---
格式版本: 2
标题: "Computer Science > Artificial Intelligence"
原文链接: "https://arxiv.org/abs/2608.18900"
发布日期: "2026-08-19"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Wed, 19 Aug 2026 13:25:50 UTC (13,412 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T16:01:48+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T15:56:53+08:00"
入库时间: "2026-08-20T08:01:48.123Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=AI&searchtype=all"
匹配关键词:
  - "AI"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 8
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "该资料为arXiv论文，主题是深度学习系统鲁棒性测试，与超节点/AI Rack/机柜级AI基础设施、供电散热互连或量产落地完全无关，仅命中‘AI’泛词，判为无关。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T16:08:29+08:00"
AI主题相关性: 0
AI来源权威性: 5
AI新颖性: 1
AI技术细节: 2
AI商业部署信号: 0
AI完整性: 0
AI摘要: "TestifAI 是一个面向深度学习系统的鲁棒性测试框架，通过部分模型断层扫描技术，仅用低阶（1–2 种）扰动测试结果预测高阶（3–4 种）组合扰动下的模型表现。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:18:33.752Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.18900"
---

## Title:\\textsc{TestifAI}: Tomography-Based Testing for Deep Learning Systems

[View PDF](https://arxiv.org/pdf/2608.18900) [HTML (experimental)](https://arxiv.org/html/2608.18900v1)

> Abstract:As AI systems are increasingly deployed in safety-critical application domains (e.g., autonomous driving), associated risks increase too. Deep learning models underlying modern AI systems, therefore, must undergo thorough testing to ensure their correct behaviour. A single robustness test involves thousands of inferences to empirically verify if a model's outputs remain stable under a bounded perturbation of its inputs. However, existing testing frameworks lack the means to systematically explore and summarise robustness across a combinatorial space of perturbations.  
> We propose TestifAI, a deep learning testing framework for efficient and accurate estimation of robustness against combinations of perturbations. TestifAI enables users to specify operational conditions as structured spaces of semantic input perturbations (e.g., image blur, brightness and zoom) and discrete severity levels (e.g., low, medium and high). Users can query model robustness for any combination (e.g., "low blur, high brightness, and medium zoom"). To achieve efficiency and accuracy, TestifAI introduces partial model tomography, a novel approach to reconstructing model behaviour in a multi-perturbation space from tests that apply only a small number of perturbations (lower-order projections). To estimate robustness against at least three perturbations, TestifAI trains an auxiliary model on the results of tests involving up to two perturbations only, avoiding execution of an exponential number of tests. Our experiments on five image and language classification tasks show that TestifAI can predict higher-order (3 and 4 perturbations) test outcomes from low-order (1 and 2 perturbations) observations with an aggregate robustness estimation error of less than 7%, while reducing the number of inferences by 60-80%.

| Subjects: | Artificial Intelligence (cs.AI) |
| --- | --- |
| Cite as: | [arXiv:2608.18900](https://arxiv.org/abs/2608.18900) \[cs.AI\] |
|  | (or [arXiv:2608.18900v1](https://arxiv.org/abs/2608.18900v1) \[cs.AI\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.18900](https://doi.org/10.48550/arXiv.2608.18900) |

## Submission history

From: Elena Botoeva \[[view email](https://arxiv.org/show-email/b09c8843/2608.18900)\]  
**\[v1\]** Wed, 19 Aug 2026 13:25:50 UTC (13,412 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.18900) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
