arXiv:2606.17435cs.LG2026-06

通过分层随机扰动生成对抗鲁棒的时序模型,成本极低且效果显著。

MorphStrata: Layer-Specific Perturbations for Generating Morphence Students in Time-Series Moving Target Defense

论文配图:MorphStrata: Layer-Specific Perturbations for Generating Morphence Students in Time-Series Moving Target Defense
图 1 · 摘自论文原文
  • 选择性地在Transformer各层注入噪声,生成结构异质的学生模型。
  • 在多个数据集上对抗攻击下,平均误差比基线低24.11%至97.97%。
  • 仅增加不足1%训练时间,适合高安全需求的实时防御场景。

时序预测模型易受基于梯度的对抗攻击,现有防御机制常在鲁棒性、响应速度与计算开销间权衡。移动目标防御(MTD)中维持多个随机化模型实例会大幅增加训练负担。本文提出MorphStrata,一种基于Transformer教师模型的分层学生生成策略,通过随机选择架构块注入结构化噪声,提升学生模型间的异质性以应对多样数据分布和威胁模型。在Jena气候、电力负荷图谱及家用电器能耗预测等基准上,针对FGSM、BIM和PGD攻击测试,结果表明:在高熵周期性数据(如AEP)上,该集成方法在所有攻击强度下保持与基准相当的对抗均方根误差(RMSE)。尤其在ε=0.5时,相较静态基线,对抗性攻击下分别实现24.11%和97.97%的误差降低。生成学生模型的层级扰动使训练时间增加不足1%,同时带来两位数的鲁棒性增益。此外,学生间更高成对L2距离与整体防御效能呈正相关。总体而言,相较于现有基线,MorphStrata在边际成本增量下维持了强对抗鲁棒性。

原文摘要 · Abstract (English)

Time-series forecasting models remain vulnerable to gradient-based adversarial attacks while existing defense mechanisms typically incur a trade-off in robustness for bounded response and compute cost. The problem is pronounced in Moving Target Defense where maintaining multiple randomized model instances substantially exacerbates the training overhead. In this work, we introduce MorphStrata, a student generation strategy with selective, layer-specific stochastic noise injection that extends the traditional Morphence defense. MorphStrata uses a Transformer backbone as the teacher and perturbs randomly selected architectural blocks to create structured heterogeneity across student models in response to varied data distributions and threat models. We evaluate against vanilla Transformer and Morphence backbones on a suite of benchmarks including the Jena Climate, Electricity Load Diagrams, and Appliances Energy Prediction using FGSM, BIM and PGD attacks across multiple attack strengths. Across datasets and attack regimes, the proposed ensemble maintains comparable adversarial RMSE. Specifically, for high entropy, periodic datasets as in the case of the AEP data, MorphStrata achieves the lowest RMSE across all attacks and perturbation budgets, improving over the static baseline by up to 24.11% and 97.97% under FGSM and BIM respectively at an epsilon value of 0.5 over 30 randomized trials. Targeting the layers to generate MorphStrata students accounts for less than 1% increase in train-times over the Morphence MTD baseline for most of the experiments, while accounting for double digit gains in adversarial RMSE reduction. We also observe a positive correlation between higher pairwise L2 distance (among generated students) and overall defense effectiveness. In summary, MorphStrata maintains adversarial robustness as an MTD defense at marginal cost deltas when compared to existing baselines.

时序防御对抗鲁棒模型异构轻量级

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。