Black-Box Adversarial Attack on Time Series Classification
Daizong Ding, Mi Zhang, Fuli Feng, Yuanmin Huang, Erling Jiang, Min Yang
Abstract
With the increasing use of deep neural networks (DNN) in time series classification (TSC), recent work reveals the threat of adversarial attack, where the adversary can construct adversarial examples to cause model mistakes. However, existing research on the adversarial attack of TSC typically adopts an unrealistic white-box setting with model details transparent to the adversary. In this work, we study a more rigorous black-box setting with attack detection applied, which restricts gradient access and requires the adversarial example to be also stealthy. Theoretical analyses reveal that the key lies in: estimating black-box gradient with diversity and non-convexity of TSC models resolved, and restricting the ℓ0 norm of the perturbation to construct adversarial samples. Towards this end, we propose a new framework named Black-TreeS, which solves the hard optimization issue for adversarial example construction with two simple yet effective modules. In particular, we propose a tree search strategy to find influential positions in a sequence, and independently estimate the black-box gradients for these positions. Extensive experiments on three real-world TSC datasets and five DNN based models validate the effectiveness of BlackTreeS, e.g., it improves the attack success rate from 19.3% to 27.3%, and decreases the detection success rate from 90.9% to 6.8% for LSTM on the UWave dataset.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e53bdec8-c886-4219-bd7f-c845eb625d74Cited by top-tier papers6
- Taxonomy Driven Fast Adversarial TrainingKun Tong, Chengze Jiang, Jie Gui, Yuan CaoAAAI 2024 · 2 citations
- Differentiable Adversarial Attacks for Marked Temporal Point ProcessesPritish Chakraborty, Vinayak Gupta, Rahul R, Srikanta J. Bedathur et al.AAAI 2025 · 1 citation
- Exposing Vulnerabilities in Explanation for Time Series Classifiers via Dual-Target AttacksBohan Wang, Zewen Liu, Lu Lin, Hui Liu et al.ICML 2026 · 1 citation
- TSFAdv: Frequency-Guided Black-Box Adversarial Attacks on Time Series ForecastingQizhuo Han, Xiangrui Cai, Sihan Xu, Ying Zhang et al.ICML 2026
- Beyond Immediate Activation: Temporally Decoupled Backdoor Attacks on Time Series ForecastingZhixin Liu, Xuanlin Liu, Sihan Xu, Yaqiong Qiao et al.AAAI 2026
Builds on3
- Heuristic Black-Box Adversarial Attacks on Video Recognition ModelsZhipeng Wei, Jingjing Chen, Xingxing Wei, Linxi Jiang et al.AAAI 2020 · 84 citations
- A Transformer-based Framework for Multivariate Time Series Representation LearningGeorge Zerveas, Srideepika Jayaraman, Dhaval Patel, Anuradha Bhamidipaty et al.KDD 2021 · 66 citations
- Lipschitz Recurrent Neural NetworksN. Benjamin Erichson, Omri Azencot, Alejandro F. Queiruga, Liam Hodgkinson et al.ICLR 2021 · 32 citations
Related papers
- A Hard Label Black-box Adversarial Attack Against Graph Neural NetworksJiaming Mu, Binghui Wang, Qi Li, Kun Sun et al.CCS 2021 · 30 citations
- Query-Based Black-Box Stealthy Sensor Attacks on Cyber-Physical SystemsShixiong Jiang, Weizhe Xu, Mengyu Liu, Fanxin KongDAC 2025
- Towards Backdoor Attack on Deep Learning based Time Series ClassificationDaizong Ding, Mi Zhang, Yuanmin Huang, Xudong Pan et al.ICDE 2022 · 17 citations
- Adversarial Defense via Learning to Generate Diverse AttacksYunseok Jang, Tianchen Zhao, Seunghoon Hong, Honglak LeeICCV 2019 · 88 citations
- Seeing is Not Believing: Adversarial Natural Object Optimization for Hard-Label 3D Scene AttacksDaizong Liu, Wei HuCVPR 2025
