Square-Based Black-Box Adversarial Attack on Time Series Classification Using Simulated Annealing and Post-Processing-Based Defense

被引:1
|
作者
Liu, Sichen [1 ,2 ]
Luo, Yuan [1 ,2 ]
机构
[1] Shanghai Jiao Tong Univ, Dept Comp Sci & Engn, Shanghai 200240, Peoples R China
[2] Shanghai Jiao Tong Univ, Blockchain Adv Res Ctr, Wuxi 214104, Peoples R China
关键词
time series classification; adversarial attack; adversarial attack defense;
D O I
10.3390/electronics13030650
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
While deep neural networks (DNNs) have been widely and successfully used for time series classification (TSC) over the past decade, their vulnerability to adversarial attacks has received little attention. Most existing attack methods focus on white-box setups, which are unrealistic as attackers typically only have access to the model's probability outputs. Defensive methods also have limitations, relying primarily on adversarial retraining which degrades classification accuracy and requires excessive training time. On top of that, we propose two new approaches in this paper: (1) A simulated annealing-based random search attack that finds adversarial examples without gradient estimation, searching only on the l(infinity)-norm hypersphere of allowable perturbations. (2) A post-processing defense technique that periodically reverses the trend of corresponding loss values while maintaining the overall trend, using only the classifier's confidence scores as input. Experiments applying these methods to InceptionNet models trained on the UCR dataset benchmarks demonstrate the effectiveness of the attack, achieving up to 100% success rates. The defense method provided protection against up to 91.24% of attacks while preserving prediction quality. Overall, this work addresses important gaps in adversarial TSC by introducing novel black-box attack and lightweight defense techniques.
引用
收藏
页数:13
相关论文
共 47 条
  • [21] SSQLi: A Black-Box Adversarial Attack Method for SQL Injection Based on Reinforcement Learning
    Guan, Yuting
    He, Junjiang
    Li, Tao
    Zhao, Hui
    Ma, Baoqiang
    [J]. FUTURE INTERNET, 2023, 15 (04):
  • [22] Black-Box Adversarial Attack on Graph Neural Networks Based on Node Domain Knowledge
    Sun, Qin
    Yang, Zheng
    Liu, Zhiming
    Zou, Quan
    [J]. KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, PT I, KSEM 2023, 2023, 14117 : 203 - 217
  • [23] Coreset Learning-Based Sparse Black-Box Adversarial Attack for Video Recognition
    Chen, Jiefu
    Chen, Tong
    Xu, Xing
    Zhang, Jingran
    Yang, Yang
    Shen, Heng Tao
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 1547 - 1560
  • [24] A CMA-ES-Based Adversarial Attack on Black-Box Deep Neural Networks
    Kuang, Xiaohui
    Liu, Hongyi
    Wang, Ye
    Zhang, Qikun
    Zhang, Quanxin
    Zheng, Jun
    [J]. IEEE ACCESS, 2019, 7 : 172938 - 172947
  • [25] Black-Box Transferable Adversarial Attack Method Based on Generative Adversarial Networks for Lung Disease Diagnosis Models
    Wang, Xiaoyin
    Wang, Dan
    Sun, Jiaze
    Yang, Yikang
    [J]. Hsi-An Chiao Tung Ta Hsueh/Journal of Xi'an Jiaotong University, 2023, 57 (10): : 196 - 206
  • [26] A Distributed Black-Box Adversarial Attack Based on Multi-Group Particle Swarm Optimization
    Suryanto, Naufal
    Kang, Hyoeun
    Kim, Yongsu
    Yun, Youngyeo
    Larasati, Harashta Tatimma
    Kim, Howon
    [J]. SENSORS, 2020, 20 (24) : 1 - 20
  • [27] Object-Aware Transfer-Based Black-Box Adversarial Attack on Object Detector
    Leng, Zhuo
    Cheng, Zesen
    Wei, Pengxu
    Chen, Jie
    [J]. PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT XII, 2024, 14436 : 278 - 289
  • [28] Parallel Population-Based Simulated Annealing for High-Dimensional Black-Box Optimization
    Zhang, Youkui
    Duan, Qiqi
    Shao, Chang
    Shi, Yuhui
    [J]. 2021 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (IEEE SSCI 2021), 2021,
  • [29] Perception-Driven Imperceptible Adversarial Attack Against Decision-Based Black-Box Models
    Zhang, Shenyi
    Zheng, Baolin
    Jiang, Peipei
    Zhao, Lingchen
    Shen, Chao
    Wang, Qian
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 3164 - 3177
  • [30] Black-Box Universal Adversarial Attack for DNN-Based Models of SAR Automatic Target Recognition
    Wan, Xuanshen
    Liu, Wei
    Niu, Chaoyang
    Lu, Wanjie
    Du, Meng
    Li, Yuanli
    [J]. IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2024, 17 : 8673 - 8696