A spatiotemporal prediction model robustness testing method, device, equipment and medium

By generating dynamic adversarial examples and identifying key nodes for iteration, the problem of robustness testing of traffic spatiotemporal prediction models is solved, and more efficient robustness evaluation is achieved.

CN115661768BActive Publication Date: 2026-04-24GUANGZHOU HKUST FOK YING TUNG RES INST
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUANGZHOU HKUST FOK YING TUNG RES INST
Filing Date
2022-11-08
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing technical methods cannot effectively test the robustness of traffic spatiotemporal prediction models, especially since adversarial attack testing is not applicable to dynamic spatiotemporal prediction models.

Method used

By generating dynamic adversarial examples, identifying a small number of victim nodes and performing multi-step iterations, an adversarial attack model with robustness testing is established, node salience is calculated, and locally optimized adversarial examples are generated.

Benefits of technology

It improves the efficiency and accuracy of robustness testing for traffic spatiotemporal prediction models, and the generated adversarial examples are more aggressive, which can fully test the robustness of the models.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115661768B_ABST
    Figure CN115661768B_ABST
Patent Text Reader

Abstract

The application discloses a kind of spatiotemporal prediction model robustness test method, device, equipment and medium, by obtaining the traffic state and prediction label of the spatiotemporal traffic prediction model of the traffic network to be tested, establish the adversarial attack model of robustness test;According to the traffic state of the spatiotemporal traffic prediction model, the traffic label of the spatiotemporal traffic prediction model is estimated;According to the traffic label and the adversarial attack model, the significance of different nodes is calculated;According to the indicator function and the significance of different nodes, determine victim node;For victim node, generate local optimization after the adversarial sample of multiple-step iteration is carried out.It can produce dynamic adversarial sample to attack traffic spatiotemporal prediction model, only need to identify a small amount of victim node to test the robustness of traffic spatiotemporal prediction model, the adversarial sample generated has stronger attack, can fully test the robustness of traffic spatiotemporal prediction model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, specifically to a method, apparatus, equipment, and medium for testing the robustness of spatiotemporal prediction models. Background Technology

[0002] In image processing, adding minute perturbations to an image is imperceptible to the human eye, yet these perturbations can cause classification systems to make incorrect classifications. These perturbated images are called adversarial examples, and the methods for generating adversarial examples are called adversarial attacks. Adversarial attacks can cause models to make incorrect judgments; therefore, adversarial attack testing of models is crucial for assessing their robustness.

[0003] Existing adversarial attack methods for testing models mainly include image classification-based adversarial attack methods and graph structure-based adversarial attack methods. For image-based adversarial attacks, the currently most effective method is gradient-based adversarial example generation. This involves calculating the gradient in the opposite direction of gradient descent, generating adversarial perturbations through multiple iterations, and finally adding them to the entire image. Graph structure-based adversarial attack methods mainly revolve around classification models and can be similarly categorized into targeted and untargeted adversarial attacks depending on the attacker's objective. The attacker sets the size of the added perturbation and generates adversarial examples based on the test model, which can test whether the model misclassifies nodes in the graph.

[0004] Existing methods focus on time-invariant label classification models to generate adversarial examples, resulting in static adversarial examples. In contrast, traffic spatiotemporal prediction models predict changing, continuous traffic flow. Therefore, existing methods are not suitable for adversarial attack testing of spatiotemporal prediction models. Summary of the Invention

[0005] To address the aforementioned issues, this invention proposes a method, apparatus, device, and medium for testing the robustness of a spatiotemporal prediction model. This method can generate dynamic adversarial examples to attack the traffic spatiotemporal prediction model, and only requires identifying a small number of victim nodes to test the robustness of the traffic spatiotemporal prediction model.

[0006] This invention provides a method for robustness testing of spatiotemporal prediction models, the method comprising:

[0007] Obtain the traffic status and prediction labels of the spatiotemporal traffic prediction model of the traffic network to be tested, and establish an adversarial attack model for robustness testing.

[0008] Estimate the traffic labels of the spatiotemporal traffic prediction model based on the traffic conditions of the spatiotemporal traffic prediction model;

[0009] The saliency of different nodes is calculated based on the traffic tags and the adversarial attack model;

[0010] The victim node is determined based on the indicator function and the salience of different nodes;

[0011] The system iterates through multiple steps to generate locally optimized adversarial examples for the victim nodes.

[0012] Preferably, the adversarial attack model is as follows:

[0013]

[0014] in, For loss function, and These are the time indices for the test set and training set of the spatiotemporal traffic prediction model, respectively. The predicted labels for the spatiotemporal traffic prediction model. For the time t of the traffic network Traffic conditions at any time For the transportation network at time t, v t Let ε be the set of nodes in the transportation network at time t. t Let be the set of edges of the traffic network at time t. The spatiotemporal traffic prediction model is defined as an aggressive adversarial traffic state, where η is the budget for the victim node, ε is the budget for adding perturbations, and X′ t To counteract the characteristics of spacetime, For clean spacetime characteristics, S t Let S be the index matrix of the victim nodes. t |0 represents the zero norm of the victim node index matrix, and p represents the p norm of the matrix.

[0015] Furthermore, the traffic tag specifically refers to

[0016] Among them, g φ (·) is the generalization function. To obtain from probability distribution Variables randomly sampled from the data.

[0017] As an improvement to the above scheme, the salience of the different nodes is:

[0018] in, Let σ be the adversarial loss function of the adversarial attack model, and let σ be the activation function. It is the set of adversarial spatiotemporal features from time t-T+1 to time t.

[0019] Preferably, the index matrix of the victim node at time t is:

[0020] in, To calculate node saliency based on indicator functions The largest set of the top k nodes, This indicates that the element at position (i, i) in the index matrix is ​​taken as the victim node v at time t. i .

[0021] Preferably, the adversarial example is

[0022] in, For the adversarial example in step i-1, X′ t To counteract spatiotemporal characteristics, ε represents the budget for adding perturbations. The `clip` function is used for clipping, and `sign(·)` is used for signing. For the estimation of adversarial traffic conditions in the (i-1)th iteration model, These are pseudo-labels for traffic conditions. To differentiate the spatiotemporal characteristics, α is the step size for adding the perturbation.

[0023] This invention also provides a robustness testing device for spatiotemporal prediction models, the device comprising:

[0024] The model building module is used to obtain the traffic state and prediction labels of the spatiotemporal traffic prediction model of the traffic network to be tested, and to build an adversarial attack model for robustness testing.

[0025] The tag calculation module is used to estimate the traffic tags of the spatiotemporal traffic prediction model based on the traffic state of the spatiotemporal traffic prediction model.

[0026] A saliency calculation module is used to calculate the saliency of different nodes based on the traffic tags and the adversarial attack model;

[0027] The node determination module is used to determine the victim node based on the indicator function and the salience of different nodes;

[0028] The sample generation module is used to perform multi-step iterations on the victim node to generate locally optimized adversarial samples.

[0029] Preferably, the adversarial attack model is specifically as follows:

[0030] in, For loss function, and These are the time indices for the test set and training set of the spatiotemporal traffic prediction model, respectively. The predicted labels for the spatiotemporal traffic prediction model. For the time t of the traffic network Traffic conditions at any time For the transportation network at time t, v t Let ε be the set of nodes in the transportation network at time t. t Let be the set of edges of the traffic network at time t. The spatiotemporal traffic prediction model is defined as an aggressive adversarial traffic state, where η is the budget for the victim node, ε is the budget for adding perturbations, and X′ t To counteract the characteristics of spacetime, For clean spacetime characteristics, S t Let S be the index matrix of the victim nodes. t |0 represents the zero norm of the victim node index matrix, and p represents the p norm of the matrix.

[0031] The traffic tag is specifically...

[0032] Among them, g φ (·) is the generalization function. To obtain from probability distribution Variables randomly sampled from the data.

[0033] The salience of the different nodes is

[0034] in, Let σ be the adversarial loss function of the adversarial attack model, and let σ be the activation function. It is the set of adversarial spatiotemporal features from time t-T+1 to time t.

[0035] The index matrix of the victim node at time t is:

[0036] in, To calculate node saliency based on indicator functions The largest set of the top k nodes, This indicates that the element at position (i, i) in the index matrix is ​​taken as the victim node v at time t. i .

[0037] The adversarial sample is

[0038] in, For the adversarial example in step i-1, X′t To counteract spatiotemporal characteristics, ε represents the budget for adding perturbations. The `clip` function is used for clipping, and `sign(·)` is used for signing. For the estimation of adversarial traffic conditions in the (i-1)th iteration model, These are pseudo-labels for traffic conditions. To differentiate the spatiotemporal characteristics, α is the step size for adding the perturbation.

[0039] This invention also provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements a spatiotemporal prediction model robustness testing method as described in any of the above embodiments.

[0040] This invention also provides a computer-readable storage medium, which includes a stored computer program, wherein the computer program, when running, controls the device where the computer-readable storage medium is located to execute a spatiotemporal prediction model robustness testing method as described in any of the above embodiments.

[0041] This invention provides a method, apparatus, device, and medium for robustness testing of a spatiotemporal prediction model. It involves acquiring the traffic state and prediction labels of a spatiotemporal traffic prediction model for a traffic network under test, establishing an adversarial attack model for robustness testing, estimating the traffic labels of the spatiotemporal traffic prediction model based on the traffic state, calculating the salience of different nodes based on the traffic labels and the adversarial attack model, identifying victim nodes based on an indicator function and the salience of different nodes, and performing multi-step iterations on the victim nodes to generate locally optimized adversarial examples. This method can generate dynamic adversarial examples to attack the spatiotemporal traffic prediction model. Only a small number of victim nodes need to be identified to test the robustness of the spatiotemporal traffic prediction model, and the generated adversarial examples are more aggressive, thus fully testing the robustness of the spatiotemporal traffic prediction model. Attached Figure Description

[0042] Figure 1 This is a flowchart illustrating a method for testing the robustness of a spatiotemporal prediction model according to an embodiment of the present invention.

[0043] Figure 2 This is a schematic diagram of the structure of a spatiotemporal prediction model robustness testing device provided in an embodiment of the present invention;

[0044] Figure 3 This is a schematic diagram of the structure of a terminal device provided in an embodiment of the present invention. Detailed Implementation

[0045] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0046] See Figure 1 This is a flowchart illustrating a method for testing the robustness of a spatiotemporal prediction model according to an embodiment of the present invention, the method comprising steps S1 to S5;

[0047] S1, obtain the traffic status and prediction labels of the spatiotemporal traffic prediction model of the traffic network to be tested, and establish an adversarial attack model for robustness testing;

[0048] S2, Estimate the traffic label of the spatiotemporal traffic prediction model based on the traffic state of the spatiotemporal traffic prediction model;

[0049] S3, calculate the salience of different nodes based on the traffic tags and the adversarial attack model;

[0050] S4. Based on the indicator function and the salience of different nodes, determine the victim node;

[0051] S5 performs multiple iterations on the victim node to generate locally optimized adversarial examples.

[0052] In the specific implementation of this embodiment, when facing adversarial attacks on the spatiotemporal traffic prediction model, it is necessary to model the robustness problem of the test traffic spatiotemporal prediction model as an adversarial attack problem, obtain the traffic status and prediction labels of the spatiotemporal traffic prediction model of the traffic network to be tested, and establish an adversarial attack model for robustness testing.

[0053] The labels of spatiotemporal traffic prediction models often represent future traffic state information. Therefore, when testing the robustness of spatiotemporal traffic prediction models, it is impossible to obtain traffic labels. Instead, it is necessary to estimate the traffic labels of the spatiotemporal traffic prediction models based on the traffic state of the models.

[0054] After obtaining the traffic labels of the spatiotemporal traffic prediction model, the salience of different nodes is calculated; node salience reflects the contribution of any node to the global loss. The greater the salience of a node, the greater its importance; therefore, affected nodes are determined based on the magnitude of node salience.

[0055] After obtaining the victim nodes, each iteration of the spatiotemporal traffic prediction model is only performed on the corresponding victim nodes, not all nodes, and adversarial examples of the traffic spatiotemporal prediction model are generated based on the victim nodes.

[0056] This embodiment proposes a method for generating spatiotemporal adversarial examples by estimating labels. By locating a small number of victim nodes and injecting adversarial examples, the robustness of the traffic spatiotemporal prediction model is tested. The generated adversarial examples are more aggressive and can fully test the robustness of the traffic spatiotemporal prediction model.

[0057] In another embodiment provided by the present invention, the adversarial attack model is specifically as follows:

[0058]

[0059] in, For loss function, and These are the time indices of the test set and the time index of the training set for the spatiotemporal traffic prediction model. The predicted labels for the spatiotemporal traffic prediction model. For the time t of the traffic network Traffic conditions at any time For the transportation network at time t, v t Let ε be the set of nodes in the transportation network at time t. t Let be the set of edges of the traffic network at time t. The spatiotemporal traffic prediction model is characterized by aggressive adversarial traffic conditions. This is a spatiotemporal adversarial example, containing adversarial spatiotemporal features and a traffic topology structure. η is the budget for victim nodes, i.e., the limit on the number of nodes selected, typically 10% of all traffic nodes. ε is the budget for adding perturbations, i.e., the limit on the size of the perturbations, typically set to 0.5. X′ t To counteract the characteristics of spacetime, S represents a clean spacetime characteristic, i.e., a characteristic that has not been attacked. t Let S be the index matrix of the victim nodes. t |0 represents the zero norm of the victim node index matrix, and p represents the p norm of the matrix.

[0060] In the specific implementation of this embodiment, For the transportation network at time t, For the traffic topology graph structure, v t Let ε be the set of nodes in the traffic network at time t, including blocks, road network segments, road sensors, etc. t Let be the set of edges of the traffic network at time t. As a spatiotemporal traffic prediction model for transportation networks, in which Indicates the time t before the traffic network Traffic conditions at any given time. The predicted labels of the spatiotemporal traffic prediction model, through the above-described construction of the spatiotemporal traffic prediction model, model the robustness problem of testing the spatiotemporal traffic prediction model as an adversarial attack problem, thus obtaining the adversarial attack model.

[0061] In the model For loss function, and These are the time indices for the test set and the training set of the spatiotemporal traffic prediction model, respectively. For the time t of the traffic network The traffic state at time t, η is the budget of the affected node, ε is the budget for adding disturbance, X′ t To counteract the characteristics of spacetime, For clean spacetime characteristics, S t Let S be the index matrix of the victim nodes. t |0 represents the zero norm of the victim node index matrix, and p represents the p norm of the matrix.

[0062] The robustness problem of the test spatiotemporal traffic prediction model is modeled as the problem of calculating the optimal adversarial traffic state that minimizes the model's performance on the test set, and then transformed into an adversarial attack model.

[0063] In another embodiment provided by the present invention, the traffic tag is specifically...

[0064] Among them, g φ (·) is the generalization function. To obtain from probability distribution Variables randomly sampled from the data.

[0065] In this specific implementation, when testing the robustness of the spatiotemporal traffic prediction model, labels cannot be obtained. Therefore, it is necessary to estimate the traffic labels obtained from the spatiotemporal traffic prediction model.

[0066] g φ (·) is specifically a generalization function, which in this embodiment can be the tanh(·) function, the sin(·) function, or f θ (·)function; To obtain from probability distribution Variables randomly sampled from the data.

[0067] In another embodiment provided by the present invention, the salience of the different nodes is

[0068] in, Let σ be the adversarial loss function of the adversarial attack model, and let σ be the activation function. It is the set of adversarial spatiotemporal features from time t-T+1 to time t.

[0069] In this specific implementation, after obtaining the traffic tags, the salience of the adversarial attack model nodes is calculated, and the salience of each node is obtained as follows:

[0070] in, Let σ be the adversarial loss function of the adversarial attack model, and let σ be the activation function. It is the set of adversarial spatiotemporal features from time t-T+1 to time t.

[0071] Node saliency reflects the contribution of any node to the global loss. The greater the saliency of a node, the greater its importance. Therefore, the importance of nodes in the spatiotemporal traffic prediction model can be determined based on the saliency of nodes. These nodes can then be used as victim nodes in adversarial attacks. By attacking nodes with high importance, the robustness of the spatiotemporal prediction model can be verified, resulting in more accurate results.

[0072] In another embodiment provided by the present invention, the index matrix of the victim node at time t is:

[0073] in, To calculate node saliency based on indicator functions The largest set of the top k nodes, This indicates that the element at position (i, i) in the index matrix is ​​taken as the victim node v at time t. i .

[0074] In this specific implementation, based on the saliency of each calculated node, the top η nodes with the highest saliency are set. The victim node is determined by the indicator function.

[0075] In another embodiment provided by the present invention, the adversarial example is

[0076] in, For the adversarial example in step i-1, X′ t To counteract spatiotemporal characteristics, ε represents the budget for adding perturbations. The `clip` function is used for clipping, and `sign(·)` is used for signing. For the estimation of adversarial traffic conditions in the (i-1)th iteration model, These are pseudo-labels for traffic conditions. To differentiate the spatiotemporal characteristics, α is the step size for adding the perturbation.

[0077] In this specific implementation, after determining the victim node, the adversarial model is iterated. During the iteration process, iteration is performed only on the corresponding victim node, rather than on all nodes. Randomly sampled noise is added to the clean samples to increase the diversity of the adversarial sample distribution. Through i-step iterations, locally optimized adversarial samples are generated.

[0078] in, For the adversarial example in step i-1, X′ t To counteract spatiotemporal characteristics, ε represents the budget for adding perturbations. The `clip` function is used for clipping, and `sign(·)` is used for signing. For the estimation of adversarial traffic conditions in the (i-1)th iteration model, These are pseudo-labels for traffic conditions. For the differentiation operation with respect to the spatiotemporal characteristics, α is the step size of the added perturbation.

[0079] The generated adversarial examples are used to perform adversarial attacks on the spatiotemporal traffic prediction model. The accuracy of the model in identifying adversarial examples after being attacked is verified to test the robustness of the model.

[0080] To verify the effectiveness of the proposed testing method, the robustness of the spatiotemporal traffic prediction model was tested on the PEMS-BAY traffic dataset. The robustness of the model was measured using MAE (Mean Average Error) and RMSE (Root Mean Square Error). Higher MAE and RMSE values ​​indicate better performance against attacks and poorer model robustness.

[0081] A classic traffic prediction model based on graph neural networks is used as the test model. For simplicity, the proposed method is named STPGD-TNDS. The algorithm is compared with a traditional gradient-optimized adversarial attack method (Projected Gradient Descent, PGD) combined with a node selection method, and contrasted with a non-attack scenario. The combination with the node selection method is as follows:

[0082] PGD-Random uses random selection of victim nodes as the node selection method and uses PGD to generate adversarial examples.

[0083] PGD-PR uses the PageRank algorithm to select victim nodes and uses PGD to generate adversarial examples.

[0084] PGD-Centrality uses the Betweenness Centrality algorithm to select victim nodes and generates adversarial examples using PGD.

[0085] PGD-Degree: Uses the degree distribution of the graph, i.e., degrees, to select victim nodes and uses PGD to generate adversarial examples.

[0086] The following table shows the metrics used to verify robustness after employing different algorithms to conduct adversarial attacks:

[0087] Table 1 Robustness Indicators of Different Algorithms

[0088] Algorithm / Indicator MAE RMSE Non-attack 1.975 4.0220 PGD-Random 4.9876 8.9343 PGD-PR 4.8599 8.8215 PGD-Centrality 5.1640 9.1369 PGD-Degree 4.9121 8.8416 STPGD-TNDS 6.1329 10.6723

[0089] The table above shows that adversarial attacks can reduce the performance of spatiotemporal traffic prediction models. The robustness performance metrics MAE and RMSE of the model after the attack using this method decreased by 67.79% and 62.31%, respectively. Furthermore, compared to other adversarial attack methods, this method achieved performance improvements of 15.80% and 15.39%. Therefore, this method can more efficiently and accurately test the robustness of spatiotemporal prediction models.

[0090] In yet another embodiment provided by the present invention, see Figure 2 This is a schematic diagram of a spatiotemporal prediction model robustness testing device provided in an embodiment of the present invention. The device includes: an image acquisition module, a video sequence set acquisition module, an input feature calculation module, a visual feature calculation module, and a probability calculation module.

[0091] The image acquisition module is used to control the PTZ camera to sequentially acquire video frames of each local field of view divided by the global field of view of the PTZ camera according to preset polling parameters;

[0092] The video sequence set acquisition module is used to rearrange all the video frames of the local field of view acquired by the PTZ camera to obtain the video sequence set of the global field of view;

[0093] The input feature calculation module is used to perform multidimensional convolution operations on each video sequence unit in the video sequence set to obtain the input features of the global field of view at each time step.

[0094] The visual feature calculation module is used to input the obtained input features into the convolutional neural network to extract the visual features at each time step.

[0095] The probability calculation module is used to input the obtained visual features into the recurrent neural network in chronological order for analysis, and to obtain the probability of occurrence of each event at each time step.

[0096] The spatiotemporal prediction model robustness testing device provided in this embodiment can execute all the steps and functions of the spatiotemporal prediction model robustness testing method provided in any of the above embodiments. The specific functions of the device will not be described in detail here.

[0097] See Figure 3 This is a schematic diagram of a terminal device provided in an embodiment of the present invention. The terminal device includes: a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a robustness testing program for a spatiotemporal prediction model. When the processor executes the computer program, it implements the steps in the various embodiments of the robustness testing method for a spatiotemporal prediction model described above, for example... Figure 1 The steps S1 to S5 are shown. Alternatively, when the processor executes the computer program, it implements the functions of each module in the above-described device embodiments.

[0098] For example, the computer program can be divided into one or more modules, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules can be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in the spatiotemporal prediction model robustness testing device. For instance, the computer program can be divided into various modules, the specific functions of which have been described in detail in the spatiotemporal prediction model robustness testing method provided in any of the above embodiments; therefore, the specific functions of the device will not be repeated here.

[0099] The aforementioned spatiotemporal prediction model robustness testing device can be a computing device such as a desktop computer, laptop, handheld computer, or cloud server. This device may include, but is not limited to, a processor and memory. Those skilled in the art will understand that the schematic diagram is merely an example of a spatiotemporal prediction model robustness testing device and does not constitute a limitation on such a device. It may include more or fewer components than illustrated, or combine certain components, or use different components. For example, the spatiotemporal prediction model robustness testing device may also include input / output devices, network access devices, buses, etc.

[0100] The processor referred to can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the spatiotemporal prediction model robustness testing device, connecting all parts of the device via various interfaces and lines.

[0101] The memory can be used to store the computer program and / or modules. The processor implements various functions of the spatiotemporal prediction model robustness testing device by running or executing the computer program and / or modules stored in the memory and calling the data stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0102] The modules integrated into the spatiotemporal prediction model robustness testing device, if implemented as software functional units and sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content contained in the computer-readable medium may be appropriately added to or subtracted from the content as required by the legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium may not include electrical carrier signals and telecommunication signals.

[0103] It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this invention, and these improvements and modifications are also considered to be within the scope of protection of this invention.

Claims

1. A method for testing the robustness of a spatiotemporal prediction model, characterized in that, The method includes: Obtain the traffic state and prediction labels of the spatiotemporal traffic prediction model of the traffic network to be tested, and establish an adversarial attack model for robustness testing; wherein, the adversarial attack model uses the adversarial traffic state corresponding to the time index of the test set as the variable, and takes the maximum loss value of the spatiotemporal traffic prediction model when the adversarial traffic state is the input as the objective optimization function; the adversarial traffic state is generated in the traffic network by applying perturbation to the clean spatiotemporal features of the nodes specified by the victim node index matrix; The traffic label of the spatiotemporal traffic prediction model is estimated based on the traffic state of the spatiotemporal traffic prediction model; wherein the traffic label is traffic state information for a specified future time period generated by generalizing the estimation of historical traffic state and superimposing random noise, and is used as a virtual label to measure the prediction error of the spatiotemporal traffic prediction model in adversarial attacks. The saliency of different nodes is calculated based on the traffic labels and the adversarial attack model; wherein the saliency is used to characterize the contribution of the corresponding node to the global loss; The victim node is determined based on the indicator function and the salience of different nodes; The system iterates through multiple steps to generate locally optimized adversarial examples for the victim nodes.

2. The robustness testing method for the spatiotemporal prediction model according to claim 1, characterized in that, The adversarial attack model is specifically as follows: ; in, For loss function, and These are the time indices for the test set and training set of the spatiotemporal traffic prediction model, respectively. , The predicted labels for the spatiotemporal traffic prediction model. For the time t of the traffic network Traffic conditions at any time For a moment t Transportation network, for t The set of nodes in the transportation network at any given time. for t The edge set of the transportation network at any given time. The spatiotemporal traffic prediction model is characterized by aggressive adversarial traffic conditions. The budget for the victim node. To add a budget for perturbation, To counteract the characteristics of spacetime, As a clean spacetime feature, This is the index matrix of the victim nodes. The zero norm of the victim node index matrix. p For matrix p Norm.

3. The robustness testing method for the spatiotemporal prediction model according to claim 2, characterized in that, The traffic tag is specifically... ; in, For generalization function, To obtain from probability distribution Variables randomly sampled from the data.

4. The robustness testing method for the spatiotemporal prediction model according to claim 3, characterized in that, The salience of the different nodes is ; in, Let be the adversarial loss function of the adversarial attack model. It is an activation function. It is the set of adversarial spatiotemporal features from time t-T+1 to time t.

5. The robustness testing method for the spatiotemporal prediction model according to claim 4, characterized in that, The index matrix of the victim node at time t is: ; in, To calculate node saliency based on indicator functions The largest set of the top k nodes, This indicates that the index is located at a position in the index matrix ( i , i The elements of ) are used as the victim nodes at time t. .

6. The method for robustness testing of spatiotemporal prediction models according to claim 5, characterized in that, The adversarial sample is ; in, For the (i-1)th step, To counteract the characteristics of spacetime, To add a budget for perturbation, For the clip function, For symbolic functions, For the estimation of adversarial traffic conditions in the (i-1)th iteration model, These are pseudo-labels for traffic conditions. To differentiate the spatiotemporal characteristics, α is the step size for adding the perturbation.

7. A robustness testing device for a spatiotemporal prediction model, characterized in that, The method for robustness testing of spatiotemporal prediction models as described in any one of claims 1 to 6; the apparatus comprises: The model building module is used to obtain the traffic state and prediction labels of the spatiotemporal traffic prediction model of the traffic network to be tested, and to build an adversarial attack model for robustness testing. The tag calculation module is used to estimate the traffic tags of the spatiotemporal traffic prediction model based on the traffic state of the spatiotemporal traffic prediction model. A saliency calculation module is used to calculate the saliency of different nodes based on the traffic tags and the adversarial attack model; The node determination module is used to determine the victim node based on the indicator function and the salience of different nodes; The sample generation module is used to perform multi-step iterations on the victim node to generate locally optimized adversarial samples.

8. The robustness testing device for spatiotemporal prediction models according to claim 7, characterized in that, The adversarial attack model is specifically as follows: ; in, For loss function, and These are the time indices for the test set and training set of the spatiotemporal traffic prediction model, respectively. , The predicted labels for the spatiotemporal traffic prediction model. For the time t of the traffic network Traffic conditions at any time For a moment t Transportation network, for t The set of nodes in the transportation network at any given time. for t The edge set of the transportation network at any given time. The spatiotemporal traffic prediction model is characterized by aggressive adversarial traffic conditions. The budget for the victim node. To add a budget for perturbation, To counteract the characteristics of spacetime, As a clean spacetime feature, This is the index matrix of the victim nodes. The zero norm of the victim node index matrix. p For matrix p Norm; The traffic tag is specifically... ; in, For generalization function, To obtain from probability distribution Variables randomly sampled from the data; The salience of the different nodes is ; in, Let be the adversarial loss function of the adversarial attack model. It is an activation function. The set of adversarial spatiotemporal features from time t-T+1 to time t; The index matrix of the victim node at time t is: ; in, To calculate node saliency based on indicator functions The largest set of the top k nodes, This indicates that the index is located at a position in the index matrix ( i , i The elements of ) are used as the victim nodes at time t. ; The adversarial sample is ; in, For the (i-1)th step, To counteract the characteristics of spacetime, To add a budget for perturbation, For the clip function, For symbolic functions, For the estimation of adversarial traffic conditions in the (i-1)th iteration model, These are pseudo-labels for traffic conditions. To differentiate the spatiotemporal characteristics, α is the step size for adding the perturbation.

9. A terminal device, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the spatiotemporal prediction model robustness testing method as described in any one of claims 1 to 6.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device on which the computer-readable storage medium is located to perform the spatiotemporal prediction model robustness testing method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Urban traffic accident early warning method based on space-time gridding data

    CN111798662A

  • Adversarial network-based traffic flow prediction method, system and device, and storage medium

    CN115099328A