针对连续时间事件序列模型,提出可微分的对抗攻击方法。
Differentiable Adversarial Attacks for Marked Temporal Point Processes
- 通过打乱事件顺序并加噪时间戳,实现对事件序列的隐蔽扰动。
- 在4个真实数据集上成功攻击MTPP模型,且推理速度更快。
- 适合研究模型鲁棒性或防御机制的研究者参考。
标记的连续时间点过程(MTPP)在建模连续时间事件序列(CTES)方面表现出色。本文针对MTPP模型设计了专门的对抗攻击方法。良好的对抗攻击需具备不可察觉性,但传统基于$ L_p $范数的扰动约束在具有时序特性和不同时间尺度的CTES中难以直接应用。为此,我们首先对事件进行重排,再向到达时间戳添加噪声。然而,此类攻击的最坏情况优化是计算复杂的组合问题,需在长度为输入序列的排列空间中搜索,该空间随序列长度呈阶乘增长。为此,我们提出新型可微分方案PERMTPP,通过学习最小化似然同时控制两段CTES间的距离,实现高效攻击。在四个真实数据集上的实验表明,PERMTPP兼具攻击有效性与防御能力,且推理时间更短。
原文摘要 · Abstract (English)
Marked temporal point processes (MTPPs) have been shown to be extremely effective in modeling continuous time event sequences (CTESs). In this work, we present adversarial attacks designed specifically for MTPP models. A key criterion for a good adversarial attack is its imperceptibility. For objects such as images or text, this is often achieved by bounding perturbation in some fixed $L_p$ norm-ball. However, similarly minimizing distance norms between two CTESs in the context of MTPPs is challenging due to their sequential nature and varying time-scales and lengths. We address this challenge by first permuting the events and then incorporating the additive noise to the arrival timestamps. However, the worst case optimization of such adversarial attacks is a hard combinatorial problem, requiring exploration across a permutation space that is factorially large in the length of the input sequence. As a result, we propose a novel differentiable scheme PERMTPP using which we can perform adversarial attacks by learning to minimize the likelihood, while minimizing the distance between two CTESs. Our experiments on four real-world datasets demonstrate the offensive and defensive capabilities, and lower inference times of PERMTPP.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。