acceptodds
Under review as a conference paper at ICLR 2027

C2F-DiffAttack: Coarse-to-fine diffusion for local black-box attack on time series classifiers

Abstract

Time series classifiers remain vulnerable to adversarial perturbations that can alter model predictions while preserving much of the original temporal structure. Local black-box attacks must determine both where to perturb and what perturbation to generate, while restricting perturbations to a small subset of timestamps. Existing methods often separate temporal support selection from perturbation generation, despite both decisions depending on broader temporal context. We propose C2FDA, the first diffusion-based framework for local black-box adversarial attacks on time series classifiers. C2FDA couples the where and what decisions through shared coarse-to-fine temporal representations. Coarse attention captures region-level relevance, while fine attention refines it into timestamp-level evidence. For where, region-level and timestamp-level evidences are combined to determine an exact-budget Top- temporal support. For what, coarse relevance provides regional context for fine refinement, and the resulting timestamp-level evidence modulates diffusion features before noise prediction to shape perturbation content. A shared hybrid boundary objective encourages boundary crossing on the final masked perturbation, jointly optimizing temporal support and perturbation content. C2FDA performs black-box attacks through cross-model transfer. Experiments across diverse time series datasets and classifier architectures show state-of-the-art attack success rates while maintaining low perturbation distortion and high temporal similarity.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.