 matchesmain.py - exp_code_and_data/
corticalcovcomp_base1/ , Python, 313 linesmodel.py - exp_code_and_data/
corticalcovcomp_base1/ , Python, 234 linesnetwork.py - exp_code_and_data/
corticalcovcomp_base1/ , Python, 23 linesparseinputs.py - exp_code_and_data/
corticalcovcomp_base1/ , Python, 362 linestestnetwork.py - exp_code_and_data/
corticalcovcomp_base1/ , Python, 152 linesutils.py - exp_code_and_data/
corticalcovcomp_base2/ , Python, 7 linesboundslist.py - exp_code_and_data/
corticalcovcomp_base2/ , Python, 225 linesdeephuntermutators.py - exp_code_and_data/
corticalcovcomp_base2/ , Python, 31 linesdownsample_vdg.py - exp_code_and_data/
corticalcovcomp_base2/ , Python, 44 linesextract_specific_mutants .py - exp_code_and_data/
corticalcovcomp_base2/ , Python, 20 linesgettotal.py - exp_code_and_data/
corticalcovcomp_base2/ , Python, 491 linesmain.py - exp_code_and_data/
corticalcovcomp_base2/ , Python, 313 linesmodel.py - exp_code_and_data/
corticalcovcomp_base2/ , Python, 234 linesnetwork.py - exp_code_and_data/
corticalcovcomp_base2/ , Python, 23 linesparseinputs.py - exp_code_and_data/
corticalcovcomp_base2/ , Python, 362 linestestnetwork.py - exp_code_and_data/
corticalcovcomp_base2/ , Python, 152 linesutils.py - exp_code_and_data/
corticalcovcomp_base3/ , Python, 7 linesboundslist.py - exp_code_and_data/
corticalcovcomp_base3/ , Python, 225 linesdeephuntermutators.py - exp_code_and_data/
corticalcovcomp_base3/ , Python, 31 linesdownsample_vdg.py - exp_code_and_data/
corticalcovcomp_base3/ , Python, 44 linesextract_specific_mutants .py - exp_code_and_data/
corticalcovcomp_base3/ , Python, 20 linesgettotal.py - exp_code_and_data/
corticalcovcomp_base3/ , Python, 491 linesmain.py - exp_code_and_data/
corticalcovcomp_base3/ , Python, 313 linesmodel.py - exp_code_and_data/
corticalcovcomp_base3/ , Python, 234 linesnetwork.py - exp_code_and_data/
corticalcovcomp_base3/ , Python, 23 linesparseinputs.py - exp_code_and_data/
corticalcovcomp_base3/ , Python, 362 linestestnetwork.py - exp_code_and_data/
corticalcovcomp_base3/ , Python, 152 linesutils.py - exp_code_and_data/
corticalcovcomp_nc/ , Python, 7 linesboundslist.py - exp_code_and_data/
corticalcovcomp_nc/ , Python, 225 linesdeephuntermutators.py - exp_code_and_data/
corticalcovcomp_nc/ , Python, 385 lineslocal_datasets.py - exp_code_and_data/
corticalcovcomp_nc/ , Python, 504 lines, 2 matchesmain.py - exp_code_and_data/
corticalcovcomp_nc/ , Python, 322 linesmodel.py - exp_code_and_data/
corticalcovcomp_nc/ , Python, 338 linesnetwork.py - exp_code_and_data/
corticalcovcomp_nc/ , Python, 23 linesparseinputs.py - exp_code_and_data/
corticalcovcomp_nc/ , Python, 152 linesutils.py - exp_code_and_data/
retinalcovcomp_phi1/ , Python, 7 linesboundslist.py - exp_code_and_data/
retinalcovcomp_phi1/ , Python, 225 linesdeephuntermutators.py - exp_code_and_data/
retinalcovcomp_phi1/ , Python, 20 linesgettotal.py - exp_code_and_data/
retinalcovcomp_phi1/ , Python, 468 lines, 1 matchmain.py - exp_code_and_data/
retinalcovcomp_phi1/ , Python, 288 linesnetwork.py - exp_code_and_data/
retinalcovcomp_phi1/ , Python, 50 linesparseinputs.py - exp_code_and_data/
retinalcovcomp_phi2/ , Python, 7 linesboundslist.py - exp_code_and_data/
retinalcovcomp_phi2/ , Python, 225 linesdeephuntermutators.py - exp_code_and_data/
retinalcovcomp_phi2/ , Python, 468 linesmain.py - exp_code_and_data/
retinalcovcomp_phi2/ , Python, 288 linesnetwork.py - exp_code_and_data/
retinalcovcomp_phi2/ , Python, 50 linesparseinputs.py - exp_code_and_data/
retinalcovcomp_phi3/ , Python, 7 linesboundslist.py - exp_code_and_data/
retinalcovcomp_phi3/ , Python, 225 linesdeephuntermutators.py - exp_code_and_data/
retinalcovcomp_phi3/ , Python, 468 linesmain.py - exp_code_and_data/
retinalcovcomp_phi3/ , Python, 288 linesnetwork.py - exp_code_and_data/
retinalcovcomp_phi3/ , Python, 50 linesparseinputs.py - main.py, Python, 468 lines
- network.py, Python, 288 lines
- parseinputs.py, Python, 12 lines
- LICENSE, License, 28 lines
- README.md, Text, 139 lines
The paper's code and data availability statement is in the Data section.
Tracing map
Proposed by the machine: these links were found in the paper and verified at the source, without human review. The map will receive a Zenodo DOI once one of the paper's authors has validated it with their ORCID.
What the map holds:
- 1 repository of the authors' code, each at its verified commit, with its license and how the link was found in the paper;
- 63 scripts, each with its path and the digest of its content;
- 5 matches between paragraphs of the paper and lines of the code (method lexical-v1);
- neither the text of the paper nor the code itself.
Its JSON (tracing-map.json) is deposited on Zenodo with its DOI once the map is validated.
Data
No dataset and no data link were found in the paper.
Data availability statement
The data that support the findings of this study are openly available at the following URL/
Reproduced under the paper's license (CC BY), from the paper cited above.
Versions
The history of this record: each version stored by the harvester or made by a correction of its authors or of the maintainers of its code, and what changed in its facts. The texts of the paper (its abstract, its availability statements) are not part of it; versions that changed only those are not listed.
Version 1, 30 September 2026: the first record
Recorded: type, language, journal, volume, issue, pages, dates, 5 authors, 5 keywords, 7 MeSH terms, 3 funders, 56 references.
Cite
This paper
Downing, M., Peng, M., Granley, J., Beyeler, M., & Bultan, T. (2026). Fuzzing the brain: automated stress testing for the safety of ML-driven neurostimulation. Journal of neural engineering, 23(2), 026004. https://
BibTeX
@article{downing2026fuzz
author = {Downing, Mara and Peng, Matthew and Granley, Jacob and Beyeler, Michael and Bultan, Tevfik},
title = {{Fuzzing the brain: automated stress testing for the safety of ML-driven neurostimulation}},
journal = {Journal of neural engineering},
year = {2026},
month = mar,
volume = {23},
number = {2},
pages = {026004},
publisher = {IOP Publishing},
issn = {1741-2560},
doi = {10.1088/
url = {https://
pmid = {41730246},
pmcid = {PMC12961644}
}
RIS
TY - JOUR
AU - Downing, Mara
AU - Peng, Matthew
AU - Granley, Jacob
AU - Beyeler, Michael
AU - Bultan, Tevfik
TI - Fuzzing the brain: automated stress testing for the safety of ML-driven neurostimulation
T2 - Journal of neural engineering
J2 - J Neural Eng
PY - 2026
DA - 2026/
VL - 23
IS - 2
SP - 026004
SN - 1741-2560
PB - IOP Publishing
DO - 10.1088/
UR - https://
LA - en
ER -
CSL-JSON
{
"id": "10.1088/
"type": "article-journal",
"title": "Fuzzing the brain: automated stress testing for the safety of ML-driven neurostimulation",
"container-title": "Journal of neural engineering",
"author": [
{
"family": "Downing",
"given": "Mara"
},
{
"family": "Peng",
"given": "Matthew"
},
{
"family": "Granley",
"given": "Jacob"
},
{
"family": "Beyeler",
"given": "Michael"
},
{
"family": "Bultan",
"given": "Tevfik"
}
],
"container-title-short":
"volume": "23",
"issue": "2",
"page": "026004",
"DOI": "10.1088/
"PMID": "41730246",
"PMCID": "PMC12961644",
"ISSN": "1741-2560",
"publisher": "IOP Publishing",
"URL": "https://
"language": "en",
"issued": {
"date-parts": [
[
2026,
3,
5
]
]
}
}
The tracing map gets a citation of its own once an author has validated it and it has a DOI.
Similar papers
The papers with a page that share the most with this one: the tools found in their code, their categories, datasets, cited references and authors, the rarest counting most.
- [1] doi:10.1016/j.celrep.2026.117420 [code]
- Neural population dynamics of direct electrical stimulation of neocortex.Journal: Cell reportsIn common: OpenCV, Pillow, pandas, 2 other tools, 3 references
- [2] doi:10.1038/s42003-026-10957-8 [code]
- Brain defence by the extracellular matrix protein Cochlin.Journal: Communications biologyIn common: Keras, TensorFlow, OpenCV, 5 other tools
- [3] doi:10.1371/journal.pcbi.1014571 [code]
- SynAPSeg: A novel dataset and image analysis framework for deep learning-based synapse detection and quantification.Journal: PLoS computational biologyIn common: Keras, TensorFlow, OpenCV, 5 other tools
- [4] doi:10.1093/jnen/nlaf152 [code]
- Clinical and pathologic correlations of machine learning quantification of Aβ deposits across 3 brain regions of decedents with Alzheimer disease.Journal: Journal of neuropathology and experimental neurologyIn common: Keras, TensorFlow, OpenCV, 5 other tools
- [5] doi:10.1371/journal.pone.0347867 [code]
- LiteFeatNet: A parameter-efficient and performance-centric deep learning model for multi-ocular disease identification using intermediate feature reduction from fundus images.Journal: PloS oneIn common: Keras, TensorFlow, OpenCV, 5 other tools
- [6] doi:10.1038/s41597-025-05174-7 [code]
- A large-scale MEG and EEG dataset for object recognition in naturalistic scenesJournal: n/aIn common: Keras, TensorFlow, OpenCV, 5 other tools
- [7] doi:10.1126/sciadv.aed3650 [code]
- Truthful visualizations for mass spectrometry imaging enable high-spatial-resolution interactive &
lt;i& gt;m/ z& lt;/ i& gt; mapping and exploration. Journal: Science advancesIn common: Keras, TensorFlow, OpenCV, 5 other tools - [8] doi:10.1364/boe.605322 [code]
- Generalized plaque digitization framework for multi-dimensional mesoscopic images.Journal: Biomedical optics expressIn common: Keras, TensorFlow, OpenCV, 5 other tools
- [9] doi:10.1038/s41467-026-72057-9 [code]
- Sex-specific behavioral feedback modulates sensorimotor processing and drives flexible social behavior.Journal: Nature communicationsIn common: Keras, TensorFlow, OpenCV, 5 other tools
- [10] doi:10.1126/sciadv.aee6952 [code]
- Wafer-scale SOT-MRAM for analog crossbar array applications.Journal: Science advancesIn common: Keras, TensorFlow, OpenCV, 4 other tools
Contribute
The authors of this paper can claim it, correct its record and validate its tracing map, and the maintainers of its code (its owner, or a public member of its organization) correct what it says of their repository; anyone signed in can ask for its removal. Every request goes to OSCR's own machine, which answers it; your account page follows them.
Sign in with ORCID to claim this paper as one of its authors, correct its record or validate its tracing map: when the paper's metadata lists your ORCID iD, you are recognized at once. Maintainers of its code: sign in with GitHub, then claim the repository on your account page.
Claim this paper
Correct its record
Say what each link of this record is, remove the ones that are not the paper's, add the ones that are missing. The correction becomes a new version of the record, in its Versions section.
Validate its tracing map
You validate the map as this page shows it: 1 repository of the authors' code, each at its verified commit and with its license, 63 scripts, and 5 matches between paragraphs and code (see the Code and Map sections). It then receives a DOI on Zenodo, with you (your ORCID iD) and OSCR as its creators; the code itself is not deposited.
The map's fingerprint: sha256:2734b38ad34095eb…
Add the badge to its README
The badge links the code to this page. Copy one of these into the README of the paper's code: only you decide where it goes, and nothing is changed for you.
Markdown
[, paste the snippet at the top, then “Commit changes…” and, to review it first, “Create a new branch and start a pull request”. You open the pull request; OSCR asks for no permission.
Request its removal
To ask OSCR to remove this record, the copies of its authors' scripts or its tracing map, use the removal request page: signed in, you say who you are, what to remove and why, then review and confirm the request. Published rules decide every request (how).
Discussion, reproductions, activity
Discussion: questions and error reports about this paper and its code, from signed-in readers and its authors. It opens with sign-in.
Reproductions: reports from readers who ran the authors' code: what they reproduced, with which environment, commit and data. It opens with sign-in.
Activity: what happens around this paper: new versions of its record, its map's validation, discussions and reproductions. It opens with sign-in.
