TY - JOUR
T1 - Rethinking robustness
T2 - Robust adversarial distillation for practical black-box signal attack in intelligent fault diagnosis
AU - Feng, Yong
AU - Chen, Jinglong
AU - Pan, Tongyang
AU - Su, Rong
N1 - Publisher Copyright:
© 2025 Elsevier Ltd
PY - 2025/12/15
Y1 - 2025/12/15
N2 - The reliability of intelligent fault diagnosis (IFD) systems is vital for industrial predictive maintenance. While existing adversarial attack studies have exposed model vulnerabilities, they primarily address the act of attacking and lack diagnostic-specific robustness evaluation frameworks that account for the dynamic characteristics of industrial monitoring data. This paper establishes a fault diagnosis-oriented adversarial robustness benchmarking methodology by proposing a novel approach, Robust Adversarial Knowledge Distillation (RAKD), which greatly enhances the effectiveness of BSA in complex scenarios and addresses the practical black-box signal attack (BSA) problem. This study theoretically rethinks the primary barriers to practical BSA: model discrepancy and data distribution shifts between the surrogate and target. RAKD aims to construct a robust surrogate model by closely observing the target model's behavior. By treating the target model as a teacher, RAKD uses knowledge distillation across clean and adversarial data distributions to reduce model discrepancy. Then, domain shift in practical monitoring data is simulated by signal augmentation and adversarial perturbation, which is mitigated by surrogate output pairing. Finally, a probabilistic model informed with explicit prior knowledge is used to generate adversarial signals for robustness evaluation of target model. Experiments in three practical BSA scenarios demonstrate that RAKD significantly decreases the diagnosis accuracy of state-of-the-art IFD models by over 90 % for both untargeted and targeted attacks. This study highlights that noise-robust IFD models remain highly vulnerable even when model and data are well protected, underscoring the urgent need for more robust resilient defensive mechanisms.
AB - The reliability of intelligent fault diagnosis (IFD) systems is vital for industrial predictive maintenance. While existing adversarial attack studies have exposed model vulnerabilities, they primarily address the act of attacking and lack diagnostic-specific robustness evaluation frameworks that account for the dynamic characteristics of industrial monitoring data. This paper establishes a fault diagnosis-oriented adversarial robustness benchmarking methodology by proposing a novel approach, Robust Adversarial Knowledge Distillation (RAKD), which greatly enhances the effectiveness of BSA in complex scenarios and addresses the practical black-box signal attack (BSA) problem. This study theoretically rethinks the primary barriers to practical BSA: model discrepancy and data distribution shifts between the surrogate and target. RAKD aims to construct a robust surrogate model by closely observing the target model's behavior. By treating the target model as a teacher, RAKD uses knowledge distillation across clean and adversarial data distributions to reduce model discrepancy. Then, domain shift in practical monitoring data is simulated by signal augmentation and adversarial perturbation, which is mitigated by surrogate output pairing. Finally, a probabilistic model informed with explicit prior knowledge is used to generate adversarial signals for robustness evaluation of target model. Experiments in three practical BSA scenarios demonstrate that RAKD significantly decreases the diagnosis accuracy of state-of-the-art IFD models by over 90 % for both untargeted and targeted attacks. This study highlights that noise-robust IFD models remain highly vulnerable even when model and data are well protected, underscoring the urgent need for more robust resilient defensive mechanisms.
KW - Adversarial attack
KW - Fault diagnosis
KW - Knowledge distillation
KW - Robustness
UR - https://www.scopus.com/pages/publications/105009457916
U2 - 10.1016/j.eswa.2025.128805
DO - 10.1016/j.eswa.2025.128805
M3 - 文章
AN - SCOPUS:105009457916
SN - 0957-4174
VL - 294
JO - Expert Systems with Applications
JF - Expert Systems with Applications
M1 - 128805
ER -