提出FABLE攻击框架,精准操控气象预测模型输出。
FABLE: A Localized, Targeted Adversarial Attack on Weather Forecasting Models
- 通过3D小波分解分离时空特征,实现精准扰动
- 扰动后模型预测偏离原结果,仍保持数据自然性
- 适合研究模型安全性的研究人员使用
基于深度学习的气象预测(DLWF)模型近期在性能上显著超越传统物理模拟工具。然而,这些模型可能面临对抗攻击威胁,引发对其可信度的担忧。本文研究了现有对抗攻击方法在DLWF模型上的可行性与挑战,并提出一种新框架FABLE(Forecast Alteration By Localized targeted advErsarial attack)。FABLE通过3D离散小波分解,分离数据的时空成分,通过调控不同成分的对抗扰动幅度,生成与原始输入高度一致但能引导模型产生目标预测结果的对抗样本。在真实气象数据集上的实验表明,FABLE在多种指标上均优于基线方法。
原文摘要 · Abstract (English)
Deep learning-based weather forecasting (DLWF) models have recently demonstrated significant performance gains over gold-standard physics-based simulation tools. However, these models are potentially vulnerable to adversarial attacks, which raises concerns about their trustworthiness. In this paper, we investigate the feasibility and challenges of applying existing adversarial attack methods to DLWF models and propose a novel framework called FABLE (Forecast Alteration By Localized targeted advErsarial attack) to address them. FABLE performs a 3D discrete wavelet decomposition to disentangle the spatial and temporal components of the data. By regulating the magnitude of adversarial perturbations across different components, FABLE produces adversarial inputs that remain closely aligned with the original inputs while steering the DLWF models toward generating the targeted forecast outcomes. Experimental results on real-world weather datasets demonstrate the effectiveness of FABLE over baseline methods across various metrics.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。