arXiv:2505.02073cs.LGcs.AI2025-05KDD

提出轻量级时间序列防御方法,比传统训练快3倍以上

Lightweight Defense Against Adversarial Attacks in Time Series Classification

  • 用五种数据增强法构建轻量防御,计算开销仅增14.07%
  • 集成方法防御效果超PGD攻击训练,且计算资源不足其1/3
  • 适合部署在资源受限的时序分类系统中

随着时间序列分类(TSC)应用日益广泛,确保模型对抗对抗攻击的鲁棒性至关重要。尽管计算机视觉领域对抗防御研究成熟,但时间序列领域仍主要依赖计算成本高昂的对抗训练(AT)。本文提出五种面向时间序列的数据增强型防御方法,其中最耗时的方法相比原模型仅增加14.07%的计算资源。此外,这些方法部署简单。基于此,我们设计了两种组合策略,其中一种为所有提议技术的集成,不仅防御效果优于基于PGD的对抗训练,还提升了模型泛化能力。更重要的是,该集成方法所需计算资源不到PGD-AT的三分之一。本工作推动了数据挖掘中的鲁棒时间序列分类发展。同时,随着基础模型在时间序列特征学习中的兴起,我们的研究也为未来将数据增强型对抗防御与大规模预训练模型结合提供了思路。

原文摘要 · Abstract (English)

As time series classification (TSC) gains prominence, ensuring robust TSC models against adversarial attacks is crucial. While adversarial defense is well-studied in Computer Vision (CV), the TSC field has primarily relied on adversarial training (AT), which is computationally expensive. In this paper, five data augmentation-based defense methods tailored for time series are developed, with the most computationally intensive method among them increasing the computational resources by only 14.07% compared to the original TSC model. Moreover, the deployment process for these methods is straightforward. By leveraging these advantages of our methods, we create two combined methods. One of these methods is an ensemble of all the proposed techniques, which not only provides better defense performance than PGD-based AT but also enhances the generalization ability of TSC models. Moreover, the computational resources required for our ensemble are less than one-third of those required for PGD-based AT. These methods advance robust TSC in data mining. Furthermore, as foundation models are increasingly explored for time series feature learning, our work provides insights into integrating data augmentation-based adversarial defense with large-scale pre-trained models in future research.

时间序列对抗防御轻量级数据增强

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。