发表机构
The University of Arizoan(亚利桑那大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对基于图的交通预测的鲁棒性,提出物理感知检测器与强化预测器结合的检测-缓解防御,在多数模型-数据集设置中优于对抗训练,能有效应对针对性物理感知攻击。
AI 中文摘要
基于图的人工智能交通预测是智能交通系统的关键组成部分,推动了针对恶意传感器读数鲁棒性的安全研究。我们认为,先前的鲁棒性评估在很大程度上受不切实际的威胁模型和无针对性目标的影响,因此必须重新审视攻击和防御方法。我们研究了一种实用的攻击者,其模型知识有限,且只能监控和操纵少数道路传感器。更重要的是,实用攻击可以定位到特定路段或路线,导致估计到达时间错误或不必要的路线重定向,同时对整个网络影响很小。这种针对性设置尚未得到充分探索,而诸如对抗训练之类的防御方法,从它们所训练的范数有界攻击,到结构不同、模拟真实拥堵的物理感知攻击,迁移效果不佳。因此,我们将鲁棒性重新定义为检测问题,引入一种学习到的物理感知检测器,其输出作为输入特征提供给强化预测器,并在预测器固定的情况下针对自适应攻击进行训练。我们在多种模型架构和基准上进行了评估。物理感知攻击使目标路段的误差增加了数倍,而全网误差几乎没有变化;针对范数有界扰动调整的对抗训练几乎无法削弱该攻击。我们的检测-缓解防御在15种模型-数据集设置中的13种上,甚至比针对物理感知攻击本身强化的对抗训练表现更好,且在保留的攻击上的提升幅度最大,同时干净样本的性能损失几乎为零。这些结果强调,需要在特定应用约束下研究抽象的人工智能对抗攻击,以评估其真实的安全影响。
英文摘要
Traffic forecasting by graph-based AI is a critical component of intelligent transportation systems, motivating security research on robustness to malicious sensor readings. We argue that prior robustness evaluations are largely shaped by unrealistic threat models and untargeted objectives, so both attacks and defenses must be revisited. We study a practical adversary with limited model knowledge and the ability to monitor and manipulate only a few road sensors. More importantly, practical attacks can be localized to specific links or routes, causing incorrect estimated arrival times or unnecessary rerouting while leaving the broader network largely unaffected. This targeted setting remains underexplored, and defenses such as adversarial training do not transfer well from the norm-bounded attacks they train on to structurally different, physics-aware attacks that mimic genuine congestion. We therefore reframe robustness as a detection problem, introducing a learned physics-informed detector whose output is fed to a hardened forecaster as an input feature and trained against adaptive attacks with the forecaster fixed. We evaluate across a variety of model architectures and benchmarks. The physics-aware attack multiplies target-link error several-fold while the network-wide error barely moves, and adversarial training, tuned to norm-bounded perturbations, barely dents it. Our detection--mitigation defense improves even on adversarial training hardened against the physics-aware attack itself, on $13$ of $15$ model--dataset settings and by the widest margin on a held-out attack, at near-zero clean cost. The results emphasize the need to examine abstracted AI adversarial attacks under application-specific constraints to assess their true security impacts.