On Poisoning Attacks and Defenses for LSTM Time Series Prediction Models: Speed Prediction as an Example
Yiyu Chen, Hui-Nien Hung, Shun‐Ren Yang, Chia-Cheng Yen, Phone Lin · 2024
The Long Short-Term Memory (LSTM) model has significantly improved time series prediction accuracy, but also brought forth concerns regarding reliability and security with its widespread adoption, particularly in the context of poisoning attacks. While there is substantial research on attacks and defenses for LSTM models, there’s limited focus on LSTM time series prediction models. In this paper, we propose an arithmetic-based poisoning attack methodology for a demonstrative LSTM time series speed prediction model. Furthermore, we employ the “red team/blue team exercises” commonly used in network security to develop defense strategies using support vector machine and linear regression analysis methods. Through the system-level simulation experiments, we verify the effectiveness of our proposed methodology. Our experiment results indicate that, regarding attacks, our methodology can identify the optimal attacks for the representative road segments. As for defenses, we demonstrate that the defended model’s performance is close to the real model’s performance.