Towards Backdoor Attack on Deep Learning based Time Series Classification
Daizong Ding, Mi Zhang, Yuanmin Huang, Xudong Pan, Fuli Feng, Erling Jiang, Min Yang
摘要
As a fundamental task in modern data mining, time series classification is powering mission-critical tasks including stock price prediction and network traffic analysis. Due to the non-linear structure of deep neural networks (DNN), deep learning has established as a promising solution to time series classification. However, the excessive learning capacity of DNNs may make them prone to threats of backdoor attacks, where an attacker embeds hidden functionalities (i.e., backdoor) to DNNs and activates the backdoor by specially-designed inputs (i.e., triggers). Despite extensive studies concerning backdoor attacks on image and text domains, there is little known about the vulnerability of DNN based time series classifiers against backdoor attacks. Due to the unique characteristics of time series data, most existing backdoor attack techniques fail to threaten time series classifiers. In this paper, through analyzing the key factors which influence the effectiveness of a backdoor, we systematize a list of practical principles for designing triggers on time series data. In this light, we propose a novel framework called TimeTrojan, which aims to learn to form the trigger pattern through a constrained multi-objective optimization. To solve the hereafter challenging optimization issue, we further design an iterative learning algorithm. Remarkably, the proposed framework is agnostic to a wide range of DNN classifiers. Extensive empirical results on 6 representative DNN classifiers and 6 real-world datasets validate the effectiveness of the proposed attack framework. In most cases, TimeTrojan successfully injects backdoors with 100% attack success rate without affecting the model accuracy on clean samples, which implies the complete control of the behavior of the DNN classifiers by the adversary.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
引用它的顶会 Paper6
- TSGBench: Time Series Generation BenchmarkYihao Ang, Qiang Huang, Yifan Bao, Anthony K. H. Tung 等VLDB 2024 · 被引用 35 次
- BackTime: Backdoor Attacks on Multivariate Time Series ForecastingXiao Lin, Zhining Liu, Dongqi Fu, Ruizhong Qiu 等NeurIPS 2024 · 被引用 25 次
- AimTS: Augmented Series and Image Contrastive Learning for Time Series ClassificationYuxuan Chen, Shanshan Huang, Yunyao Cheng, Peng Chen 等ICDE 2025 · 被引用 5 次
- Revisiting Backdoor Attacks on Time Series Classification in the Frequency DomainYuanmin Huang, Mi Zhang, Zhaoxiang Wang, Wenxuan Li 等WWW 2025 · 被引用 5 次
- Beyond Immediate Activation: Temporally Decoupled Backdoor Attacks on Time Series ForecastingZhixin Liu, Xuanlin Liu, Sihan Xu, Yaqiong Qiao 等AAAI 2026
相关 Paper
- Deep Feature Space Trojan Attack of Neural Networks by Controlled DetoxificationSiyuan Cheng, Yingqi Liu, Shiqing Ma, Xiangyu ZhangAAAI 2021 · 被引用 191 次
- TrojanFlow: A Neural Backdoor Attack to Deep Learning-based Network Traffic ClassifiersRui Ning, Chunsheng Xin, Hongyi WuINFOCOM 2022 · 被引用 27 次
- An Embarrassingly Simple Approach for Trojan Attack in Deep Neural NetworksRuixiang Tang, Mengnan Du, Ninghao Liu, Fan Yang 等KDD 2020 · 被引用 164 次
- T-Miner: A Generative Approach to Defend Against Trojan Attacks on DNN-based Text ClassificationAhmadreza Azizi, Ibrahim Asadullah Tahmid, Asim Waheed, Neal Mangaokar 等USENIX Security 2021 · 被引用 98 次
- UNICORN: A Unified Backdoor Trigger Inversion FrameworkZhenting Wang, Kai Mei, Juan Zhai, Shiqing MaICLR 2023 · 被引用 7 次
