气象数据被蓄意破坏的风险正在上升

qimuai 发布于 阅读:43 一手编译

气象数据被蓄意破坏的风险正在上升

内容来源:https://www.technologyreview.com/2026/07/17/1140622/weather-data-sabotage/

内容总结:

气象数据遭篡改风险加剧:当赌注与AI遇上精准预报

每天清晨,全球的航空公司调度员、电网运营者和农民都依赖同一个信息做出关键决策:天气预报。然而,随着天气预测市场(允许人们就真实世界事件下注的新兴行业)的兴起,以及人工智能(AI)预报技术的快速普及,气象数据的准确性正面临前所未有的威胁。

今年4月,巴黎戴高乐机场的气象站被发现遭人用吹风机或打火机恶意篡改,导致温度读数异常飙升。这一操作让在线预测市场中押注气温达到22°C的投机者获利高达2万美元,而当日实际平均气温仅为18°C左右。尽管这一事件最终被法国气候非营利组织成员偶然发现并曝光,但它敲响了警钟:如果缺乏人工监控,或者攻击者采取更隐蔽、更大规模的协同操控(例如同时微调多个站点数据,使每个变化看起来合理),现有的质量控制体系将难以招架。

更令人担忧的是,AI预报模型(尤其是所谓的“数据驱动模型”)对观测数据的准确性和可靠性依赖度极高。传统预报系统(如欧洲中期天气预报中心的模式)通过“数据同化”步骤,将实测数据与物理模型及邻近站读数进行比对,起到安全过滤作用。但一些研究正尝试跳过这一步骤,直接从原始观测数据生成预报,甚至将气象站数据与大语言模型及自主AI结合,用于极端天气下的实时决策。这虽能提升效率,却也意味着“将人排除在外”,引入了大量新风险。

风险层级正在递升:从个人投机者篡改单个站点牟利(如戴高乐机场案),到团体协同操纵可再生能源预测以影响电价牟取暴利,再到国家级行为体通过篡改多个站点触发虚假预警或使预警系统在关键时刻“失声”。这已从单纯的欺诈行为,升级为危害防灾减灾、甚至威胁国家安全的系统性问题。

面对挑战,专家提出三大防护策略:第一,强化站点监控,实施持续物理安防、实时异常检测与人工复核,并加快数据标准化处理速度,确保AI系统使用前即时发现问题;第二,保护数据以捍卫AI,在AI全流程部署可解释性和对抗性鲁棒性工具,识别数据与模型问题,提升抵御攻击的能力;第三,确保全链条问责,从站点运营者、国家气象部门到预报中心,每个环节都需保护自身数据链,任何异常必须即时沿链条通报。

戴高乐机场案件虽已被发现,但应被视为一记警钟。随着观测数据在天气预报中的核心地位日益凸显,我们必须通过加强现有监管与问责架构,并促进关键合作伙伴间的协调,来适应不断演变的威胁,确保预报的准确性与公共安全。

中文翻译:

天气数据遭破坏的风险正在上升
预测市场与人工智能预测技术的兴起,正开始威胁天气预报的准确性。以下是我们该如何加以保护的措施。

每天清晨,全球各地的航班调度员、电网运营者和农民都在依据同一件事做出决策:天气预报。

尽管大多数人只花两秒钟瞥一眼这些预报,但天气预报却影响着多个行业的重大战略决策,涉及真金白银、生计乃至生命。农民用它决定播种哪种作物、何时施肥、在灌溉基础设施上投入多少、牲畜放牧多久;公用事业公司用它决定在哪里建造太阳能和风力发电场,以及如何为批发电力定价;预报用于向人们发出极端天气预警,并触发应急响应措施。最近,天气预报还与一个新兴行业——预测市场——产生了关联,人们在这个市场上对包括天气在内的各种现实事件下注。

然而,为了在预测市场中获取优势而操纵天气数据的诱惑,加上业界集体转向数据驱动的人工智能天气预报,正开始危及天气预报的准确性。目前,这些风险相对可控,但作为该领域的专家,我们可以预见到它们可能演变成更大、更系统性的问题。

要生成天气预报,我们需要对当前状况进行精确观测。这些观测数据来自多个来源,包括机场、公用事业公司或交通服务部门的天气站。传统运行系统(如天气研究与预报模型或欧洲中期天气预报中心的综合预报系统)将这些观测数据与数值近似相结合,以估算未来的天气模式。

有时,天气站会因仪器故障或设备升级等问题出现异常。这些问题可以通过实时检查与修正或在事后被发现。传统预报系统还内置了一项名为“数据同化”的保障措施:每个传入的测量值都会与物理模型预测的情况以及附近站点的读数进行比对。

这些机制共同帮助确保天气观测的可靠性和预报的稳健性。然而,新的威胁正危及观测精度。今年早些时候,媒体报道称,巴黎戴高乐机场的天气站曾被篡改,导致2026年4月6日和4月15日记录到异常的温度峰值。当局推测,可能有人使用了手持吹风机或打火机。无论方式如何,这次篡改让在线预测市场中的赌徒获得了大额赔付——他们押注当天的气温将达到22°C(71.6°F),而实际平均气温约为18°C(64.4°F)。其中一人赢取了2万美元。

幸运的是,此类针对单个站点的篡改通常可以通过人工监控或现有的统计方法被发现。在此案例中,法国一个气候非营利组织的成员偶然注意到了这些异常,并发出了警报。

但如果没有人工监控系统呢?如果发生其他类型的操纵呢?假如有人不是篡改一个站点,而是远程同时微调多个站点的读数——使每个变化小到足以单独看起来合理——又会怎样?现有的质量控制措施很难发现这种协同操纵。而且时间并不站在我们这一边;仔细检查数据和元数据需要数小时甚至数天,但无论天气如何,预报都必须按时发布。

天气预报领域向人工智能的转变加剧了风险。这些方法更加依赖准确可靠的天气观测数据;事实上,它们被称为“数据驱动模型”。例如,欧洲中期天气预报中心的研究人员正在探索是否可以直接从原始观测数据中生成高质量天气预报,跳过目前作为质量过滤器的同化步骤。其他研究人员则更进一步:将地理空间数据(包括天气站数据)与大型语言模型和自主人工智能相结合,以支持在风暴等极端事件期间进行实时的自主决策。

潜在的好处包括准确性、效率和速度的提升。但将人类从这一过程中移除,也引入了大量新的风险。

在风险规模的较低端,是个人投机者为谋取私利操纵天气站——就像戴高乐机场案例那样。再进一步:一群交易者可以协调行动,使可再生能源产出的预测产生偏差,从而影响批发电价,让交易对手方承担损失。在最极端的情况下,一个国家的行为者或破坏者可以操纵一个或多个天气站,触发预警系统,甚至在本应发出警报时使其保持沉默。风险一步步升级,从欺诈到削弱灾害应对能力,再到国家安全问题。

只要存在金融或其他方面的动机来操纵观测数据,对手就会寻找新的机会,而我们的任务就是始终领先一步。以下是三种方法。

  1. 监控天气站。数据质量控制应包括站点安全、异常检测与修正以及人工监督。天气站应持续受到监控,以威慑篡改行为。用于清理天气记录的数据均质化方法也需要加快速度,目标是实现实时发现异常。随着自主人工智能系统利用这些数据做出实时决策,这一点将变得愈发重要。最后,需要人工监督来标记可疑数据和模型输出结果。毕竟,正是人类发现了戴高乐机场的篡改行为。

  2. 保护数据以保障人工智能安全。数据防御机制必须贯穿人工智能管道的各个环节。人工智能的可解释性和对抗鲁棒性工具可以帮助我们理解底层数据和人工智能模型输出,帮助我们识别与数据或模型相关的问题,并可能增强我们对对抗性攻击的抵御能力。

  3. 确保整个链条中的持续问责。观测数据会经过多个环节:运营天气站的操作人员、保管记录的国家气象部门,以及将这些数据转化为预报的预报中心。其中任何一方都无法单独保护数据完整性——每个环节只能守护自己的那一段,任何异常都需要在整个链条中传达,从站点操作员到依据预报采取行动的人。

幸运的是,戴高乐机场的情况被及时发现了,但这应当成为一个警钟。随着观测数据在天气预报中的作用日益增强,我们需要适应不断演变的威胁。这意味着通过加强现有的监督和问责机制,并改善关键合作伙伴之间的协调,来保护我们的数据和模型。

本文由以下人士撰写:

深度探索
人工智能
一家初创公司声称突破了制约大语言模型的瓶颈
Subquadratic现已公布了其新模型的更多细节,但仍有部分人持怀疑态度。

对人工智能就业恐慌的现实核查
关于人工智能对劳动力市场的影响,数字究竟说明了什么?答案可能会让你大吃一惊。

Anthropic的“Code with Claude”展示了编码的未来——无论你是否喜欢
随着Claude Code等工具的不断进步,越来越多的开发者乐于将编码任务交给它们。软件构建方式已永久改变。

Anthropic发现了一个隐藏空间,Claude在其中思考概念
一项新技术使该公司能够比以前更深入地探究大语言模型的奇异运作机制。

保持联系
获取来自《麻省理工科技评论》的最新资讯
发现特别优惠、热门故事和即将举行的活动等更多内容。

英文来源:

The risk of weather data sabotage is rising
Prediction markets and a move toward AI forecasting are starting to put the accuracy of weather predictions at risk. Here’s what we can do to safeguard them.
Every morning, airline dispatchers, grid operators, and farmers around the world make decisions based on the same thing: a weather forecast.
While these forecasts are something that most people glance at for two seconds, weather predictions influence major strategic decisions in many industries, with real money, livelihoods, and even actual lives at stake. Farmers use them to determine which crop variety to sow, when to fertilize, how much to invest in irrigation infrastructure, and how long livestock should graze. Utilities use them to decide where to build solar and wind farms, as well as how to price wholesale electricity. Predictions are used to warn people about extreme weather and to trigger emergency response measures. More recently, weather predictions have become relevant for an emerging industry: prediction markets, where people bet money on all kinds of real-world events, including the weather.
However, the temptation to manipulate weather data to get an edge in these markets, combined with a collective move toward data-driven AI weather forecasting, is starting to put the accuracy of weather predictions at risk. These risks are relatively manageable for now, but as experts in the field, we can foresee scenarios where they snowball into far bigger, more systemic problems.
To develop weather predictions, we need accurate observations of current conditions. These are collected from several sources, including weather stations at airports, utilities, or transport services. Traditional operational systems like the Weather Research and Forecasting model or the European Centre for Medium-Range Weather Forecast (ECMWF) Integrated Forecasting System combine these observations with numerical approximations in order to estimate future weather patterns.
Sometimes, weather stations have issues because of, for example, instrument failures or upgrades in equipment. These can be caught either in real time (through checking and correction) or retroactively. Traditional forecasting systems also have a built-in safeguard called data assimilation: Every incoming measurement is weighed against what the physical model says should be happening and against readings from nearby stations.
Together, these mechanisms help keep weather observations reliable and predictions robust. However, new threats are putting observational accuracy at risk. Earlier this year, news outlets reported that the weather station at Paris Charles de Gaulle Airport (CDG) had been manipulated to record suspicious temperature spikes on April 6 and April 15, 2026. Authorities speculate that a hand-held hairdryer or lighter might have come into play. Either way, it led to some big payouts for online prediction-market gamblers who had bet it would hit 22 °C (71.6 °F) on days when the actual average was around 18°C (64.4°F). One individual won $20,000.
Fortunately, tampering with a single station like this can usually be caught by human monitoring or current statistical methods. In this case, members of a French climate nonprofit association noticed the anomalies by chance and raised the alarm.
But what if there are no human monitoring systems in place? And what about other types of manipulation? What if, instead of tampering with one station, someone remotely nudged the readings at many stations at once—making each change small enough to look plausible on its own? Existing quality controls struggle to catch this kind of coordinated manipulation. And time works against us; careful checks of data and metadata take hours or days, but forecasts have to go out on schedule, whatever the weather is doing.
The shift toward artificial intelligence in weather prediction raises the stakes. These methods are even more dependent on accurate, reliable weather observations; in fact, they are known as “data-driven models.” For example, researchers at ECMWF are exploring whether high-quality weather forecasts can be produced directly from raw observations, skipping the assimilation step that currently acts as a quality filter. Other researchers are going one step further; combining geospatial data (including weather station data) with large language models and agentic AI to support real-time, autonomous decision-making during extreme events such as storms.
Possible benefits are improvements in accuracy, efficiency, and speed. But removing humans from the equation introduces a vast range of new risks.
At the low end of the risk scale, an individual speculator manipulates a weather station for personal gain—that is the CDG Airport case. One step up: A group of traders could coordinate to bias forecasts of renewable energy output, moving wholesale electricity prices and leaving whoever is on the other side of the trade holding the loss. And at the far end, a state actor or saboteur could manipulate one or many stations to set off an early warning system or even keep one silent when it should sound. Step by step, the risk grows, from fraud to compromised disaster preparedness to a matter of national security.
As long as there are financial (or other) incentives to manipulate observational data, adversaries will search for new opportunities, and it is our task to stay one step ahead. Here are three ways.

  1. Watch the stations. Data quality controls should include station security, anomaly detection and correction, and human oversight. Weather stations should be monitored continuously to deter tampering. Data homogenization methods that clean up weather records also need to get faster, with the goal of catching problems in real time. This will become increasingly important as agentic AI systems use these data to deliver real-time decisions. Finally, human oversight is needed to flag questionable data and model outcomes. After all, it was humans who caught the CDG Airport manipulation.
  2. Protect the data to safeguard the AI. Data defense mechanisms must be positioned throughout the AI pipeline. AI explainability and adversarial robustness tools can help us understand the underlying data and the AI model outputs, help us identify data- or model-related issues, and potentially make us more resilient to adversarial attacks.
  3. Ensure continuous accountability along the chain. Observational data passes through many hands: the operators who run the stations, the national weather services that steward the records, and the forecasting centers that turn them into predictions. No single one of them can protect data integrity alone—each guards its own link, and any anomaly needs to be communicated along the whole chain, from station operators to the people acting on the forecast.
    It is fortunate that the situation at CDG Airport was caught, but it should serve as a wake-up call. As the role of observational data grows in weather forecasting, we need to adapt to evolving threats. This means protecting our data and models by strengthening existing oversight and accountability structures, and improving coordination among key partners.
    This op-ed was written by:
    • Monique Kuglitsch — Innovation Manager at Fraunhofer Heinrich Hertz Institute and Chair of the UN Global Initiative on Resilience to Natural Hazards through AI Solutions
    • Jesper Dramsch — Scientist for Machine Learning at the European Centre for Medium-Range Weather Forecasts (ECMWF), where they work on AIFS (Artificial Intelligence Forecasting System), ECMWF's data-driven weather prediction model
    • Franz G. Kuglitsch — Climate Scientist and Executive Secretary of the International Union of Geodesy and Geophysics (IUGG) at the GFZ Helmholtz Centre for Geosciences in Potsdam
    • Andrea Toreti — Senior Scientist at the European Commission's Joint Research Centre (JRC), where he coordinates the European and Global Drought Observatory under the Copernicus Emergency Management Service <
      Deep Dive
      Artificial intelligence
      A startup claims it broke through a bottleneck that’s holding back LLMs
      Subquadratic has now shared more details about its new model. But some are still skeptical.
      A reality check on the AI jobs hysteria
      What do the numbers really say about the impact of artificial intelligence on the labor market? The answer might surprise you.
      Anthropic’s Code with Claude showed off coding’s future—whether you like it or not
      As tools like Claude Code get better, more and more developers are happy to hand off coding tasks to them. The way software gets built has changed for good.
      Anthropic found a hidden space where Claude puzzles over concepts
      A new technique has let the company probe deeper than ever into the weird workings of an LLM.
      Stay connected
      Get the latest updates from
      MIT Technology Review
      Discover special offers, top stories, upcoming events, and more.

MIT科技评论

文章目录


    扫描二维码,在手机上阅读