Attack resisting method and device for prediction model

Through the adversarial attack method against the prediction model, historical flight data and loss function are used to project the significance, combined with binary search and internal iteration, indirect targeted attacks on the flight delay prediction model are achieved, solving the problem of insufficient use of attack time cost control and disturbance information in the existing methods, improving the attack success rate and reducing the number of victim nodes.

CN120047296APending Publication Date: 2025-05-27NORTHWESTERN POLYTECHNICAL UNIV +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510186835.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The existing adversarial attack methods mainly focus on targetless attacks and global direct attacks. The research on indirect targeted attack attacks against flight delay prediction models is still a blank, and the existing methods ignore the control of attack time costs and the full utilization of perturbation information during multiple iterations.

Method used

A method of adversarial attack against a prediction model is provided. By determining the average flight arrival data and takeoff delay data of each node at the historical time step as the initial samples, projecting according to the significance of the target node loss function and the non-target node, and obtaining the updated adversarial sample. Then, through binary search and internal iteration, the victim node subset is gradually refined, the attack success rate is maximized, the minimum victim node subset is determined, and the final adversarial sample is generated.

Benefits of technology

Indirect targeted confrontation attacks against flight delay prediction models are realized, reducing the number of victim nodes, improving the attack success rate, and effectively controlling the attack time cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120047296A_ABST
    Figure CN120047296A_ABST
Patent Text Reader

Abstract

The invention discloses an attack resisting method and device for a prediction model, and belongs to the field of artificial intelligence security. And indirect targeted countermeasure attacks are realized aiming at the network range flight delay prediction model. According to the method, significance of non-target nodes is evaluated based on gradient, then a preliminary candidate range including a first damaged node subset is determined by using binary search external circulation and nesting internal circulation, and on this basis, gradual refining of the external circulation and nesting of the internal circulation are performed to approach a minimum damaged node subset. In the two circulation processes, the intersection of the first damaged subset and the second damaged subset of two adjacent external iterations is accumulated to obtain a second initial sample and a third initial sample, disturbance information is fully utilized, the antagonistic potential of damaged nodes is maximized, the number of the damaged nodes needed by attacks is reduced, and the attack efficiency is improved. The minimization capability of the victim node subset is effectively improved, and the attack budget is saved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of artificial intelligence security, and more particularly relates to an adversarial attack method and device for a prediction model. Background Art

[0002] With the rapid development of the aviation industry and the rapid growth of air traffic, flight delays are increasing continuously, becoming an important factor affecting the operation efficiency of the aviation system, and bringing inconvenience and economic losses to stakeholders such as airports, airlines and passengers. This makes accurate flight delay prediction increasingly important. The aviation system can be regarded as an interconnected airport network, where airports are dynamically connected by a large number of flights passing through the system, so the flight delays at each airport exhibit complex spatio-temporal dependencies. With the development of artificial intelligence, especially deep learning technology, many deep neural networks are used to capture spatio-temporal dependencies from massive historical data, model the propagation law of flight delays in the airport network, and thus achieve more accurate delay prediction. The network-wide flight delay prediction model focuses on the average delay level of flights at each airport in the airport network, providing a reference for aviation management from a macroscopic perspective.

[0003] However, deep neural networks have been proven to be vulnerable to adversarial examples. An attacker can make the neural network model produce a prediction with a huge deviation by adding a carefully designed tiny perturbation to the original input. This input with the added perturbation is called an adversarial example, and the process of generating an adversarial example is called an adversarial attack. The research on adversarial attacks can promote the understanding of the inherent defects of the model, reveal potential security vulnerabilities, and thus promote the progress of defense mechanisms and continuously improve the robustness of the deep neural network model, which is particularly important for deep learning applications in safety-critical systems.

[0004] According to whether there is a clear attack target, adversarial attacks can be divided into untargeted attacks and targeted attacks. For a real-valued prediction model, an untargeted attack only requires the attacked model to make a deviated prediction, while a targeted attack intends to induce the model to produce a deviated prediction within a specified range, in a specified direction or at a specified level. Targeted attacks on a multi-variate prediction model such as a spatio-temporal prediction model can be further divided into direct targeted attacks and indirect targeted attacks. A direct targeted attack is achieved by directly applying a perturbation to the data on the target node or target feature, while an indirect targeted attack injects a perturbation into some other nodes or features other than the target node or target feature, and uses the dependency relationship between each node and feature to indirectly manipulate the model prediction on the target node or target feature to reach the specified target.

[0005] Although adversarial attacks have been widely studied in fields such as computer vision and natural language processing, the problem of adversarial attacks on spatio-temporal prediction models has received less attention and mainly focuses on traffic prediction tasks. In addition, most of the existing attack methods are limited to untargeted attacks and global direct attacks, and the research on indirect targeted attacks on flight delay prediction models is still a blank. Moreover, for identifying the smallest subset of victim nodes that can achieve the attack goal, the existing methods mainly use importance measurement and enumeration iteration, ignoring the control of the attack time cost and the full utilization of the perturbation information in multiple iterations, and the attack budget can be further reduced. Summary of the Invention

[0006] Embodiments of the present invention provide an adversarial attack method and apparatus for a prediction model, and implement an indirect targeted adversarial attack on a network-wide flight delay prediction model.

[0007] Embodiments of the present invention provide an adversarial attack method for a prediction model, including:

[0008] Determine the average arrival data and takeoff delay data of flights at each node in the historical time step as the first initial sample, project according to the gradient of the current iteration of the first adversarial sample of the target node loss function and the first binary tensor of non-target nodes to obtain the first updated adversarial sample; obtain the first significance according to the iterative output of the first adversarial sample, the target node loss function, and the gradient of the iterative output of the first adversarial sample on each non-target node;

[0009] In the current outer iteration, update the first subset of victim nodes according to the increment of the midpoint of the binary search and the first significance, accumulate the intersection of the first subsets of victim nodes in two adjacent outer iterations to obtain the second initial sample of the current outer iteration, perform an inner iteration based on the second initial sample to obtain the output second adversarial sample, and update the left pointer and right pointer of the binary searcher according to the relationship between the attack success rate corresponding to the second adversarial sample and the target success rate. When the binary search interval is empty, determine the first subset of victim nodes as the initial range and obtain the second significance;

[0010] In the current outer iteration, remove some nodes within the initial range according to the second significance to obtain the second subset of victims, accumulate the intersection of the second subsets of victims in two adjacent outer iterations to obtain the third initial sample of the current outer iteration, perform an inner iteration based on the third initial sample to obtain the output third adversarial sample. If the attack success rate corresponding to the third adversarial sample is greater than or equal to the target success rate, confirm that the attack is successful, determine the third subset of victim nodes as the smallest subset of victim nodes, and obtain the final adversarial sample according to the final adversarial perturbation and the first initial sample.

[0011] Preferably, updating the left pointer and the right pointer of the binary searcher according to the relationship between the attack success rate corresponding to the second adversarial sample and the target success rate specifically includes:

[0012] If the attack success rate of the second adversarial sample output by the current outer iteration is greater than or equal to the target success rate, update the right pointer included in the binary search indicator based on r = m; or, if the attack success rate of the second adversarial sample output by the current outer iteration is less than the target success rate, update the left pointer included in the binary search indicator based on l = m + 1, where r represents the right pointer, m represents the midpoint of the binary search, and l represents the left pointer;

[0013] When the binary search interval is empty, determining the first subset of victim nodes as the initial range and obtaining the second significance further includes:

[0014] If the attack success rate corresponding to the second adversarial sample is greater than or equal to the target success rate, determine the first subset of victim nodes corresponding to the current outer iteration as the initial range; if the attack success rate corresponding to the second adversarial sample is less than the target success rate, add victim nodes selected from non-target nodes to the first subset of victim nodes according to the second significance determined in the previous outer iteration.

[0015] Preferably, updating the first subset of victim nodes according to the increment of the midpoint of the binary search and the first significance specifically includes:

[0016] If the increment of the midpoint of the binary search is greater than zero, select the Δm nodes with the highest second significance from non-target nodes according to the second significance determined in the previous outer iteration and add them to the first subset of victim nodes to obtain the first subset of victim nodes for the current outer iteration; or

[0017] If the increment of the midpoint of the binary search is less than zero, select the (-Δm) nodes with the lowest second significance and remove them from the first subset of victim nodes corresponding to the previous outer iteration to obtain the first subset of victim nodes for the current outer iteration, where Δm is equal to the increment of the midpoint of the binary search.

[0018] Preferably, accumulating the intersection of the first subsets of victim nodes in two adjacent outer iterations to obtain the second initial sample for the current outer iteration specifically includes:

[0019] Determine the intersection of the first subset of victim nodes corresponding to the current outer iteration and the first subset of victim nodes corresponding to the previous outer iteration, and accumulate the perturbations on the intersection with a first attenuation coefficient to obtain the second initial sample for the current outer iteration as shown below:

[0020]

[0021] Accumulating the intersection of the second victim subsets of two adjacent external iterations to obtain the third initial sample of the current external iteration, specifically including:

[0022]

[0023] Among them, represents the second initial sample of the j 1 -th external iteration, represents the second binary tensor, represents the second adversarial sample output by the (j 1 -1)-th external iteration, X represents the first initial sample, and β represents the first attenuation coefficient; represents the third binary tensor, represents the third adversarial sample output by the (j 2 -1)-th external iteration, represents the third initial sample of the j 2 -th external iteration.

[0024] Preferably, performing internal iteration based on the second initial sample to obtain the output second adversarial sample, specifically including:

[0025] Obtaining the momentum gradient of the current internal iteration in the current external iteration according to the momentum gradient of the previous internal iteration in the current external iteration, the total loss function of the previous internal iteration in the current external iteration, and the second adversarial sample of the previous internal iteration in the current external iteration;

[0026] Performing projection according to the momentum gradient of the current internal iteration in the current external iteration, the second adversarial sample of the previous internal iteration in the current external iteration, and the step size of the internal iteration to obtain the second updated adversarial sample;

[0027]

[0028] Among them, represents the momentum gradient of the o 1 -th internal iteration in the k 2 -th external iteration, represents the momentum gradient of the (i 1 -1)-th internal iteration in the j 2 -th external iteration, μ represents the second attenuation coefficient, ‖·‖ 1 represents the sum of the absolute values of all elements, represents the second adversarial sample of the (i 1 -1)-th internal iteration in the j 2 -th external iteration, represents the total loss function of the (i 1 -1)-th internal iteration in the j 2 -th external iteration, Denote the second updated adversarial sample as M I Denote the third binary tensor of the victim node as ∏ ε (·) represents the projection operation, α a Denote the step size of the internal iteration.

[0029] Preferably, projecting according to the gradient of the first adversarial sample in the current iteration of the target node loss function and the first binary tensor of the non-target node to obtain the first updated adversarial sample specifically includes:

[0030] Determine the gradient of the first adversarial sample in the current iteration of the target node loss function according to the current iteration of the target node loss function, the first adversarial sample in the previous iteration, the target threshold, and the target model parameters; project according to the gradient of the first adversarial sample in the current iteration of the target node loss function, the step size of the current iteration, the first binary tensor of the non-target node, and the first adversarial sample in the previous iteration to obtain the first updated adversarial sample;

[0031]

[0032] Among them, Denote the gradient of the first adversarial sample in the i-th iteration of the target node loss function 1 , Denote taking the gradient of the first adversarial sample X′ obtained in the (i - 1)-th iteration 1 , (i-1) , Denote the first adversarial sample in the (i - 1)-th iteration, B represents the target threshold, θ represents the target model parameters, 1 , Denote the target node loss function in the i-th iteration 1 , Denote the first updated adversarial sample as ∏ ε (·) represents the projection operation, α s Denote the step size of the PGD projected gradient descent, M V-T Denote the first binary tensor of the non-target node.

[0033] Preferably, before determining that the attack is successful if the attack success rate corresponding to the third adversarial sample is greater than or equal to the target success rate and determining the third victim node subset as the minimum victim node subset, and obtaining the final adversarial sample according to the final adversarial perturbation and the first initial sample, further includes:

[0034] If the third subset of victim nodes contains only one victim node, confirm the end of the current outer iteration; or if the attack success rate corresponding to the third adversarial sample in the current outer iteration is less than the target success rate, the attack success rate corresponding to the third adversarial sample in the previous outer iteration is less than the target success rate, and the attack success rate corresponding to the third adversarial sample in the current outer iteration is less than the attack success rate corresponding to the third adversarial sample in the previous outer iteration, confirm the end of the current outer iteration.

[0035] Preferably, the first significance is as follows:

[0036]

[0037] where S v(0) represents the first significance of the non-target node v, represents the component of the iteratively output first adversarial sample X′ on the non-target node v, where X′ represents the iteratively output first adversarial sample, represents the gradient operation, ‖·‖ F represents the Frobenius norm.

[0038] The embodiment of the present invention provides an adversarial attack device for a prediction model, including:

[0039] A first obtaining unit, configured to determine the average arrival data and takeoff delay data of each node at historical time steps as a first initial sample, project according to the gradient of the current iteration of the first adversarial sample of the target node loss function and the first binary tensor of the non-target node to obtain a first updated adversarial sample; obtain the first significance according to the iteratively output first adversarial sample, the target node loss function, and the gradient of the iteratively output first adversarial sample on each of the non-target nodes;

[0040] A second obtaining unit, configured to update the first subset of victim nodes according to the increment of the midpoint of the binary search and the first significance in the current outer iteration, accumulate the intersection of the first subsets of victim nodes in two adjacent outer iterations to obtain a second initial sample for the current outer iteration, perform an inner iteration based on the second initial sample to obtain an output second adversarial sample, update the left pointer and the right pointer of the binary searcher according to the relationship between the attack success rate corresponding to the second adversarial sample and the target success rate, and when the binary search interval is empty, determine the first subset of victim nodes as the initial range and obtain the second significance;

[0041] A determination unit is configured to, in a current outer iteration, remove some nodes within the initial range according to the second significance level to obtain a second victim subset, accumulate the intersection of the second victim subsets of two adjacent outer iterations to obtain a third initial sample of the current outer iteration, perform an inner iteration based on the third initial sample to obtain an output third adversarial sample. If the attack success rate corresponding to the third adversarial sample is greater than or equal to the target success rate, it is confirmed that the attack is successful, the third victim node subset is determined as the minimum victim node subset, and a final adversarial sample is obtained according to the final adversarial perturbation and the first initial sample.

[0042] An embodiment of the present invention provides a computer device, which includes a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor is caused to execute the adversarial attack method of the prediction model described in any one of the above.

[0043] An embodiment of the present invention provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor is caused to execute the adversarial attack method of the prediction model described in any one of the above.

[0044] The invention embodiment provides a method and device for adversarial attack on a prediction model, including: determining the average arrival data and takeoff delay data of each node at historical time steps as a first initial sample, projecting according to the gradient of the current iteration of the first adversarial sample of the target node loss function and the first binary tensor of the non-target nodes to obtain a first updated adversarial sample; obtaining a first significance according to the iterative output of the first adversarial sample, the target node loss function, and the gradient of the iterative output of the first adversarial sample on each of the non-target nodes; in the current external iteration, updating the first victim node subset according to the increment of the midpoint of the binary search and the first significance, accumulating the intersection of the first victim node subsets of two adjacent external iterations to obtain a second initial sample of the current external iteration, performing an internal iteration based on the second initial sample to obtain an output second adversarial sample, and updating the left pointer and the right pointer of the binary searcher according to the relationship between the attack success rate corresponding to the second adversarial sample and the target success rate. When the binary search interval is empty, determining the first victim node subset as the initial range and obtaining a second significance; in the current external iteration, removing some nodes within the initial range according to the second significance to obtain a second victim subset, accumulating the intersection of the second victim subsets of two adjacent external iterations to obtain a third initial sample of the current external iteration, performing an internal iteration based on the third initial sample to obtain an output third adversarial sample. If the attack success rate corresponding to the third adversarial sample is greater than or equal to the target success rate, confirming that the attack is successful, determining the third victim node subset as the minimum victim node subset, and obtaining a final adversarial sample according to the final adversarial perturbation and the first initial sample. This method first evaluates the significance of non-target nodes based on gradients, and then uses a binary search external loop nested with an internal loop to determine a preliminary candidate range including the first victim node subset. On this basis, it further refines the external loop nested with the internal loop to approximate the minimum victim node subset. During the above two loop processes, the intersections of the first victim subsets and the second victim subsets of two adjacent external iterations are accumulated to obtain the second initial sample and the third initial sample respectively, making full use of the perturbation information, maximizing the adversarial potential of the victim nodes, reducing the number of victim nodes required for the attack, effectively improving the ability to minimize the victim node subset, and saving the attack budget. This method utilizes the spatio-temporal dependence relationship in the airport network to achieve indirect targeted adversarial attacks on the network-wide flight delay prediction model. By applying adversarial perturbations on the victim nodes, it indirectly manipulates the future delay prediction on the target node to reach the specified target. Description of the Drawings

[0045] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0046] Figure 1 Schematic flow chart of the adversarial attack method for the prediction model provided by the embodiment of the present invention;

[0047] Figure 2 Schematic structural diagram of the adversarial attack method device for the prediction model provided by the embodiment of the present invention. Detailed implementation manners

[0048] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0049] Figure 1 Schematic flow chart of the adversarial attack method for the prediction model provided by the embodiment of the present invention, as Figure 1 shown, the method mainly includes the following steps:

[0050] Step 101: Determine the average arrival delay data and takeoff delay data of each node at the historical time step as the first initial sample. Project according to the gradient of the current iteration of the first adversarial sample of the target node loss function and the first binary tensor of the non-target nodes to obtain the first updated adversarial sample; obtain the first significance according to the iterative output of the first adversarial sample, the target node loss function, and the gradient of the iterative output of the first adversarial sample on each of the non-target nodes;

[0051] Step 102: In the current external iteration, update the first victim node subset according to the increment of the midpoint of the binary search and the first significance, accumulate the intersection of the first victim node subsets of two adjacent external iterations to obtain the second initial sample of the current external iteration, perform internal iteration based on the second initial sample to obtain the output second adversarial sample, and update the left pointer and right pointer of the binary searcher according to the relationship between the attack success rate corresponding to the second adversarial sample and the target success rate. When the binary search interval is empty, determine the first victim node subset as the initial range and obtain the second significance;

[0052] Step 103: In the current external iteration, remove some nodes within the initial range according to the second significance level to obtain a second victim subset. Cumulate the intersection of the second victim subsets of two adjacent external iterations to obtain the third initial sample of the current tail iteration. Perform an internal iteration based on the third initial sample to obtain an output third adversarial sample. If the attack success rate corresponding to the third adversarial sample is greater than or equal to the target success rate, confirm that the attack is successful, determine the third victim node subset as the minimum victim node subset, and obtain the final adversarial sample according to the final adversarial perturbation and the first initial sample.

[0053] The adversarial attack method for the prediction model provided by the embodiments of the present invention utilizes the spatio-temporal dependence relationship in the airport network to achieve an indirect targeted adversarial attack on the flight delay prediction model within the network scope.

[0054] Specifically, by using a search strategy of first estimating and then refining and a perturbation accumulation technique, it strengthens the full utilization of perturbation information during the search process, accelerates the search process for the minimum victim node subset, and further reduces the number of victim nodes.

[0055] Before step 101, first set the attack target and related parameters, which will guide the subsequent attack process:

[0056] Target node subset T, Set the target node subset, which can clarify the set of airport nodes for the attacker to predict the corresponding operation results; V represents all nodes, which can be airport nodes here.

[0057] The target success rate is R (0 < R < 1), which clarifies the proportion of data points whose predicted values expected by the attacker cross the target threshold;

[0058] The target threshold is B (B > 0), which is used to determine whether the predicted value crosses the threshold within the specified range;

[0059] Perturbation amplitude limit ε, which limits the maximum amplitude of the adversarial perturbation to ensure that the perturbation will not be too large;

[0060] PGD iteration times Q and step size α during iteration s = ε / Q, the PGD iteration times determines the number of iteration rounds when calculating the first significance level, and the step size controls the perturbation amplitude of each iteration;

[0061] MIM iteration times N and step size α during iteration a = ε / N, the MIM iteration times determines the number of iteration rounds when generating the adversarial perturbation, and the step size controls the perturbation amplitude of each iteration;

[0062] Momentum gradient decay coefficient (second decay coefficient) μ (0 < μ < 1), which is used to decay the gradient of the previous iteration in the MIM algorithm to avoid gradient oscillation;

[0063] Weight factor λ for the loss of non-target nodes nt (0 < λ nt < 1), which is used to control the trade-off between the losses of target nodes and non-target nodes;

[0064] Decay coefficient (the first decay coefficient) β (0 < β < 1) in perturbation accumulation, which is used to attenuate the perturbation on the intersection during the perturbation accumulation operation;

[0065] Victim node subset I

[0066] In practical applications, the goal of the indirect targeted attack is to apply adversarial perturbations to the historical delay data of the victim nodes in the victim node subset I, so that the flight delay prediction model f θ (·) can cross the specified target threshold B with a specified success rate R for the future delay prediction of the target nodes, that is, for all target nodes and all data points at τ future time steps, when the proportion of data points whose predicted values fall outside the interval [-B, B] exceeds the specified success rate R, the attack is considered successful.

[0067] To reduce the attack budget, it is necessary to find the smallest victim node subset and the corresponding adversarial perturbations that can achieve the attack goal, which can be formulated as a joint optimization problem regarding the victim node subset I and the adversarial perturbation δ t-h+1:t as follows, shown in the following formulas (1) and (2):

[0068]

[0069] X adv = X + δ t-h+1:t (2)

[0070] where s(·) represents the function for calculating the success rate, ε represents the maximum limit of the perturbation δ t-h+1:t under the p-norm constraint (p can generally take 1, 2, or ∞), and X adv represents the final adversarial sample added with the adversarial perturbation.

[0071] The above joint optimization problem can be solved through a process of external minimization of the victim node subset and internal maximization of the attack effect. The external minimization of the victim node subset is achieved through a process of binary search and step-by-step refinement, and the internal maximization of the attack effect is achieved through minimizing the loss function by the gradient attack algorithm.

[0072] It should be noted that the adversarial attack method for the prediction model provided in the embodiments of the present invention includes 3 steps, and each step involves an iterative loop. Among them, the PGD loop is involved in step 101, the binary search outer loop and the nested MIM inner loop are involved in step 102, and the outer loop nested with the MIM inner loop is refined in step 103.

[0073] In step 101, this step executes the PGD loop and calculates the first significance value of each non-target node using gradient information.

[0074] PGD loop:

[0075] Set the loop condition of the PGD loop, and iterate from i 1 = 1 to i 1 = Q.

[0076] Start the PGD loop, and first determine the loss function of the target node:

[0077] Among them, the loss function of the target node is determined by the target node loss on the arrival delay feature, the target node loss on the departure delay feature, the adaptive weight on the arrival delay feature, and the adaptive weight on the departure delay feature.

[0078] Specifically, the average arrival data and departure delay data of flights at each node in the historical time step are determined as the first initial sample. For a certain or multiple target nodes set, the arrival delay prediction and departure delay prediction of the target nodes can be obtained through the flight delay prediction model in multiple future time steps.

[0079] Calculate the target node loss on the arrival delay feature according to the arrival delay prediction of the target node, and then calculate the target node loss on the departure delay feature according to the departure delay prediction of the target node, as shown below:

[0080]

[0081]

[0082]

[0083] Among them, L arr represents the target node loss on the arrival delay feature, L dep represents the target node loss on the departure delay feature, D(·) represents the distance operator, represents the arrival delay prediction value of node v at the q-th time step, represents the departure delay prediction value of node v at the q-th time step, v ∈ T, q ∈ [t + 1:t + τ], |T| represents the number of victim nodes, τ represents the number of future time steps to be predicted on the target node; k represents a coefficient, represents the current predicted value, and the coefficient k≥1 is used to ensure that when the predicted value is close to the target threshold B, it still has the ability to cross it.

[0084] In practical applications, the distance operator is used to evaluate the distance between the predicted value and the boundaries of the interval [-B, B] formed by the target threshold. When the predicted value falls within the interval, this operator measures the distance from the predicted value to the nearest boundary; when the predicted value crosses the interval boundary, the calculated value is 0 (when k = 1). In the target node loss function with the above two features, the distance operator accurately quantifies the difference between the predicted value and the target threshold, and encourages the model prediction to cross the nearest interval boundary through the coefficient k.

[0085] Furthermore, the adaptive weights on the takeoff delay feature and the adaptive weights on the arrival delay feature are determined by the following formula:

[0086]

[0087]

[0088] where represents the adaptive weight on the arrival delay feature at the i-th iteration, represents the i 1 -th iteration of the adaptive weight on the takeoff delay feature, represents the i 1 -1-th iteration of the adaptive weight on the arrival delay feature, represents the i 1 -1-th iteration of the adaptive weight on the takeoff delay feature.

[0089] Furthermore, the loss of the model prediction on the target node relative to the target threshold is determined according to the following formula, that is, the target node loss function:

[0090]

[0091] where represents the target node loss function at the i 1 -th iteration, L arr represents the target node loss on the arrival delay feature, L dep represents the target node loss on the takeoff delay feature, represents the adaptive weight on the arrival delay feature, represents the adaptive weight on the takeoff delay feature.

[0092] At the current iteration, after obtaining the target node loss function, the i-th 1The gradient of the first adversarial sample obtained in the -1-th iteration, and then add a perturbation with a step size of α along the direction of the gradient sign, and project the perturbed sample into an ∞-norm ball with a radius of ε s to constrain the maximum magnitude of the perturbation. r Specifically, the gradient of the first adversarial sample obtained in the i-th iteration of the target node loss function and the first updated adversarial sample can be expressed by the following formula:

[0093] where 1 represents the gradient of the first adversarial sample in the i-th iteration of the target node loss function,

[0094]

[0095]

[0096] represents taking the gradient of the first adversarial sample X′ obtained in the (i - 1)-th iteration, represents the i-th 1 iteration of the first adversarial sample, B represents the target threshold, θ represents the target model parameter, represents the i-th 1 (i - 1)-th iteration of the first adversarial sample X′ (i-1) for taking the gradient, represents the first adversarial sample in the i-th 1 (i - 1)-th iteration, B represents the target threshold, θ represents the target model parameter, represents the i-th 1 iteration of the target node loss function, represents the first updated adversarial sample (the first adversarial sample in the i-th 1 iteration), ∏ ε (·) represents the projection operation, α s = ε / Q represents the iteration step size of PGD projected gradient descent, M V-T represents the first binary tensor of non-target nodes, L tgr (X′ (i-1) , B; θ) represents the loss of the model prediction on the target node relative to the target threshold.

[0097] In this iteration process, when i 1 = Q, when the iteration end condition is reached, the following parameters can be obtained:

[0098] The first adversarial sample X ′(Q) (the iterative output first adversarial sample X′) in the Q-th iteration, which represents the first adversarial sample in the Q-th iteration obtained after a series of gradient perturbations and projection operations on the first initial sample X ′(0) = X.

[0099] The adaptive weight on the takeoff delay feature in the Q-th iteration (the adaptive weight on the final takeoff delay feature) and the adaptive weight on the arrival delay feature at the Q-th iteration (the adaptive weight on the final arrival delay feature) They reflect the variation of the relative importance of the arrival delay feature and the departure delay feature in the loss of the target node with the iteration, and can be used to analyze the attention degree of the model to different features.

[0100] The loss function of the target node at the Q-th iteration (the final loss function of the target node) It reflects the final loss of the model prediction relative to the target threshold, and can be used to evaluate the performance of the model or the effect of adversarial attacks.

[0101] In the embodiment of the present invention, after the iteration ends, the first adversarial sample X′ and related parameters can be output according to the iteration, and the first significance of each non-target node can be determined through the following formula:

[0102]

[0103] where S v(0) represents the first significance of the non-target node v, represents the component of the first adversarial sample X′ output by the iteration on the non-target node v, represents the gradient operation, ‖·‖ F represents the Frobenius norm, v ∈ V, L tgt represents the target node loss function, B represents the target threshold, θ represents the target model parameter, represents the gradient of the target node loss function with respect to the component of the first adversarial sample output by the iteration on the non-target node, and X′ represents the first adversarial sample output by the iteration.

[0104] In the embodiment of the present invention, the first significance of the non-target node obtained based on the gradient can reflect to a certain extent the unit change of the data on the non-target node. At the same time, the unit change of the data on the non-target node can cause the change of the target node loss function. Therefore, in the subsequent steps, the continuously updated first significance of the non-target node will be used to evaluate the priority of each non-target node being selected as the victim node.

[0105] In step 102, this step initially candidates the range of the victim node through binary search, involving an external loop of binary search and nesting an internal loop of MIM.

[0106] Specifically, set the external loop of binary search:

[0107] Initialize the binary search indicator, determine the initial left pointer of the binary search indicator as zero, and determine the initial right pointer according to the number of each node included in the first initial sample; in this embodiment, the initial right pointer can be determined according to the number of airport nodes.

[0108] Further, when the initial left pointer is less than the initial right pointer, a loop starts. That is, during the j-th outer iteration of the binary search, the first binary midpoint is determined by the following formula. It should be noted that during the first (j 1 = 1) iteration, the binary search midpoint is called the first binary midpoint. Correspondingly, if it is the second (j 1 = 2) iteration, the binary search midpoint is called the second binary midpoint.

[0109]

[0110] where m 1 represents the first binary search midpoint, l 0 represents the initial left pointer, r 0 represents the initial right pointer, represents floor function. For example, if the initial left pointer l = 0 and the initial right pointer r = |V| + 1 = 11, the second binary midpoint

[0111] Further, update the victim node subset according to the first binary search midpoint. Specifically, if the increment Δm of the first binary midpoint is greater than zero, indicating that the target success rate is not reached, then according to the first significance of the non-target nodes determined in step 101, select the Δm non-target nodes with the highest first significance and add them to the first victim node subset, where is equal to the increment of the first binary midpoint Δm; correspondingly, if the increment Δm of the first binary midpoint is less than zero, indicating that the target success rate is achieved, then it is necessary to select and remove the (-Δm) nodes with the lowest first significance from the first victim node subset, and then the victim node subset during the j 1 -th outer iteration can be obtained

[0112] If the increment Δm > 0, it means that the m victim nodes included in the first victim node subset during the j-th outer iteration are not sufficient to make the attack on the target node reach (greater than or equal to) the target success rate, so more victim nodes need to be added for continuous iteration; correspondingly, if Δm < 0, it means that the number of victim nodes needs to be reduced. In this embodiment, the first significance value of the non-target nodes is used to evaluate the priority of a non-target node being selected as a victim node. Therefore, when adding victim nodes, select the Δm non-target nodes with the highest first significance from the remaining non-target nodes; when reducing victim nodes, select and remove the (-Δm) nodes with the lowest first significance from the first victim node subset.

[0113] Further, after updating the first victim node subset, take the first victim node subset in the current iteration (the j 1 -th outer iteration) and the first victim node subset in the previous iteration (the j 1The intersection of the first victim node subsets in the (-1)-th outer iteration is used to accumulate the perturbations on the intersection to a certain extent with the first attenuation coefficient β, and thus the second initial sample as shown below is obtained. Here, the second initial sample is used to distinguish from the first initial sample in step 101 above.

[0114]

[0115] Among them, represents the second binary tensor, represents the j 1 -1-th outer iteration outputs the second adversarial sample, represents the second initial sample in the j 1 -th outer iteration, X represents the first initial sample, and β represents the first attenuation coefficient.

[0116] It should be noted that the perturbations generated for the same victim node in each outer iteration will be different due to the different victim node subsets to which the node belongs. Perturbation accumulation can strengthen the full utilization of these perturbation information, so as to maximize the adversarial potential of each victim node. In this embodiment, the subscript (j) represents the outer iteration, and each outer iteration includes N inner iterations, which are described by the superscript (i).

[0117] Set the inner loop iteration, and the loop condition is from i 2 = 1 to i 2 = N 1 .

[0118] Specifically, in the i 2 -th inner iteration, based on the gradient 2 in the previous inner iteration (the (i -1)-th), the momentum gradient 2 of the current inner iteration (the i -th) is obtained by accumulating the normalized gradient with the second attenuation coefficient μ as follows:

[0119]

[0120] Among them, represents the momentum gradient in the i 1 -th inner iteration in the j 2 -th outer iteration, represents the momentum gradient in the (i 1 -1)-th inner iteration in the j 2 -th outer iteration, μ represents the second attenuation coefficient, ‖·‖ 1 represents the sum of the absolute values of all elements, represents the gradient in the i 1 -th inner iteration in the j 2The second adversarial sample of the -1-th internal iteration, represents the i-th 1 in the j-th 2 total loss function of the -1-th internal iteration.

[0121] It should be noted that, represents the second initial sample of the first internal iteration in the j-th 1 external iteration.

[0122] In formula (14), the total loss function of the i-th 2 -1-th internal iteration in the j-th external iteration consists of two parts: the loss of the target node and the loss of the non-target node, which are specifically as follows:

[0123]

[0124] Among them, represents the total loss function of the i-th 1 -1-th internal iteration in the j-th external iteration, 2 represents the second adversarial sample of the i-th -1-th internal iteration at the j-th external iteration, L 2 represents the loss function of the target node, L tgt represents the loss function of the non-target node, λ nt represents the weight factor, X′ represents the adversarial sample, Y represents the true delay value at the future τ time steps on each node, B represents the target threshold, θ represents the target model parameters, nt represents the loss function of the non-target node at the i-th -1-th internal iteration in the j-th external iteration. 1 In this embodiment, the loss function of the non-target node is used to measure the loss of the prediction on the non-target node relative to the true value Y. The loss function of the non-target node is used as a regularization term to constrain the impact of the attack on the non-target node, and the weight factor λ 2 is used to control the loss functions of the target node and the non-target node, which are specifically as follows:

[0125] is used to measure the loss of the prediction on the non-target node relative to the true value Y. The loss function of the non-target node is used as a regularization term to constrain the impact of the attack on the non-target node, and the weight factor λ nt is used to control the loss functions of the target node and the non-target node, which are specifically as follows:

[0126]

[0127] Among them, represents the loss function of the non-target node at the i-th 2 -th internal iteration in the j-th external iteration, |T| represents the number of victim nodes, τ represents the future time steps to be predicted on the target node, v represents the non-target node, Y v,q,arr represents the true arrival delay value of node v at the q-th time step, Y v,q,depDenote the true value of the takeoff delay of node v at the q-th time step, where v ∈ {V - T}, q ∈ [t + 1:t + τ], and |V| represents the total number of nodes. Denote the 1 i-th 2 internal iteration in the j-th external iteration, and the predicted value of the arrival delay of node v at the q-th time step. 1 Denote the 2 i-th

[0128] internal iteration in the j-th 1 external iteration, and the predicted value of the takeoff delay of node v at the q-th time step. 2 Furthermore, based on the momentum gradient, the third binary tensor of the victim node, and the second adversarial sample of the (i - 1)-th 1 internal iteration in the j-th 2 external iteration, perform a projection to obtain the second updated adversarial sample (the second adversarial sample of the i-th 1 internal iteration in the j-th 2 external iteration), which is specifically as follows:

[0129]

[0130] where, denotes the second updated adversarial sample (the second adversarial sample of the i-th 2 internal iteration in the j-th I external iteration), M ε denotes the third binary tensor of the victim node, ∏ a (·) represents the projection operation, α denotes the second adversarial sample of the (i - 1)-th 1 internal iteration in the j-th 2 external iteration.

[0131] In this embodiment, if the internal iteration included in the j-th 1 external iteration is executed N 1 times, then the second adversarial sample of the N-th internal iteration in the j-th external iteration 1 (the second adversarial sample output by the j-th external iteration) is obtained on the basis of the second initial sample after cumulative perturbation, and is updated through N 1 times of MIM iteration. It contains the information after perturbing the subset of victim nodes.

[0132] Furthermore, when the internal iteration is N1 After that, according to the j 1 -th external iteration, output the second adversarial example Recalculate the second saliency of each non-target node to measure the second saliency of each non-target node of the second adversarial example output based on the j 1 -th external iteration, that is, the ability of each non-target node of the second adversarial example output based on the j 1 -th external iteration to affect L tgt :

[0133]

[0134] Among them, represents the second saliency of the non-target node v updated in the j 1 -th external iteration, represents the component of the second adversarial example output in the j 1 -th external iteration on the non-target node v.

[0135] Furthermore, determine the attack success rate (i.e., the proportion of data points whose predicted values cross the target threshold) achieved by the second adversarial example output in the j 1 -th external iteration. According to the size relationship between the attack success rate of the j 1 -th external iteration and the target success rate, determine how to update the left pointer and the right pointer included in the binary search indicator.

[0136] Specifically, when the attack success rate achieved by the second adversarial example output in the j-th external iteration is greater than the target success rate then update the right pointer included in the binary search indicator based on r = m; if the attack success rate achieved by the second adversarial example output in the j-th external iteration is greater than the target success rate then update the left pointer included in the binary search indicator based on l = m + 1.

[0137] It should be noted that after each update of the binary search indicator, it is necessary to execute the binary search outer loop and the inner loop nested in the binary search outer loop again until the binary search area becomes empty, that is, l = r, then the binary search ends and the final subset of victim nodes I is obtained.

[0138] It should be noted that for the binary search outer loop provided in step 102 and the MIM inner loop nested therein, if the target success rate is never achieved during the binary search process, it is still necessary to supplement the iteration for the case of I = V - T (that is, all non-target nodes are used as victim nodes), that is, supplement and execute the inner loop once.

[0139] ​In step 103, this step includes refining the outer loop nested with the MIM inner loop, which involves gradually refining the outer loop and nesting the MIM inner loop.

[0140] Specifically, for the first gradual refinement of the outer loop, j 2 = 1:

[0141] Remove the node with the second lowest significance from the final victim node subset obtained based on step 102 to obtain the second victim node subset for the j 2 -th outer iteration.

[0142] Furthermore, take the intersection of the second victim node subset in the current iteration (the j 2 -th outer iteration) and the second victim node subset in the previous iteration (the j 2 -1 -th outer iteration), and accumulate the perturbations on the intersection to a certain extent with the first attenuation coefficient β, that is, obtain the third initial sample for the j 2 -th outer iteration as follows:

[0143]

[0144] Where, represents the third binary tensor, represents the third adversarial sample output in the j 2 -1 -th outer iteration, represents the third initial sample for the j 2 -th outer iteration, X represents the first initial sample, and β represents the first attenuation coefficient.

[0145] Set the inner loop iteration, and the loop condition is from i 3 = 1 to i 3 = N 2 , and the specific inner loop iteration can refer to step 102, which will not be elaborated here.

[0146] In this embodiment, if the inner iteration included in the j 2 -th outer iteration has been executed N 2 times, then the third adversarial sample in the N 2 -th inner iteration in the j 2 -th outer iteration (the third adversarial sample output in the r -th outer iteration ), and the third adversarial sample output in the j 2 -th outer iteration is obtained by updating through N times of MIM iteration on the basis of the third initial sample 2 after accumulating perturbations, and it contains the information after perturbing the victim node subset.

[0147] Further, when the internal iteration is N 2 times, according to the j 2 th external iteration, the third adversarial example is output Recalculate the third significance of each non-target node to measure the third significance of each non-target node for the third adversarial example output based on the jth external iteration, that is, the ability of each non-target node for the third adversarial example output based on the rth external iteration to affect L tgt :

[0148]

[0149] Wherein, represents the third significance of the non-target node v updated in the j 2 th external iteration,

[0150] represents the component of the third adversarial example output in the rth external iteration on the non-target node v.

[0151] Further, determine the attack success rate (i.e., the proportion of data points whose predicted values cross the target threshold) achieved by the third adversarial example output in the j 2 th external iteration. According to the size relationship between the attack success rate of the j 2 th external iteration and the target success rate, determine whether the attack is successful.

[0152] Specifically, when the attack success rate achieved by the third adversarial example output in the j 2 th external iteration is greater than the target success rate then based on the second victim node subset in the j 2 th external iteration, remove the node with the lowest second significance from it to obtain the second victim node subset in the j 2 +1th external iteration. Further, according to the second victim node subset in the j 2 +1th external iteration and the second victim node subset in the j 2 th external iteration, obtain the third initial sample in the j 2 +1th external iteration. Then set the internal loop iteration, and the loop condition is from i 3 =1 to i 3 =N 2 , and then determine the attack success rate achieved by the third adversarial example output in the j 2 +1th external iteration.

[0153] In the embodiments of the present invention, if there is only 1 node remaining in the second victim node subset in the j 2 +1th external iteration, it can be confirmed that the algorithm ends; or, if in the j2 The attack success rate achieved by the third adversarial sample in the +1-th external iteration is less than both the target success rate and the attack success rate achieved by the third adversarial sample in the j-th 2 external iteration, and the attack success rate achieved by the third adversarial sample in the j-th 2 +2-th external iteration is less than the attack success rate achieved by the third adversarial sample in the j-th 2 external iteration, and the attack success rate achieved by the third adversarial sample in the +1-th external iteration, then the algorithm can also be confirmed to end.

[0154] Furthermore, if the attack success rate achieved by the third adversarial sample in any external iteration has never reached (less than) the target success rate, it is considered an attack failure; if the attack success rate achieved by the third adversarial sample in any external iteration has once reached (greater than or equal to) the target success rate, it is considered an attack success, and the subset of victim nodes at the last time of reaching is determined as the minimum subset of victim nodes, and the corresponding adversarial perturbation is the final adversarial perturbation.

[0155] To more clearly explain the method provided by the embodiments of the present invention, the following introduces in detail the adversarial attack method for the prediction model provided by the embodiments of the present invention in combination with two embodiments.

[0156] Embodiment 1

[0157] There are |V| = 10 airport nodes in an aviation network, which are v 1 , v 2 , v 3 , …, v 10 , in the actual application scenario, V can be a set composed of all civilian airports in a certain country or region. The subset of target nodes T = {v 1 , v 2}, in the actual scenario, T may include some important hub airports, and the attacker attempts to manipulate the future flight delay predictions of these key airports (important hub airports). The subset of victim nodes I is initially empty, I ∩ T = 0, in the actual scenario, these airport nodes are not key airports, but the attacker indirectly affects the target nodes by imposing perturbations on the historical delay data of the victim nodes.

[0158] The target success rate R = 0.7, the target threshold B = 15 (unit: minute, assuming the delay time is calculated in minutes), the perturbation amplitude limit ε = 3 (unit: minute), the number of PGD iterations Q for initial significance calculation = 3, and the corresponding step size The number of MIM iterations N for adversarial perturbation generation = 5, and the corresponding step size The momentum gradient decay coefficient μ = 0.8, and the weight factor λ of the non-target node loss nt= 0.2, the decay coefficient β in the perturbation accumulation is 0.7. At the same time, assume that the historical time step h = 2 and the future time step τ = 4.

[0159] In this embodiment, a prediction model f with parameter θ is used θ (·), and the average arrival and departure delays X = X of each airport node at the historical h time steps are utilized t-h+1:t to predict the average arrival and departure delays of each airport node at the future τ time steps. When an attacker attempts to manipulate the future delay predictions of some key airports, the data of these airport nodes may be difficult to directly attack due to more stringent security measures and other reasons. However, by leveraging the propagation law of flight delays in the network, the attacker can indirectly manipulate the future delay predictions on the target nodes by implementing perturbations at some relatively less critical airport nodes.

[0160] Step 201, this step performs the PGD loop and calculates the first significance value of each non-target node using gradient information, where the number of PGD iterations Q = 3 and the iteration step size is

[0161] Step 201-1, let the clean sample X be a 10×2 matrix, representing the average arrival and departure delay data of 10 airport nodes at 2 historical time steps. The initial adversarial sample X ′(0) = X. And set the loop condition for the first PGD loop, from i 1 = 1 to i 1 = Q.

[0162] Step 201-2, the first PGD loop (i 1 = 1):

[0163] First, determine the loss function of the target node:

[0164] Calculate the loss of the target node for the arrival delay feature row: For the target nodes v 1 and v 2 , at the future τ = 4 time steps, the arrival delay prediction value of the target node v 1 is obtained through the prediction model The arrival delay prediction value of the target node v 2 is

[0165] Furthermore, according to the distance operator formula (assuming k = 2), calculate and Suppose, for

[0166] Similarly, calculate other values and then obtain

[0167]

[0168] Correspondingly, the target node loss of the takeoff delay feature row can be calculated: for the target node v 1 and v 2 , at the next τ = 4 time steps, the takeoff delay prediction value of the target node v 1 is obtained through the prediction model The takeoff delay prediction value of the target node v 2 The takeoff delay prediction value of Calculate

[0169] Since it is the first iteration, the adaptive weights on the takeoff delay feature and the arrival delay feature are respectively and

[0170] Furthermore, determine the loss of the model prediction on the target node relative to the target threshold (target node loss function) through formula (8), that is

[0171] Calculate the gradient g of the target node loss function with respect to the first adversarial sample (1) , assuming the gradient value of the non-target node v 3 is Then update the adversarial sample X ′(1) .

[0172] Step 201-3, the second PGD iteration (i 1 = 2):

[0173] Recalculate Calculate the new gradient g (2) , update the adversarial sample X ′(2) .

[0174] Step 201-4, the third PGD iteration (i 1 = 3):

[0175] Re-execute the above process to obtain the first adversarial sample X in the 3rd iteration ′(3) (Iteratively output the first adversarial sample X′).

[0176] Step 201-5, calculate the initial significance value of the non-target node, according to the first adversarial sample X in the 3rd iteration ′(3)(Iteratively output the first adversarial example \(X'\)), calculate the first saliency of each non-target node through formula (11), such as non-target node \(v\). 3 The first saliency

[0177] Step 202, binary search to determine the preliminary candidate range of the victim node (binary search loop nested in the MIM loop): Initialize the binary search indicator: left pointer \(l = 0\), right pointer \(r=|V| + 1=11\).

[0178] Step 202-1, the first iteration of the binary search loop (\(j\) 1 \(=1\)), calculate the midpoint of the binary search:

[0179] Update the subset of victim nodes According to the first saliency of non-target nodes, select the 5 non-target nodes with the highest saliency, such as \(v\) 3 , \(v\) 4 , \(v\) 5 , \(v\) 6 , \(v\) 7 , to form \(I\) (1) .

[0180] Perturbation accumulation operation:

[0181] Generate adversarial examples by MIM iteration (inner loop):

[0182] The first iteration of MIM (\(i\) 2 \(=1\)): Calculate the loss of the total loss function of the \(i\) 2 -th inner iteration in the \(j\) (Assume \(L\) tgt \(=25\), ), calculate the momentum gradient of the first inner iteration in the first outer iteration Get the second updated adversary (The second adversarial example of the first inner iteration in the first outer iteration).

[0183] Step 202-2, from the second to the fifth iteration of MIM, repeat the calculation process, and finally get

[0184] Update the saliency of non-target nodes, such as the second saliency of \(v\) 8

[0185] Calculate the tool success rate and update the indicator. Assume the calculated attack success rate Then \(l=m + 1=6\).

[0186] Step 202-3, the second binary search loop iteration (j 1 = 2), continue to calculate the midpoint, update the victim node subset, etc. until the binary search ends, and obtain the final victim node subset I.

[0187] Step 203, gradually refine and approximate the minimum victim node subset (gradual refinement loop nested MIM loop)

[0188] The first external loop of gradual refinement, (j 2 = 1): Remove the node v with the second lowest significance from the final victim node subset I 9 , and obtain the second victim node subset for the j 2 = 1st external iteration.

[0189] Perform perturbation accumulation, adversarial sample generation, and node significance update: Obtain new adversarial samples and updated non-target node significance values.

[0190] Update the attack success rate: Assume Continue the loop.

[0191] The second external loop of gradual refinement, (j 2 = 2): Repeat the above steps until the end condition is met, and determine the minimum victim node subset and the final adversarial perturbation.

[0192] Example 2

[0193] To visually display the effect of the indirect targeted attack method provided by the embodiments of the present invention, the model prediction results before and after the attack in a scenario are visualized. The dataset used contains 50 airport nodes, and the range of the delay data statistically in the dataset is [-30min, 30min]. The target model for the attack is STPN (SpatioTemporal Propagation Network), which uses the historical delay data of 36 time steps to predict the future delay of 12 times. Select the 10 airports closest to Shanghai Pudong International Airport in the dataset as the target nodes, set the target threshold B = 15min, the target success rate R = 40%, the perturbation amplitude limit ε = 20min, the number of PGD iterations Q = 5 for initial significance calculation, the corresponding step size α s = ε / Q = 4min, the number of MIM iterations N = 7 for adversarial perturbation generation, the corresponding step size α a = ε / N ≈ 2.857min, the corresponding momentum gradient decay coefficient μ = 0.6, the weight factor λ of the non-target node loss nt = 0.2, and the decay coefficient β in perturbation accumulation = 0.8.

[0194] In this scenario, the delay data on 5 peripheral victim nodes is perturbed, such that the delay levels predicted by the STPN model on 10 target nodes increase significantly.

[0195] Based on the same inventive concept, an embodiment of the present invention provides an adversarial attack device for a prediction model. Since the principle of this device for solving technical problems is similar to the adversarial attack method for a prediction model, the implementation of this device can refer to the implementation of the method, and repeated parts will not be elaborated.

[0196] Figure 2 The structural schematic diagram of the adversarial attack device for a prediction model provided by an embodiment of the present invention is as Figure 2 shown. The device includes: a first obtaining unit 201, a second obtaining unit 202, and a determining unit 203.

[0197] The first obtaining unit 201 is configured to determine the average arrival data and takeoff delay data of flights at each node in the historical time step as the first initial sample, project according to the gradient of the current iteration of the first adversarial sample of the target node loss function and the first binary tensor of the non-target nodes, to obtain the first updated adversarial sample; according to the iterative output of the first adversarial sample, the target node loss function, and the gradient of the iterative output of the first adversarial sample on each of the non-target nodes, obtain the first significance.

[0198] The second obtaining unit 202 is configured to, in the current external iteration, update the first victim node subset according to the increment of the midpoint of the binary search and the first significance, accumulate the intersection of the first victim node subsets in two adjacent external iterations, obtain the second initial sample of the current external iteration, perform internal iteration based on the second initial sample to obtain the output second adversarial sample, update the left pointer and the right pointer of the binary searcher according to the relationship between the attack success rate corresponding to the second adversarial sample and the target success rate. When the binary search interval is empty, determine the first victim node subset as the initial range, and obtain the second significance.

[0199] The determining unit 203 is configured to, in the current external iteration, remove some nodes within the initial range according to the second significance to obtain the second victim subset, accumulate the intersection of the second victim subsets in two adjacent external iterations, obtain the third initial sample of the current external iteration, perform internal iteration based on the third initial sample to obtain the output third adversarial sample. If the attack success rate corresponding to the third adversarial sample is greater than or equal to the target success rate, confirm that the attack is successful, determine the third victim node subset as the minimum victim node subset, and obtain the final adversarial sample according to the final adversarial perturbation and the first initial sample.

[0200] It should be understood that the units included in the adversarial attack device for the prediction model above are only logical divisions based on the functions realized by the device. In actual applications, the above units can be superimposed or split. Moreover, the functions realized by the adversarial attack device for the prediction model provided in this embodiment correspond one by one to the adversarial attack method for the prediction model provided in the above embodiment. For the more detailed processing flow realized by this device, it has been described in detail in the first method embodiment above, and will not be described in detail here.

[0201] Another embodiment of the present invention also provides a computer device, which includes: a processor and a memory; the memory is used to store computer program code, and the computer program code includes computer instructions; when the processor executes the computer instructions, the electronic device executes each step of the adversarial attack method for the prediction model in the method flow shown in the above method embodiment.

[0202] Another embodiment of the present invention also provides a computer-readable storage medium, in which computer instructions are stored. When the computer instructions run on a computer device, the computer device is caused to execute each step of the adversarial attack method for the prediction model in the method flow shown in the above method embodiment.

[0203] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they know the basic creative concept. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications falling within the scope of the present invention.

[0204] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. The adversarial attack method for the prediction model is characterized by: include: The average flight arrival data and takeoff delay data of each node in the historical time step are determined as the first initial sample, and the first updated adversarial sample is obtained according to the gradient of the first adversarial sample of the current iteration of the target node loss function and the first binary tensor of the non-target node for projection; the first significance is obtained according to the gradient of the iterative output first adversarial sample, the target node loss function and the iterative output first adversarial sample on each of the non-target nodes; In the current external iteration, the first victim node subset is updated according to the increment of the binary search midpoint and the first significance, the intersection of the first victim node subsets of two adjacent external iterations is accumulated to obtain the second initial sample of the current external iteration, the internal iteration is performed based on the second initial sample to obtain the output second adversarial sample, the left pointer and the right pointer of the binary searcher are updated according to the relationship between the attack success rate and the target success rate corresponding to the second adversarial sample, when the binary search interval is empty, the first victim node subset is determined as the initial range, and the second significance is obtained; In the current external iteration, some nodes in the initial range are removed according to the second significance to obtain the second victim subset, and the intersection of the second victim subsets of two adjacent external iterations is accumulated to obtain the third initial sample of the current external iteration. An internal iteration is performed based on the third initial sample to obtain an output third adversarial sample. If the attack success rate corresponding to the third adversarial sample is greater than or equal to the target success rate, the attack is confirmed to be successful, and the third victim node subset is determined as the minimum victim node subset. The final adversarial sample is obtained according to the final adversarial perturbation and the first initial sample.

2. The method according to claim 1, characterized in that The updating of the left pointer and the right pointer of the binary searcher according to the relationship between the attack success rate and the target success rate corresponding to the second adversarial sample specifically includes: If the attack success rate of the second adversarial sample output by the current external iteration is greater than or equal to the target success rate, then the right pointer included in the binary search indicator is updated based on r=m; or, if the attack success rate of the second adversarial sample output by the current external iteration is less than the target success rate, the left pointer included in the binary search indicator is updated based on l=m+1, where r represents the right pointer, m represents the midpoint of the binary search, and l represents the left pointer; When the binary search interval is empty, the first victim node subset is determined as an initial range, and a second significance is obtained, further comprising: If the attack success rate corresponding to the second adversarial sample is greater than or equal to the target success rate, the first victim node subset corresponding to the current external iteration is determined as the initial range; if the attack success rate corresponding to the second adversarial sample is less than the target success rate, the victim nodes are selected from the non-target nodes and added to the first victim node subset according to the second significance determined by the previous external iteration.

3. The method according to claim 1, characterized in that The updating of the first victim node subset according to the increment of the binary search midpoint and the first significance specifically includes: If the increment of the midpoint of the binary search is greater than zero, select Δm nodes with the second highest significance from the non-target nodes according to the second significance determined in the previous external iteration and add them to the first victim node subset to obtain the first victim node subset of the current external iteration; or If the increment of the midpoint of the binary search is less than zero, according to the second significance determined by the previous external iteration, select the (-Δm) nodes with the lowest second significance and remove them from the first victim node subset corresponding to the previous external iteration to obtain the first victim node subset of the current external iteration, where Δm is equal to the increment of the midpoint of the binary search.

4. The method according to claim 1, characterized in that The accumulating the intersection of the first victim node subsets of two adjacent external iterations to obtain the second initial sample of the current external iteration specifically includes: Determine the intersection of the first victim node subset corresponding to the current external iteration and the first victim node subset corresponding to the previous external iteration, accumulate the disturbance on the intersection with the first attenuation coefficient, and obtain the second initial sample of the current external iteration as shown below: The accumulating the intersection of the second victim subsets of two adjacent external iterations to obtain the third initial sample of the current external iteration specifically includes: in, represents the second initial sample of the j1th external iteration, represents the second binary tensor, represents the second adversarial sample outputted at the j1-1th external iteration, X represents the first initial sample, and β represents the first attenuation coefficient; represents the third binary tensor, It means that the j2-1th external iteration outputs the third adversarial sample, represents the third initial sample of the j2th external iteration.

5. The method according to claim 1, characterized in that The step of performing internal iteration based on the second initial sample to obtain an output second adversarial sample specifically includes: The momentum gradient of the current internal iteration in the current external iteration is obtained according to the momentum gradient of the previous internal iteration in the current external iteration, the total loss function of the previous internal iteration in the current external iteration, and the second adversarial example of the previous internal iteration in the current external iteration; Projecting the momentum gradient of the current internal iteration in the current external iteration, the second adversarial sample of the previous internal iteration in the current external iteration, and the step size of the internal iteration to obtain a second updated adversarial sample; in, represents the momentum gradient of the i2th inner iteration in the j1th outer iteration, represents the momentum gradient of the i2-1th internal iteration in the j1th external iteration, μ represents the second decay coefficient, ||·||1 represents the sum of the absolute values ​​of all elements, represents the second adversarial example of the i2-1th internal iteration in the j1th external iteration, represents the total loss function of the i2-1th internal iteration in the j1th external iteration, represents the second updated adversarial sample, M I The third binary tensor representing the victim node, ∏ ε (·) represents the projection operation, α a Indicates the step size of the internal iteration.

6. The method according to claim 1, characterized in that The step of obtaining a first updated adversarial sample by projecting the gradient of the first adversarial sample of the current iteration of the target node loss function and the first binary tensor of the non-target node specifically includes: Determine the gradient of the first adversarial sample of the current iteration of the target node loss function according to the current iteration target node loss function, the first adversarial sample of the previous iteration, the target threshold and the target model parameters; perform projection according to the gradient of the first adversarial sample of the current iteration of the target node loss function, the iteration step of the current iteration, the first binary tensor of the non-target node and the first adversarial sample of the previous iteration to obtain a first updated adversarial sample; in, represents the gradient of the first adversarial sample of the target node loss function at the i1th iteration, Represents the first adversarial sample X′ obtained for the i1-1th iteration (i-1) Find the gradient, represents the first adversarial sample of the i1-1th iteration, B represents the target threshold, θ represents the target model parameter, represents the target node loss function for the i1th iteration, represents the first updated adversarial sample, ∏ ε (·) represents the projection operation, α s represents the iterative step size of PGD projected gradient descent, M V-T The first binary tensor representing the non-target nodes.

7. The method according to claim 1, characterized in that If the attack success rate corresponding to the third adversarial sample is greater than or equal to the target success rate, the attack is confirmed to be successful, and the third victim node subset is determined as the minimum victim node subset. Before obtaining the final adversarial sample according to the final adversarial perturbation and the first initial sample, the method further includes: If the third victim node subset includes only one victim node, the current external iteration is confirmed to be finished; or the attack success rate corresponding to the third adversarial sample in the current external iteration is less than the target success rate, the attack success rate corresponding to the third adversarial sample in the previous external iteration is less than the target success rate, and the attack success rate corresponding to the third adversarial sample in the current external iteration is less than the attack success rate corresponding to the third adversarial sample in the previous external iteration, the current external iteration is confirmed to be finished.

8. The method according to claim 1, characterized in that The first significance is as follows: Among them, S v(0) represents the first saliency of the non-target node v, It represents the component of the first adversarial sample X′ on the non-target node v, X′ represents the first adversarial sample outputted iteratively, represents the gradient operation, ||·|| F represents the Frobenius norm.

9. A device for attacking a prediction model, characterized in that: include: A first obtaining unit is used to determine the average flight arrival data and takeoff delay data of each node in the historical time step as the first initial sample, and project the gradient of the first adversarial sample of the current iteration of the target node loss function and the first binary tensor of the non-target node to obtain a first updated adversarial sample; Obtaining a first saliency according to the iteratively output first adversarial sample, the target node loss function, and the gradient of the iteratively output first adversarial sample on each of the non-target nodes; A second obtaining unit is used to update the first victim node subset according to the increment of the binary search midpoint and the first significance in the current external iteration, accumulate the intersection of the first victim node subsets of two adjacent external iterations, obtain the second initial sample of the current external iteration, perform internal iteration based on the second initial sample to obtain an output second adversarial sample, update the left pointer and the right pointer of the binary searcher according to the relationship between the attack success rate and the target success rate corresponding to the second adversarial sample, and when the binary search interval is empty, determine the first victim node subset as the initial range, and obtain the second significance; A determination unit is used to remove some nodes in the initial range according to the second significance in the current external iteration to obtain a second victim subset, accumulate the intersection of the second victim subsets of two adjacent external iterations to obtain a third initial sample of the current external iteration, perform internal iteration based on the third initial sample to obtain an output third adversarial sample, if the attack success rate corresponding to the third adversarial sample is greater than or equal to the target success rate, confirm that the attack is successful, determine the third victim node subset as the minimum victim node subset, and obtain a final adversarial sample according to the final adversarial perturbation and the first initial sample.

10. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the anti-attack method for the prediction model according to any one of claims 1 to 8.

Citation Information

Cited By

  • Adversarial sample generation method, system and device in combination with disturbance evolution in sample and disturbance amplitude normalization, and storage medium

    CN120932075A