arXiv:2604.03427cs.LGcs.SY2026-04

提出对抗鲁棒性设计新框架,揭示模型不稳定与维度对攻击敏感性的放大机制。

Adversarial Robustness of Deep State Space Models for Forecasting

  • 从控制论出发,将鲁棒预测建模为对抗者与预测器的斯塔克尔伯格博弈。
  • 推导出对抗误差的闭式上界,发现开环/闭环不稳定性及解码器维度会加剧脆弱性。
  • 无需梯度计算的模型无关攻击可使误差提升33%以上,适合关注安全性的部署者。

时序预测中的状态空间模型(SSM)在基准数据集上表现出色,但其在对抗扰动下的鲁棒性尚不清楚。本文从控制论视角研究最近提出的Spacetime SSM预测器,首先证明仅解码器结构的Spacetime架构在自回归生成过程下可表示最优卡尔曼预测器——这是其他SSM不具备的性质。基于此,将鲁棒预测器设计建模为对抗者受检测预算约束的最坏情况隐秘对手的斯塔克尔伯格博弈,并通过对抗训练求解。推导出对抗预测误差的闭式上界,揭示了开环不稳定性、闭环不稳定性以及解码器状态维度如何放大脆弱性,为鲁棒设计提供可操作原则。最后,实验表明,即使对手无法访问预测器,也可通过利用模型局部线性输入输出特性构造有效攻击,完全绕过梯度计算。在Monash基准数据集上的实验显示,无梯度的模型无关攻击造成的误差比小步长投影梯度下降高出至少33%。

原文摘要 · Abstract (English)

State-space model (SSM) for time-series forecasting have demonstrated strong empirical performance on benchmark datasets, yet their robustness under adversarial perturbations is poorly understood. We address this gap through a control-theoretic lens, focusing on the recently proposed Spacetime SSM forecaster. We first establish that the decoder-only Spacetime architecture can represent the optimal Kalman predictor when the underlying data-generating process is autoregressive - a property no other SSM possesses. Building on this, we formulate robust forecaster design as a Stackelberg game against worst-case stealthy adversaries constrained by a detection budget, and solve it via adversarial training. We derive closed-form bounds on adversarial forecasting error that expose how open-loop instability, closed-loop instability, and decoder state dimension each amplify vulnerability - offering actionable principles towards robust forecaster design. Finally, we show that even adversaries with no access to the forecaster can nonetheless construct effective attacks by exploiting the model's locally linear input-output behavior, bypassing gradient computations entirely. Experiments on the Monash benchmark datasets highlight that model-free attacks, without any gradient computation, can cause at least 33% more error than projected gradient descent with a small step size.

状态空间模型对抗鲁棒性时间序列预测控制论

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。