BoundaryWarp: Revealing and Exploiting Patch-End Vulnerabilities in Time-Series Foundation Models
Abstract
State-of-the-art time-series foundation models divide input sequences into fixed, non-overlapping patches before forecasting, yet the robustness consequences of this design are not well understood. We identify a recurring tokenizer-relative patch-end vulnerability in which model sensitivity concentrates at the final position of a patch. To distinguish this pattern from general recency effects, we shift tokenizer alignment and patch length and find that the sensitivity maximum moves with the active patch grid rather than remaining at a fixed temporal position. Internal-boundary, unpatched, recency-controlled, and content-matched analyses further support a tokenizer-relative explanation. We then introduce BoundaryWarp, an untargeted temporal deformation attack that exploits this structural sensitivity through bounded resampling while preserving temporal order, endpoints, and context length. Across Chronos-Bolt, Moirai, and TimesFM on four forecasting benchmarks, BoundaryWarp consistently degrades forecasts under sub-sample temporal constraints. With a maximum displacement of half a sampling interval, it increases median mean squared forecasting error by up to 12.76% relative to clean predictions. Our results show that fixed patch geometry is not only a computational design choice but also a robustness-relevant architectural property that can create a systematic adversarial attack surface in time-series foundation models.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.