arXiv:2607.27604cs.CRcs.AI2026-07

针对交通预测图模型的攻击,提出物理感知检测新方法。

Revisiting the Adversarial Robustness of Graph-Based Traffic Forecasting

论文配图:Revisiting the Adversarial Robustness of Graph-Based Traffic Forecasting
图 1 · 摘自论文原文
  • 设计可定位攻击的物理感知检测器,识别局部传感器干扰
  • 在15组实验中,新方法在13组上显著降低目标链路误差
  • 适合关注交通系统安全的工程与研究者使用

基于图的交通预测是智能交通系统的关键,但现有鲁棒性评估受不切实际威胁模型影响。本文研究具备有限模型知识、仅操控少数道路传感器的现实攻击者,其攻击可局部化于特定路段或路线,引发错误到达时间估计或无谓绕行,同时不影响整体网络。传统对抗训练对这类结构化、物理感知攻击无效。因此,将鲁棒性重构为检测问题,引入学习型物理感知检测器,输出作为硬化预测器的输入特征,并在固定预测器条件下对抗自适应攻击进行训练。在多种模型架构与基准测试中,物理感知攻击使目标链路误差增加数倍,而全局误差变化极小;对抗训练在范数约束攻击下有效,但对本类攻击几乎无效。所提检测-缓解方案在15组设置中的13组表现更优,且在留出攻击上提升最显著,清洁数据代价接近零。结果强调需在应用具体约束下评估抽象对抗攻击的真实安全影响。

原文摘要 · Abstract (English)

Traffic forecasting by graph-based AI is a critical component of intelligent transportation systems, motivating security research on robustness to malicious sensor readings. We argue that prior robustness evaluations are largely shaped by unrealistic threat models and untargeted objectives, so both attacks and defenses must be revisited. We study a practical adversary with limited model knowledge and the ability to monitor and manipulate only a few road sensors. More importantly, practical attacks can be localized to specific links or routes, causing incorrect estimated arrival times or unnecessary rerouting while leaving the broader network largely unaffected. This targeted setting remains underexplored, and defenses such as adversarial training do not transfer well from the norm-bounded attacks they train on to structurally different, physics-aware attacks that mimic genuine congestion. We therefore reframe robustness as a detection problem, introducing a learned physics-informed detector whose output is fed to a hardened forecaster as an input feature and trained against adaptive attacks with the forecaster fixed. We evaluate across a variety of model architectures and benchmarks. The physics-aware attack multiplies target-link error several-fold while the network-wide error barely moves, and adversarial training, tuned to norm-bounded perturbations, barely dents it. Our detection--mitigation defense improves even on adversarial training hardened against the physics-aware attack itself, on $13$ of $15$ model--dataset settings and by the widest margin on a held-out attack, at near-zero clean cost. The results emphasize the need to examine abstracted AI adversarial attacks under application-specific constraints to assess their true security impacts.

交通预测图神经网络对抗攻击物理感知

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。