AI天气预报系统存安全漏洞,微小数据干扰可伪造极端天气
Adversarial Observations in Weather Forecasting
- 通过细微扰动气象观测数据,攻击扩散模型预测结果
- 扰动小于0.1%测量值,却能生成虚假飓风等极端天气
- 适用于关注AI安全、气象系统防御的研究者
基于AI的系统(如Google的GenCast)已大幅改进天气预报精度与时效性,覆盖日常天气及极端事件。然而,这类系统正引入新安全隐患。本文研究此类威胁,提出针对自回归扩散模型(如GenCast所用)的新攻击方法,可操纵天气预测并虚构极端天气事件(如飓风、热浪、强降雨)。攻击在气象观测中引入微小扰动,统计上与自然噪声无异,改变量不足0.1%的测量值,相当于篡改单一气象卫星数据。现代预报融合近百家卫星及多国数据源,本研究揭示了潜在大规模破坏风险,可能引发系统性误判并动摇公众对预报的信任。
原文摘要 · Abstract (English)
AI-based systems, such as Google's GenCast, have recently redefined the state of the art in weather forecasting, offering more accurate and timely predictions of both everyday weather and extreme events. While these systems are on the verge of replacing traditional meteorological methods, they also introduce new vulnerabilities into the forecasting process. In this paper, we investigate this threat and present a novel attack on autoregressive diffusion models, such as those used in GenCast, capable of manipulating weather forecasts and fabricating extreme events, including hurricanes, heat waves, and intense rainfall. The attack introduces subtle perturbations into weather observations that are statistically indistinguishable from natural noise and change less than 0.1% of the measurements - comparable to tampering with data from a single meteorological satellite. As modern forecasting integrates data from nearly a hundred satellites and many other sources operated by different countries, our findings highlight a critical security risk with the potential to cause large-scale disruptions and undermine public trust in weather prediction.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。