GENADA: efficient generative time series adversarial attack framework

arXiv:2608.12535 · cs.LG · Submitted 2026-08-12 · Read on arXiv

Michael Baronov, Denis Vorobev, Margarita Rusanova, Petr Sokerin, Alexey Zaytsev

Moscow Independent Research Institute of Artificial Intelligence · HSE University

cs.LG

Submitted: 2026-08-12

Updated: 2026-08-14

Code: https://github.com/timeseriesAI/tsai

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

Importance score: 75/100

The gist: GENADA: efficient generative time series adversarial attack framework This paper introduces GENADA (GENerative ADversarial Attack), a generative framework for adversarial attacks on time series

Terminology

Summary

GENADA: efficient generative time series adversarial attack framework

This paper introduces GENADA (GENerative ADversarial Attack), a generative framework for adversarial attacks on time series classification models. The core idea is to train a separate neural network generator to produce adversarial perturbations directly, avoiding the computational burden of classical gradient-based attacks like FGSM and iFGSM, which require repeated backpropagation through the target model during inference.

The authors propose two main attack variants: a single-step generative attack (GENADA) and an iterative generative attack (iGENADA). In the single-step version, the generator produces a perturbation that is post-processed with tanh during training and sign at inference to ensure l∞-boundedness. The iterative version applies perturbations over T steps, with a training strategy that gradually increases the number of trainable steps across epochs to reduce memory consumption. Additionally, the paper presents a distillation training procedure where an iFGSM teacher attack is used to generate cached perturbations offline, and a student generator is trained to mimic them without further access to the target model's gradients.

The method is validated on three binary classification datasets from the UCR archive: PowerCons, GunPoint, and Strawberry, using LSTM, ResCNN, and PatchTST as target classifiers. Generators follow corresponding backbone architectures, with additional evaluation of RNNA and S4 as generator architectures. Metrics include fooling rate, attack effectiveness, target accuracy, and inference time.

Empirically, GENADA achieves attack quality competitive with strong white-box baselines while substantially reducing adversarial example generation time. The results show that generative attacks can successfully approximate the behavior of iterative optimization-based attacks while avoiding their high inference-time cost. The authors observe a consistent generator hierarchy: PatchTST and S4 perform best, followed by RNNA, with LSTM and ResidualCNN being weakest. Distilled attacks nearly match white-box teachers on larger datasets like Strawberry, while performance degrades on smaller datasets due to limited training data.

The paper also provides a theoretical justification (Theorem A.1) showing that the quality gap between the generator and the optimal attack is bounded by the generator approximation error and the optimization error, under assumptions of L-smoothness, uniform approximation capacity, and the Polyak–Łojasiewicz condition.

Limitations acknowledged include evaluation only in binary classification settings and the need for further exploration of generator architectures and ensemble-based attacks. The code is available in an anonymized GitHub repository.

Improvements for AI systems

Improvements to AI Systems:

  1. Real-Time Adversarial Defense Training: Integrate GENADA’s generator as a fast, online adversarial example generator during the training of time series classifiers. This enables continuous data augmentation with fresh, diverse attacks (e.g., for LSTM or PatchTST models) without the computational overhead of per-sample gradient computation, leading to more robust models trained at scale.

  2. Efficient Robustness Evaluation Pipeline: Replace iterative white-box attacks (iFGSM) with GENADA’s distilled student generator in automated red-teaming systems. This allows for rapid, batch-wise adversarial testing of deployed time series models (e.g., in healthcare monitoring or industrial sensors), reducing evaluation time from minutes to milliseconds while maintaining high attack fidelity.

  3. Gradient-Free Adversarial Transfer for Black-Box Systems: Use GENADA’s generative framework to craft perturbations for proprietary or opaque time series classifiers (e.g., cloud-based APIs) where gradients are inaccessible. The generator learns attack patterns from a surrogate model’s cached iFGSM outputs, enabling effective black-box attacks with minimal queries—improving security auditing of commercial AI services.

  4. Memory-Efficient Iterative Attack for Edge Devices: Deploy iGENADA’s progressive training strategy (increasing trainable steps over epochs) to create lightweight, iterative attack generators that run on resource-constrained hardware (e.g., IoT devices). This enables on-device adversarial testing and self-defense for embedded time series models without needing large GPU memory for backpropagation.

  5. Adaptive Attack Generator for Classifier-Agnostic Robustness: Train a single GENADA generator (using PatchTST or S4 backbone) that produces perturbations transferable across multiple time series classifiers (LSTM, ResCNN, PatchTST). This yields a universal adversarial perturbation engine, allowing AI systems to preemptively harden themselves against a family of models, not just one—improving generalization of defenses.

  6. Distillation-Based Knowledge Transfer for Attack Generation: Adopt the teacher-student distillation procedure to create compact attack generators for new, unseen time series datasets. The student can be fine-tuned on a small amount of cached iFGSM data, enabling rapid deployment of attack capabilities for novel domains (e.g., EEG, financial series) without retraining from scratch—reducing engineering effort and computational cost.

What the Improved AI System Can Do:

  • Self-Hardening Classifiers: Continuously generate adversarial examples during training to achieve higher robustness against unseen attacks, with negligible training time increase.

  • Real-Time Security Auditing: Instantly probe live time series models for vulnerabilities, flagging weak points in milliseconds, enabling immediate defensive action.

  • Black-Box Attack Simulation: Successfully attack proprietary models with high success rates using only a surrogate generator, supporting security research and regulatory compliance testing.

  • On-Device Adversarial Defense: Run iterative attack generation on low-power hardware, allowing autonomous systems (e.g., wearable health monitors) to test and adapt their own models in the field.

  • Universal Robustness Benchmarking: Generate a single set of perturbations to evaluate and compare robustness across multiple model architectures, standardizing AI safety assessments.

  • Rapid Adaptation to New Domains: Quickly produce effective attacks for new time series tasks (e.g., anomaly detection in new sensor types) using distilled generators, accelerating research and deployment of robust AI.

Sources

Related papers