Affiliation:
1. Department of Computer Science and Engineering, Shanghai Jiao Tong University, Shanghai 200240, China
2. Blockchain Advanced Research Center, Shanghai Jiao Tong University, Wuxi 214104, China
Abstract
While deep neural networks (DNNs) have been widely and successfully used for time series classification (TSC) over the past decade, their vulnerability to adversarial attacks has received little attention. Most existing attack methods focus on white-box setups, which are unrealistic as attackers typically only have access to the model’s probability outputs. Defensive methods also have limitations, relying primarily on adversarial retraining which degrades classification accuracy and requires excessive training time. On top of that, we propose two new approaches in this paper: (1) A simulated annealing-based random search attack that finds adversarial examples without gradient estimation, searching only on the l∞-norm hypersphere of allowable perturbations. (2) A post-processing defense technique that periodically reverses the trend of corresponding loss values while maintaining the overall trend, using only the classifier’s confidence scores as input. Experiments applying these methods to InceptionNet models trained on the UCR dataset benchmarks demonstrate the effectiveness of the attack, achieving up to 100% success rates. The defense method provided protection against up to 91.24% of attacks while preserving prediction quality. Overall, this work addresses important gaps in adversarial TSC by introducing novel black-box attack and lightweight defense techniques.
Funder
Shanghai Science and Technology Innovation Action Plan
Reference27 articles.
1. Wang, Z., Yan, W., and Oates, T. (2017, January 14–19). Time series classification from scratch with deep neural networks: A strong baseline. Proceedings of the 2017 International Joint Conference on Neural Networks (IJCNN), Anchorage, AK, USA.
2. Ismail Fawaz, H., Forestier, G., Weber, J., Idoumghar, L., and Muller, P.A. (2019, January 14–19). Adversarial Attacks on Deep Neural Networks for Time Series Classification. Proceedings of the 2019 International Joint Conference on Neural Networks (IJCNN), Budapest, Hungary.
3. Inceptiontime: Finding alexnet for time series classification;Lucas;Data Min. Knowl. Discov.,2020
4. Zhang, X., Gao, Y., Lin, J., and Lu, C.T. (2020, January 7–12). Tapnet: Multivariate time series classification with attentional prototypical network. Proceedings of the AAAI Conference on Artificial Intelligence, New York, NY, USA.
5. Adversarial attack on attackers: Post-process to mitigate black-box score-based query attacks;Chen;Adv. Neural Inf. Process. Syst.,2022
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献