arXiv:2504.20295cs.LGcs.AI2025-04

揭露数字孪生水网预测模型的漏洞,展示攻击如何让误差飙升至35%以上

The Dark Side of Digital Twins: Adversarial Attacks on AI-Driven Water Forecasting

  • 用学习自动机动态调整干扰,让攻击更隐蔽
  • 攻击使预测误差从26%升至35%以上
  • 适合关注智能水务安全的工程师与研究者

数字孪生(DT)通过实时数据、分析和预测模型优化供水系统。本文构建了一个基于西班牙供水网络的DT平台,采用长短期记忆(LSTM)网络预测用水量。然而,机器学习模型易受对抗攻击,如快速梯度符号法(FGSM)和投影梯度下降(PGD)。这些攻击通过微调关键参数,引入细微扰动,降低预测准确性。为此,我们提出一种基于学习自动机(LA)及随机LA的方法,动态调节扰动,使攻击更难被发现。实验表明,该方法显著影响预测可靠性,导致平均绝对百分比误差(MAPE)从26%上升至35%以上。自适应攻击策略进一步放大此效应,凸显了AI驱动数字孪生系统的网络安全风险。亟需强化防御措施,包括对抗训练、异常检测和安全数据管道。

原文摘要 · Abstract (English)

Digital twins (DTs) are improving water distribution systems by using real-time data, analytics, and prediction models to optimize operations. This paper presents a DT platform designed for a Spanish water supply network, utilizing Long Short-Term Memory (LSTM) networks to predict water consumption. However, machine learning models are vulnerable to adversarial attacks, such as the Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD). These attacks manipulate critical model parameters, injecting subtle distortions that degrade forecasting accuracy. To further exploit these vulnerabilities, we introduce a Learning Automata (LA) and Random LA-based approach that dynamically adjusts perturbations, making adversarial attacks more difficult to detect. Experimental results show that this approach significantly impacts prediction reliability, causing the Mean Absolute Percentage Error (MAPE) to rise from 26% to over 35%. Moreover, adaptive attack strategies amplify this effect, highlighting cybersecurity risks in AI-driven DTs. These findings emphasize the urgent need for robust defenses, including adversarial training, anomaly detection, and secure data pipelines.

数字孪生对抗攻击水网预测AI安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。