Fig 1.
Adversarial attacks and defenses in wind power forecasting system.
Table 1.
Structure of the forecasting model.
Fig 2.
Structure of the LSTM layer.
Table 2.
Structure of the substitute model.
Table 3.
Structure of DAE.
Fig 3.
Structure of the DAE defense model.
Fig 4.
Performance of the DC-MI-FGSM attack algorithm under different momentum decay factors across different attack scenarios.
Fig 5.
Adversarial attacks on wind power forecasting under the white-box scenario.
(a) Impact of DC-MI-FGSM () on the forecast curves when
. (b) Impact of DC-MI-FGSM (
) on the forecast curves when
.
Table 4.
Forecast errors of different attack methods under varying perturbation strengths in the white-box environment.
Fig 6.
Stealthiness comparison of DC-MI-FGSM, FGSM, PGD, and MI-FGSM in the white-box environment.
(a) APP of adversarial samples under different attacks when . (b) APP of adversarial samples under different attacks when
.
Fig 7.
Adversarial attacks on wind power forecasting under the black-box scenario.
(a) Impact of DC-MI-FGSM () on the forecast curves when
. (b) Impact of DC-MI-FGSM (
) on the forecast curves when
.
Table 5.
Forecast errors of different attack methods under varying perturbation strengths in the black-box environment.
Fig 8.
Stealthiness comparison of DC-MI-FGSM, FGSM, PGD, and MI-FGSM in the black-box environment.
(a) APP of adversarial samples under different attacks when . (b) APP of adversarial samples under different attacks when
.
Fig 9.
Comparison of defense performance between DAE and AT in the white-box environment.
(a) MAPE reduction of the attacked forecasting model under different defense strategies when ; (b) MAPE reduction of the attacked forecasting model under different defense strategies when
.
Fig 10.
Defense performance of DAE against the DC-MI-FGSM white-box attacks.
(a) Restoration of the attacked forecast curve under the DAE defense when . (b) Restoration of the attacked forecast curve under the DAE defense when
.
Table 6.
Forecast errors of the forecasting model with defense algorithms.
Fig 11.
Comparison of defense performance between DAE and AT in the black-box environment.
(a) MAPE reduction of the attacked forecasting model under different defense strategies when ; (b) MAPE reduction of the attacked forecasting model under different defense strategies when
.
Fig 12.
Defense performance of DAE against the DC-MI-FGSM black-box attacks.
(a) Restoration of the attacked forecast curve under the DAE defense when . (b) Restoration of the attacked forecast curve under the DAE defense when
.