arXiv:2512.13207cs.LGcs.CR2025-12被引 2

研究联邦学习在气温预测中如何被恶意客户端攻击,发现小部分污染数据可引发大范围预测偏差。

Evaluating Adversarial Attacks on Federated Learning for Temperature Forecasting

  • 模拟多地客户端,测试局部与全局攻击对气温预测的影响
  • 单个客户端攻击使预测偏差达-1.7K,协同攻击误差翻超三倍
  • 基于均值裁剪的防御对局部攻击无效,适合应对全局偏差

深度学习与联邦学习(FL)正成为下一代气象预报的重要组合。深度学习可实现高分辨率时空预测,超越传统数值模型;而联邦学习使不同地区机构能在不共享原始数据的前提下协作训练,兼顾效率与安全。然而,其分布式特性引入新风险:数据投毒攻击中,受损客户端注入伪造训练数据,导致模型性能下降或引入系统性偏差。此类威胁因气象数据的空间相关性而加剧,局部扰动可通过全局聚合影响广泛区域。本研究以欧洲区域再分析(CERRA)数据集为基础,评估联邦表面气温预测中对抗性客户端的影响。通过模拟地理分布的客户端,测试基于补丁和全局偏移的攻击策略。结果表明,少量污染客户端即可误导大范围区域预测:单个客户端发起的全局温度偏移攻击使预测值降低最多达-1.7 K;协同补丁攻击使均方误差增加超过三倍,并产生持续超过+3.5 K的区域性异常。最后评估了裁剪均值聚合作为防御机制的效果,发现其可有效抵御全局偏移攻击(性能下降2%-13%),但对补丁攻击无效(误差放大281%-603%),揭示基于异常值剔除的防御在空间相关数据中的局限性。

原文摘要 · Abstract (English)

Deep learning and federated learning (FL) are becoming powerful partners for next-generation weather forecasting. Deep learning enables high-resolution spatiotemporal forecasts that can surpass traditional numerical models, while FL allows institutions in different locations to collaboratively train models without sharing raw data, addressing efficiency and security concerns. While FL has shown promise across heterogeneous regions, its distributed nature introduces new vulnerabilities. In particular, data poisoning attacks, in which compromised clients inject manipulated training data, can degrade performance or introduce systematic biases. These threats are amplified by spatial dependencies in meteorological data, allowing localized perturbations to influence broader regions through global model aggregation. In this study, we investigate how adversarial clients distort federated surface temperature forecasts trained on the Copernicus European Regional ReAnalysis (CERRA) dataset. We simulate geographically distributed clients and evaluate patch-based and global biasing attacks on regional temperature forecasts. Our results show that even a small fraction of poisoned clients can mislead predictions across large, spatially connected areas. A global temperature bias attack from a single compromised client shifts predictions by up to -1.7 K, while coordinated patch attacks more than triple the mean squared error and produce persistent regional anomalies exceeding +3.5 K. Finally, we assess trimmed mean aggregation as a defense mechanism, showing that it successfully defends against global bias attacks (2-13% degradation) but fails against patch attacks (281-603% amplification), exposing limitations of outlier-based defenses for spatially correlated data.

联邦学习天气预测对抗攻击数据安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。