详细信息
Adversarial attacks on industrial soft sensors: Multi-target attacks based on diffusion models ( SCI-EXPANDED收录 EI收录)
文献类型:期刊文献
英文题名:Adversarial attacks on industrial soft sensors: Multi-target attacks based on diffusion models
作者:Jiang, Qingchao[1];Fan, Shihao[1];Zhu, Zhiying[1];Hou, Zhenxuan[1];Zhong, Weimin[1];Tan, Lei[2];Qian, Zhenxing[2];Zhang, Xinpeng[2]
机构:[1]East China Univ Sci & Technol, Sch Informat Sci & Engn, Shanghai 200237, Peoples R China;[2]Fudan Univ, Coll Comp Sci & Artificial Intelligence, Shanghai 200433, Peoples R China
年份:2026
卷号:725
外文期刊名:INFORMATION SCIENCES
收录:;EI(收录号:20254119301471);WOS:【SCI-EXPANDED(收录号:WOS:001591442600001)】;
基金:Acknowledgement This work was supported by the National Natural Science Foundation of China under Grant (62402182, 62572125) , and the Natural Science Foundation of Shanghai under Grant 25ZR1401019. The authors are extremely grateful to the editors and anonymous reviewers for their insightful and constructive comments on this work.
语种:英文
外文关键词:Multi-target adversarial examples; Soft sensors; Diffusion models
摘要:Industrial soft sensors serve as critical instruments for real-time monitoring and quality prediction in complex industrial systems, including chemical processing and energy production. While adversarial attacks on these sensors have garnered extensive attention, a critical gap persists: existing methods are fundamentally limited to single-target objectives. They fail to address inherent multi-variable couplings in industrial processes, limiting applicability in real-world scenarios requiring coordinated control of interdependent variables. To bridge this gap, this paper introduces a multi-target adversarial example attack framework based on diffusion models (DMAA) for the first time, which integrates noise scheduling and inverse denoising processes to generate adversarial examples that are more reasonable and invisible. The framework incorporates a multi-target attack optimization module, which facilitates targeted bias control for several key variables after the noise is added. Subsequently, it leverages a multilayer perceptron to effectively predict noise and generate adversarial examples, thereby driving the multi-target prediction outcomes to diverge from the actual ground truth. In case study of the sulfur recovery unit dataset (SRU), compared to existing methods, the proposed method shows significant advantages in attack effectiveness and stealth, providing new insights for the security evaluation and defense mechanism design of industrial soft sensors.
参考文献:
正在载入数据...
