arXiv:2511.19330cs.LG2025-11被引 1

提出两种新攻击方法,可让金融时间序列预测的走势翻倍

Targeted Manipulation: Slope-Based Attacks on Financial Time-Series Data

  • 基于斜率设计攻击,直接操纵模型预测趋势
  • 使预测斜率翻倍,且能绕过检测机制
  • 适合关注模型安全与全链路防护的研究者

针对深度学习模型的对抗攻击在图像领域已深入研究,但在时间序列尤其是金融数据预测领域仍较少。本文在N-HiTS模型基础上,提出两种新的斜率攻击方法——通用斜率攻击与最小二乘斜率攻击,可使预测趋势斜率翻倍。相比正常预测,这两种方法能有效绕过4层CNN构成的判别器,使其特异性降至28%、准确率降至57%。此外,该攻击被集成至GAN架构中,用于生成逼真的合成数据并欺骗模型。最后,本文还设计了一种样本恶意软件,可注入模型推理库实施攻击,表明机器学习安全需兼顾模型与整个系统管道。

原文摘要 · Abstract (English)

A common method of attacking deep learning models is through adversarial attacks, which occur when an attacker specifically modifies the input of a model to produce an incorrect result. Adversarial attacks have been deeply investigated in the image domain; however, there is less research in the time-series domain and very little for forecasting financial data. To address these concerns, this study aims to build upon previous research on adversarial attacks for time-series data by introducing two new slope-based methods aimed to alter the trends of the predicted stock forecast generated by an N-HiTS model. Compared to the normal N-HiTS predictions, the two new slope-based methods, the General Slope Attack and Least-Squares Slope Attack, can manipulate N-HiTS predictions by doubling the slope. These new slope attacks can bypass standard security mechanisms, such as a discriminator that filters real and perturbed inputs, reducing a 4-layered CNN's specificity to 28% and accuracy to 57%. Furthermore, the slope based methods were incorporated into a GAN architecture as a means of generating realistic synthetic data, while simultaneously fooling the model. Finally, this paper also proposes a sample malware designed to inject an adversarial attack in the model inference library, proving that ML-security research should not only focus on making the model safe, but also securing the entire pipeline.

对抗攻击金融预测时间序列模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。