MLmisFinder: A Specification and Detection Approach of Machine Learning Service Misuses
Machine Learning (ML) cloud services, offered by leading providers such as Amazon, Google, and Microsoft, enable the integration of ML components into software systems without building them from scratch. However, the rapid adoption of ML services, coupled with the growing complexity of business requirements, has led to a rise in misuses by software developers, compromising the quality, maintainability, and evolution of ML service-based systems. Though prior research has explored patterns and antipatterns in service-based and ML-based systems separately, automatic detection of ML service misuses remains a challenge. In this paper, we propose MLmisFinder, an automatic approach to detect ML service misuses in software systems, aiming to identify instances of improper use of ML services to help developers properly integrate ML components in ML service-based systems. To do so, we propose a generic, extensible, and reusable metamodel that captures the data needed to detect misuses in ML service-based systems and employs it to develop rule-based detection algorithms for seven types of misuse. We validated our approach on 107 software systems collected from open-source GitHub repositories and compared our results with a state-of-the-art (SOTA) baseline. Our results show that MLmisFinder effectively detects ML service misuses, achieving an average precision of 96.7% and recall of 97%, outperforming the SOTA baseline. Moreover, MLmisFinder demonstrated high efficiency and scalability in detecting misuses in 817 ML service-based systems and revealed a widespread prevalence of such misuses, especially in data drift monitoring and schema validation.
Wed 18 MarDisplayed time zone: Athens change
14:00 - 15:30 | Session 2B - Security, Vulnerabilities, and MisusesResearch Track / Industrial Track at Megaron Beta Chair(s): Minhaz F. Zibran Idaho State University | ||
14:00 15mTalk | What You Trust Is Insecure: Demystifying How Developers (Mis)Use Trusted Execution Environments in Practice Research Track Yuqing Niu , Jieke Shi Singapore Management University, Ruidong Han Singapore Management University, Ye Liu Singapore Management University, Chengyan Ma Singapore Management University, Yunbo Lyu Singapore Management University, David Lo Singapore Management University Pre-print | ||
14:15 15mTalk | From Patterns to Precision: LLM-Guided Detection of Signature Verification Flaws in Smart Contracts Research Track | ||
14:30 15mTalk | SeBERTis: A Framework for Producing Classifiers of Security-Related Issue Reports Research Track Sogol Masoumzadeh Mcgill University, Yufei Li McGill University, Shane McIntosh University of Waterloo, Daniel Varro Linköping University / McGill University, Lili Wei McGill University | ||
14:45 15mTalk | MLmisFinder: A Specification and Detection Approach of Machine Learning Service Misuses Research Track Hadil Ben Amor Ecole de Technologie Supérieure, Niruthiha Selvanayagam Ecole de Technologie Supérieure, Manel Abdellatif École de Technologie Supérieure, Taher A. Ghaleb Trent University, Naouel Moha École de Technologie Supérieure (ETS) | ||
15:00 15mTalk | VulTerminator: Bringing Back Template-Based Automated Repair for Fixing Java Vulnerabilities Research Track Quang-Cuong Bui Hamburg University of Technology, Emanuele Iannone Hamburg University of Technology, Riccardo Scandariato Hamburg University of Technology Pre-print | ||
15:15 15mTalk | From Legacy Designs to Vulnerability Fixes: Understanding SAST Adoption in Non-Technological Companies Industrial Track Luis Henrique Vieira Amaral University of Brasília, Brazil, Michael Schlichtig Heinz Nixdorf Institut, Paderborn University, Wagner Emanuel , Joilton Almeida de Jesus , Carine Ferreira , Jérôme Kempf , Rodrigo Bonifácio Informatics Center - CIn/UFPE and Computer Science Department / University of Brasília, Eric Bodden Heinz Nixdorf Institute at Paderborn University & Fraunhofer IEM, Laerte Peotta University of Brasília, Brazil, Gustavo Pinto Zup Innovation & UFPA, Márcio Ribeiro Federal University of Alagoas, Brazil | ||