arXiv:2604.11928cs.LGcs.CR2026-04

针对时间序列预测的实时攻击框架,精准打击高置信度时刻,提升攻击效率。

INTARG: Informed Real-Time Adversarial Attack Generation for Time-Series Regression

  • 基于模型置信度和误差预测,选择性攻击关键时间点。
  • 攻击仅在不足10%时间步进行,却使预测误差提升2.42倍。
  • 适用于对实时性与隐蔽性要求高的系统安全评估。

时间序列预测通过建模历史观测中的时序依赖关系来预测未来值,是众多现实系统的核心组件,准确预测可提升运营效率并降低不确定性和风险。近年来,机器学习尤其是深度学习模型广泛应用于时间序列预测,但其仍易受对抗攻击影响。然而,许多先进攻击方法不适用于时间序列场景,因完整存储历史数据或在每个时间步攻击常不切实际。本文提出一种面向在线有界缓冲区设置的时间序列预测对抗攻击框架,采用知情且选择性的攻击策略。通过聚焦模型置信度高且预期预测误差最大的时间步,该框架以更少攻击次数实现显著更高破坏力。实验表明,本框架可在不到10%的时间步进行攻击的情况下,使预测误差最高提升2.42倍。

原文摘要 · Abstract (English)

Time-series forecasting aims to predict future values by modeling temporal dependencies in historical observations. It is a critical component of many real-world systems, where accurate forecasts improve operational efficiency and help mitigate uncertainty and risk. More recently, machine learning (ML), and especially deep learning (DL)-based models, have gained widespread adoption for time-series forecasting, but they remain vulnerable to adversarial attacks. However, many state-of-the-art attack methods are not directly applicable in time-series settings, where storing complete historical data or performing attacks at every time step is often impractical. This paper proposes an adversarial attack framework for time-series forecasting under an online bounded-buffer setting, leveraging an informed and selective attack strategy. By selectively targeting time steps where the model exhibits high confidence and the expected prediction error is maximal, our framework produces fewer but substantially more effective attacks. Experiments show that our framework can increase the prediction error up to 2.42x, while performing attacks in fewer than 10% of time steps.

时间序列对抗攻击实时生成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。