TSFMs虽预测能力强,但极易被微小干扰误导,需强化防御才能安全部署。
Are Time-Series Foundation Models Deployment-Ready? A Systematic Study of Adversarial Robustness Across Domains
- 针对时序特性设计了抗干扰评估框架,考虑扰动稀疏性和尺度不变性。
- 六种主流模型在微小扰动下均出现趋势反转等严重错误,且越长上下文越脆弱。
- 简单对抗训练即可显著提升鲁棒性,适合实际部署场景快速加固。
时序基础模型(TSFMs)正从研究原型快速转向关键决策系统的核心组件,得益于其出色的零样本预测能力。然而,随着部署加速,一个关键盲点浮现:它们在对抗攻击下的脆弱性。这种忽视可能带来严重风险,尤其在易受操控的高风险环境中。本文提出系统性诊断研究,论证对于TSFMs而言,鲁棒性并非次要指标,而是可信赖部署的先决条件,与准确性同等重要。评估框架专门针对时序数据特性设计,包含归一化、稀疏感知的扰动预算及白盒与黑盒设置下的统一尺度不变指标。在六种代表性TSFMs上,我们发现当前架构极为脆弱:极小扰动即可可靠引导预测进入特定失败模式,如趋势翻转和恶意漂移。我们揭示了特有脆弱模式,包括临近预测时域的脆弱性、更长上下文窗口导致敏感度上升,以及跨模型迁移能力弱,表明故障模式具有模型特异性而非通用畸变。最后,我们证明简单的对抗微调即可在无需领域内数据的情况下实现显著鲁棒性提升。本研究弥合了TSFM能力与安全约束之间的差距,为打造下一代稳健预测系统提供关键指导。
原文摘要 · Abstract (English)
Time-Series Foundation Models (TSFMs) are rapidly transitioning from research prototypes to core components of critical decision-making systems, driven by their impressive zero-shot forecasting capabilities. However, as their deployment surges, a critical blind spot remains: their fragility under adversarial attacks. This lack of scrutiny poses severe risks, particularly as TSFMs enter high-stakes environments vulnerable to manipulation. We present a systematic, diagnostic study arguing that for TSFMs, robustness is not merely a secondary metric but a prerequisite for trustworthy deployment comparable to accuracy. Our evaluation framework, explicitly tailored to the unique constraints of time series, incorporates normalized, sparsity-aware perturbation budgets and unified scale-invariant metrics across white-box and black-box settings. Across six representative TSFMs, we demonstrate that current architectures are alarmingly brittle: even small perturbations can reliably steer forecasts toward specific failure modes, such as trend flips and malicious drifts. We uncover TSFM-specific vulnerability patterns, including horizon-proximal brittleness, increased susceptibility with longer context windows, and weak cross-model transfer that points to model-specific failure modes rather than generic distortions. Finally, we show that simple adversarial fine-tuning offers a cost-effective path to substantial robustness gains, even with out-of-domain data. This work bridges the gap between TSFM capabilities and safety constraints, offering essential guidance for hardening the next generation of forecasting systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。