arXiv:2512.08832cs.LG2025-12被引 3

提出可隐蔽扰动天气预测模型的新攻击方法

Forecasting Fails: Unveiling Evasion Attacks in Weather Prediction Models

  • 设计自适应扰动优化框架,确保扰动物理合理且难察觉
  • 在ERA5数据和FourCastNet上实现精准预测偏离目标
  • 揭示初始条件微小扰动可导致预报严重偏差

随着人工智能模型在天气预报中的广泛应用,评估其对对抗性扰动的脆弱性至关重要。本文提出天气自适应对抗扰动优化(WAAPO)框架,可生成既有效操纵预测结果又难以被检测的定向对抗扰动。该方法通过引入通道稀疏性、空间局部性和平滑性约束,确保扰动具有物理合理性且不易察觉。基于ERA5数据集与FourCastNet(Pathak et al. 2022)模型的实验表明,即使在约束条件下,WAAPO仍能生成与预设目标高度一致的对抗轨迹。实验揭示了当前AI驱动预报模型的关键漏洞:初始条件的微小扰动即可引发预测天气模式的显著偏差。这一发现凸显了在实际预报系统中构建鲁棒防护机制的紧迫性。

原文摘要 · Abstract (English)

With the increasing reliance on AI models for weather forecasting, it is imperative to evaluate their vulnerability to adversarial perturbations. This work introduces Weather Adaptive Adversarial Perturbation Optimization (WAAPO), a novel framework for generating targeted adversarial perturbations that are both effective in manipulating forecasts and stealthy to avoid detection. WAAPO achieves this by incorporating constraints for channel sparsity, spatial localization, and smoothness, ensuring that perturbations remain physically realistic and imperceptible. Using the ERA5 dataset and FourCastNet (Pathak et al. 2022), we demonstrate WAAPO's ability to generate adversarial trajectories that align closely with predefined targets, even under constrained conditions. Our experiments highlight critical vulnerabilities in AI-driven forecasting models, where small perturbations to initial conditions can result in significant deviations in predicted weather patterns. These findings underscore the need for robust safeguards to protect against adversarial exploitation in operational forecasting systems.

天气预测对抗攻击模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。