Skip to main navigation Skip to search Skip to main content

Rethinking robustness: Robust adversarial distillation for practical black-box signal attack in intelligent fault diagnosis

  • Xi'an Jiaotong University
  • Central South University
  • Nanyang Technological University

Research output: Contribution to journalArticlepeer-review

5 Scopus citations

Abstract

The reliability of intelligent fault diagnosis (IFD) systems is vital for industrial predictive maintenance. While existing adversarial attack studies have exposed model vulnerabilities, they primarily address the act of attacking and lack diagnostic-specific robustness evaluation frameworks that account for the dynamic characteristics of industrial monitoring data. This paper establishes a fault diagnosis-oriented adversarial robustness benchmarking methodology by proposing a novel approach, Robust Adversarial Knowledge Distillation (RAKD), which greatly enhances the effectiveness of BSA in complex scenarios and addresses the practical black-box signal attack (BSA) problem. This study theoretically rethinks the primary barriers to practical BSA: model discrepancy and data distribution shifts between the surrogate and target. RAKD aims to construct a robust surrogate model by closely observing the target model's behavior. By treating the target model as a teacher, RAKD uses knowledge distillation across clean and adversarial data distributions to reduce model discrepancy. Then, domain shift in practical monitoring data is simulated by signal augmentation and adversarial perturbation, which is mitigated by surrogate output pairing. Finally, a probabilistic model informed with explicit prior knowledge is used to generate adversarial signals for robustness evaluation of target model. Experiments in three practical BSA scenarios demonstrate that RAKD significantly decreases the diagnosis accuracy of state-of-the-art IFD models by over 90 % for both untargeted and targeted attacks. This study highlights that noise-robust IFD models remain highly vulnerable even when model and data are well protected, underscoring the urgent need for more robust resilient defensive mechanisms.

Original languageEnglish
Article number128805
JournalExpert Systems with Applications
Volume294
DOIs
StatePublished - 15 Dec 2025

Keywords

  • Adversarial attack
  • Fault diagnosis
  • Knowledge distillation
  • Robustness

Fingerprint

Dive into the research topics of 'Rethinking robustness: Robust adversarial distillation for practical black-box signal attack in intelligent fault diagnosis'. Together they form a unique fingerprint.

Cite this