Transferable Adversarial Robustness for Categorical Data via Universal Robust Embeddings

06/06/2023
by   Klim Kireev, et al.
0

Research on adversarial robustness is primarily focused on image and text data. Yet, many scenarios in which lack of robustness can result in serious risks, such as fraud detection, medical diagnosis, or recommender systems often do not rely on images or text but instead on tabular data. Adversarial robustness in tabular data poses two serious challenges. First, tabular datasets often contain categorical features, and therefore cannot be tackled directly with existing optimization procedures. Second, in the tabular domain, algorithms that are not based on deep networks are widely used and offer great performance, but algorithms to enhance robustness are tailored to neural networks (e.g. adversarial training). In this paper, we tackle both challenges. We present a method that allows us to train adversarially robust deep networks for tabular data and to transfer this robustness to other classifiers via universal robust embeddings tailored to categorical data. These embeddings, created using a bilevel alternating minimization framework, can be transferred to boosted trees or random forests making them robust without the need for adversarial training while preserving their high accuracy on tabular data. We show that our methods outperform existing techniques within a practical threat model suitable for tabular data.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/30/2022

Improving Corruption and Adversarial Robustness by Enhancing Weak Subnets

Deep neural networks have achieved great success in many computer vision...
research
05/30/2020

Exploring Model Robustness with Adaptive Networks and Improved Adversarial Training

Adversarial training has proven to be effective in hardening networks ag...
research
05/20/2019

Adversarially robust transfer learning

Transfer learning, in which a network is trained on one task and re-purp...
research
06/02/2022

Adaptive Adversarial Training to Improve Adversarial Robustness of DNNs for Medical Image Segmentation and Detection

Recent methods based on Deep Neural Networks (DNNs) have reached high ac...
research
11/03/2021

Pareto Adversarial Robustness: Balancing Spatial Robustness and Sensitivity-based Robustness

Adversarial robustness, which mainly contains sensitivity-based robustne...
research
08/01/2023

Doubly Robust Instance-Reweighted Adversarial Training

Assigning importance weights to adversarial data has achieved great succ...
research
11/24/2021

Challenges of Adversarial Image Augmentations

Image augmentations applied during training are crucial for the generali...

Please sign up or login with your details

Forgot password? Click here to reset