Adversarial Observations in Weather Forecasting
Erik Imgrund, Thorsten Eisenhofer, Konrad Rieck
Abstract
AI-based systems, such as Google's GenCast, have recently redefined the state of the art in weather forecasting, offering more accurate and timely predictions of both everyday weather and extreme events. While these systems are on the verge of replacing traditional meteorological methods, they also introduce new vulnerabilities into the forecasting process. In this paper, we investigate this threat and present a novel attack on autoregressive diffusion models, such as those used in GenCast, capable of manipulating weather forecasts and fabricating extreme events, including hurricanes, heat waves, and intense rainfall. The attack introduces subtle perturbations into weather observations that are statistically indistinguishable from natural noise and change less than 0.1% of the measurements—comparable to tampering with data from a single meteorological satellite. As modern forecasting integrates data from nearly one hundred satellites and many other sources operated by different countries, our findings highlight a critical security risk with the potential to cause large-scale disruptions and undermine public trust in weather forecasting.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7f48707b-f3c2-4ee2-a6ad-8fa142cbe49cBuilds on7
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Adversarial Example Does Good: Preventing Painting Imitation from Diffusion Models via Adversarial ExamplesChumeng Liang, Xiaoyu Wu, Yang Hua, Jiaru Zhang et al.ICML 2023 · 200 citations
- DiffDA: a Diffusion model for weather-scale Data AssimilationLangwen Huang, Lukas Gianinazzi, Yuejiang Yu, Peter D. Düben et al.ICML 2024 · 81 citations
- Diffusion Policy Attacker: Crafting Adversarial Attacks for Diffusion-based PoliciesYipu Chen, Haotian Xue, Yongxin ChenNeurIPS 2024 · 23 citations
Related papers
- Adversarial Attacks on Probabilistic Autoregressive Forecasting ModelsRaphaël Dang-Nhu, Gagandeep Singh, Pavol Bielik, Martin T. VechevICML 2020 · 28 citations
- Distracting Downpour: Adversarial Weather Attacks for Motion EstimationJenny Schmalfuss, Lukas Mehl, Andrés BruhnICCV 2023 · 23 citations
- Data-Free Model-Related Attacks: Unleashing the Potential of Generative AIDayong Ye, Tianqing Zhu, Shang Wang, Bo Liu et al.USENIX Security 2025
- U-Cast: A Surprisingly Simple and Efficient Frontier Probabilistic AI Weather ForecasterSalva Ruhling Cachay, Duncan Watson-Parris, Rose YuICML 2026 · 3 citations
- STCast: Adaptive Boundary Alignment for Global and Regional Weather ForecastingHao Chen, Tao Han, Jie Zhang, Song Guo et al.CVPR 2026 · 7 citations
