Adversarial Attacks on Deep Temporal Point Process

Adversarial Attacks on Deep Temporal Point Process
复制标题

DOI:
10.1109/icmla55696.2022.10102767
复制
发表时间:
2022-12
期刊:
2022 21st IEEE International Conference on Machine Learning and Applications (ICMLA)
影响因子:
--
通讯作者:
Samira Khorshidi;Bao Wang;G. Mohler
Samira Khorshidi;Bao Wang;G. Mohler
中科院分区:
其他
文献类型:
--
作者:
Samira Khorshidi;Bao Wang;G. Mohler

文献摘要

相似文献

时点过程有许多应用,从犯罪预测到对地震余震序列进行建模。由于深度学习的灵活性和表现力,基于神经网络的方法最近在对点过程强度进行建模方面表现出了希望。然而,在对抗攻击和对系统的自然冲击方面,缺乏关于这种模型的稳健性的研究。准确地说,虽然神经点过程在样本内测试中的表现可能优于更简单的参数模型,但这些模型在遇到对抗性例子或尖锐的非平稳趋势时的表现仍是未知的。目前的工作提出了几种针对基于深度神经网络建模的时间点过程的白盒和黑盒对抗性攻击。大量实验证实,神经点过程的预测性能和参数建模容易受到敌意攻击。此外,我们以新冠肺炎大流行期间的犯罪数据集为例,评估了这些模型在存在非平稳突变的情况下的脆弱性和性能。
Temporal point processes have many applications, from crime forecasting to modeling earthquake aftershocks sequences. Due to the flexibility and expressiveness of deep learning, neural network-based approaches have recently shown promise for modeling point process intensities. However, there is a lack of research on the robustness of such models in regards to adversarial attacks and natural shocks to systems. Precisely, while neural point processes may outperform simpler parametric models on in-sample tests, how these models perform when encountering adversarial examples or sharp non-stationary trends remains unknown. Current work proposes several white-box and blackbox adversarial attacks against temporal point processes modeled by deep neural networks. Extensive experiments confirm that predictive performance and parametric modeling of neural point processes are vulnerable to adversarial attacks. Additionally, we evaluate the vulnerability and performance of these models in the presence of non-stationary abrupt changes, using the crimes dataset, during the Covid-19 pandemic, as an example.