提升粒子对撞机时间序列分类的抗干扰能力,保障晶体准直器对齐精度。
Adversarial Robustness of Time-Series Classification for Crystal Collimator Alignment
- 设计轻量可微分预处理封装,兼容真实部署流程中的归一化与扰动约束。
- 对抗微调使模型鲁棒准确率提升18.6%,且不影响原始准确率。
- 首次实现滑动窗口下序列级鲁棒性分析,发现跨窗口持续误判现象。
本文分析并改进了用于大型强子对撞机(LHC)晶体准直器对齐的卷积神经网络(CNN)在时间序列分类任务中的对抗鲁棒性。该模型基于束流损失监测器(BLM)在晶体旋转过程中的时间序列数据进行分类。我们基于真实场景合理性,形式化了一种局部鲁棒性定义。借鉴已有的参数化输入变换模式,构建了一个面向部署流水线的预处理感知封装:将时间序列归一化、填充约束和结构化扰动编码为轻量级可微分前缀,使现有基于梯度的鲁棒性框架能作用于实际运行环境。由于依赖数据的预处理(如每窗z-score归一化)引入非线性算子,需验证器特异性抽象,因此本文聚焦于基于攻击的鲁棒性评估与流水线有效性验证,使用Foolbox和ART框架进行基准测试。对抗微调使模型鲁棒准确率最高提升18.6%,且未降低干净准确率。最后,将时间序列鲁棒性从单窗口扩展至全扫描序列级别,提出对抗序列作为时序鲁棒性要求的反例,并观察到攻击引发的误分类在相邻窗口间持续存在。
原文摘要 · Abstract (English)
In this paper, we analyze and improve the adversarial robustness of a convolutional neural network (CNN) that assists crystal-collimator alignment at CERN's Large Hadron Collider (LHC) by classifying a beam-loss monitor (BLM) time series during crystal rotation. We formalize a local robustness property for this classifier under an adversarial threat model based on real-world plausibility. Building on established parameterized input-transformation patterns used for transformation- and semantic-perturbation robustness, we instantiate a preprocessing-aware wrapper for our deployed time-series pipeline: we encode time-series normalization, padding constraints, and structured perturbations as a lightweight differentiable wrapper in front of the CNN, so that existing gradient-based robustness frameworks can operate on the deployed pipeline. For formal verification, data-dependent preprocessing such as per-window z-normalization introduces nonlinear operators that require verifier-specific abstractions. We therefore focus on attack-based robustness estimates and pipeline-checked validity by benchmarking robustness with the frameworks Foolbox and ART. Adversarial fine-tuning of the resulting CNN improves robust accuracy by up to 18.6 % without degrading clean accuracy. Finally, we extend robustness on time-series data beyond single windows to sequence-level robustness for sliding-window classification, introduce adversarial sequences as counterexamples to a temporal robustness requirement over full scans, and observe attack-induced misclassifications that persist across adjacent windows.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。