Forecasting plays a crucial role in modern safety-critical applications, such as space operations. However, the increasing use of deep forecasting models introduces a new security risk of trojan horse attacks, carried out by hiding a backdoor in the training data or directly in the model weights. Once implanted, the backdoor is activated by a specific trigger pattern at test time, causing the model to produce manipulated predictions. We focus on this issue in our \textit{Trojan Horse Hunt} data science competition, where more than 200 teams faced the task of identifying triggers hidden in deep forecasting models for spacecraft telemetry. We describe the novel task formulation, benchmark set, evaluation protocol, and best solutions from the competition. We further summarize key insights and research directions for effective identification of triggers in time series forecasting models. All materials are publicly available on the official competition webpage https://www.kaggle.com/competitions/trojan-horse-hunt-in-space.
翻译:预测在现代安全关键应用(如太空操作)中扮演着至关重要的角色。然而,深度预测模型的日益普及引入了木马攻击这一新的安全风险,攻击者通过在训练数据或模型权重中隐藏后门实施攻击。一旦植入,后门会在测试时由特定触发模式激活,导致模型产生被操纵的预测。我们在《木马猎手》数据科学竞赛中聚焦这一问题,超过200支队伍需识别隐藏在航天器遥测深度预测模型中的触发模式。我们描述了新颖的任务设计、基准数据集、评估协议及竞赛中的最佳解决方案。进一步,我们总结了有效识别时间序列预测模型中触发模式的关键见解与研究方向的启示。所有材料已在竞赛官方网页(https://www.kaggle.com/competitions/trojan-horse-hunt-in-space)公开。