arXiv:2509.04169cs.LG2025-09被引 3

提出针对时间序列预测模型的隐私攻击,发现用户级攻击几乎可完美识别训练数据。

Privacy Risks in Time Series Forecasting: User- and Record-Level Membership Inference

  • 将分类模型的成员推理攻击适配到时间序列场景,提出新方法DTS
  • 在真实数据集上验证,用户级攻击准确率接近100%
  • 适用于医疗信号等敏感时序数据的隐私评估,关注隐私风险的研究者必读

成员推理攻击(MIAs)旨在判断特定数据是否被用于模型训练。尽管在分类模型中已广泛研究,但其对时间序列预测的影响仍基本未被探索。本文填补这一空白,提出两种新攻击:(i) 将多变量LiRA(一种先进的分类模型攻击)适配至时间序列预测场景;(ii) 提出一种全新的端到端学习方法——深时序(DTS)攻击。我们在TUH-EEG和ELD数据集上,在真实设置下对这两种方法及其它分类领域主流攻击的适配版本进行基准测试,针对LSTM和最新N-HiTS两种强预测架构,评估记录级与用户级威胁模型下的性能。结果表明,预测模型存在显著隐私风险,用户级攻击常实现近乎完美的检测效果。所提方法在多个场景中表现最优,确立了时间序列预测隐私风险评估的新基线。此外,隐私脆弱性随预测范围拉长和训练样本减少而加剧,这一趋势与大语言模型中的观察一致。

原文摘要 · Abstract (English)

Membership inference attacks (MIAs) aim to determine whether specific data were used to train a model. While extensively studied on classification models, their impact on time series forecasting remains largely unexplored. We address this gap by introducing two new attacks: (i) an adaptation of multivariate LiRA, a state-of-the-art MIA originally developed for classification models, to the time-series forecasting setting, and (ii) a novel end-to-end learning approach called Deep Time Series (DTS) attack. We benchmark these methods against adapted versions of other leading attacks from the classification setting. We evaluate all attacks in realistic settings on the TUH-EEG and ELD datasets, targeting two strong forecasting architectures, LSTM and the state-of-the-art N-HiTS, under both record- and user-level threat models. Our results show that forecasting models are vulnerable, with user-level attacks often achieving perfect detection. The proposed methods achieve the strongest performance in several settings, establishing new baselines for privacy risk assessment in time series forecasting. Furthermore, vulnerability increases with longer prediction horizons and smaller training populations, echoing trends observed in large language models.

隐私攻击时序预测成员推理医疗数据

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。