Square-Based Black-Box Adversarial Attack on Time Series Classification Using Simulated Annealing and Post-Processing-Based Defense

被引:1
|
作者
Liu, Sichen [1 ,2 ]
Luo, Yuan [1 ,2 ]
机构
[1] Shanghai Jiao Tong Univ, Dept Comp Sci & Engn, Shanghai 200240, Peoples R China
[2] Shanghai Jiao Tong Univ, Blockchain Adv Res Ctr, Wuxi 214104, Peoples R China
关键词
time series classification; adversarial attack; adversarial attack defense;
D O I
10.3390/electronics13030650
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While deep neural networks (DNNs) have been widely and successfully used for time series classification (TSC) over the past decade, their vulnerability to adversarial attacks has received little attention. Most existing attack methods focus on white-box setups, which are unrealistic as attackers typically only have access to the model's probability outputs. Defensive methods also have limitations, relying primarily on adversarial retraining which degrades classification accuracy and requires excessive training time. On top of that, we propose two new approaches in this paper: (1) A simulated annealing-based random search attack that finds adversarial examples without gradient estimation, searching only on the l(infinity)-norm hypersphere of allowable perturbations. (2) A post-processing defense technique that periodically reverses the trend of corresponding loss values while maintaining the overall trend, using only the classifier's confidence scores as input. Experiments applying these methods to InceptionNet models trained on the UCR dataset benchmarks demonstrate the effectiveness of the attack, achieving up to 100% success rates. The defense method provided protection against up to 91.24% of attacks while preserving prediction quality. Overall, this work addresses important gaps in adversarial TSC by introducing novel black-box attack and lightweight defense techniques.
引用
收藏
页数:13
相关论文
共 47 条
  • [1] Black-Box Adversarial Attack on Time Series Classification
    Ding, Daizong
    Zhang, Mi
    Feng, Fuli
    Huang, Yuanmin
    Jiang, Erling
    Yang, Min
    [J]. THIRTY-SEVENTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 37 NO 6, 2023, : 7358 - 7368
  • [2] TSadv: Black-box adversarial attack on time series with local perturbations
    Yang, Wenbo
    Yuan, Jidong
    Wang, Xiaokang
    Zhao, Peixiang
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2022, 114
  • [3] TSadv: Black-box adversarial attack on time series with local perturbations
    Yang, Wenbo
    Yuan, Jidong
    Wang, Xiaokang
    Zhao, Peixiang
    [J]. ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2022, 114
  • [4] Local perturbation-based black-box federated learning attack for time series classification
    Chen, Shengbo
    Yuan, Jidong
    Wang, Zhihai
    Sun, Yongqi
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2024, 158 : 488 - 500
  • [5] A low-query black-box adversarial attack based on transferability
    Ding, Kangyi
    Liu, Xiaolei
    Niu, Weina
    Hu, Teng
    Wang, Yanping
    Zhang, Xiaosong
    [J]. KNOWLEDGE-BASED SYSTEMS, 2021, 226
  • [6] An adversarial attack on DNN-based black-box object detectors
    Wang, Yajie
    Tan, Yu-an
    Zhang, Wenjiao
    Zhao, Yuhang
    Kuang, Xiaohui
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2020, 161
  • [7] Black-Box Decision based Adversarial Attack with Symmetric α-stable Distribution
    Srinivasan, Vignesh
    Kuruoglu, Ercan E.
    Mueller, Klaus-Robert
    Samek, Wojciech
    Nakajima, Shinichi
    [J]. 2019 27TH EUROPEAN SIGNAL PROCESSING CONFERENCE (EUSIPCO), 2019,
  • [8] An Optimized Black-Box Adversarial Simulator Attack Based on Meta-Learning
    Chen, Zhiyu
    Ding, Jianyu
    Wu, Fei
    Zhang, Chi
    Sun, Yiming
    Sun, Jing
    Liu, Shangdong
    Ji, Yimu
    [J]. ENTROPY, 2022, 24 (10)
  • [9] Boosting Decision-Based Black-Box Adversarial Attack with Gradient Priors
    Liu, Han
    Huang, Xingshuo
    Zhang, Xiaotong
    Li, Qimai
    Ma, Fenglong
    Wang, Wei
    Chen, Hongyang
    Yu, Hong
    Zhang, Xianchao
    [J]. PROCEEDINGS OF THE THIRTY-SECOND INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2023, 2023, : 1195 - 1203
  • [10] Greedy-Based Black-Box Adversarial Attack Scheme on Graph Structure
    Shao, Shushu
    Xia, Hui
    Zhang, Rui
    Cheng, Xiangguo
    [J]. WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS, WASA 2021, PT II, 2021, 12938 : 96 - 106