Towards Understanding the Robustness Against Evasion Attack on Categorical Data
Hongyan Bao, Yufei Han, Yujun Zhou, Yun Shen, Xiangliang Zhang
Abstract
Characterizing and assessing the adversarial vulnerability of classification models with categorical input has been a practically important, while rarely explored research problem. Our work echoes the challenge by first unveiling the impact factors of adversarial vulnerability of classification models with categorical data based on an information-theoretic adversarial risk analysis about the targeted classifier. Though certifying the robustness of such classification models is intrinsically an NP-hard combinatorial problem, our study shows that the robustness certification can be solved via an efficient greedy exploration of the discrete attack space for any measurable classifiers with a mild smoothness constraint. Our proposed robustness certification framework is instantiated with deep neural network models applied on real-world safety-critic data sources. Our empirical observations confirm the impact of the key adversarial risk factors with categorical input.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers2
- Probabilistic Categorical Adversarial Attack and Adversarial TrainingHan Xu, Pengfei He, Jie Ren, Yuxuan Wan et al.ICML 2023 · 7 citations
- Attack-free Evaluating and Enhancing Adversarial Robustness on Categorical DataYujun Zhou, Yufei Han, Haomin Zhuang, Hongyan Bao et al.ICML 2024 · 2 citations
Related papers
- Towards Efficient and Domain-Agnostic Evasion Attack with High-Dimensional Categorical InputsHongyan Bao, Yufei Han, Yujun Zhou, Xin Gao et al.AAAI 2023 · 5 citations
- Probabilistic Robustness Certificates against Adversarial AttacksSara Taheri, Majid ZamaniICML 2026
- Adversarial Neural Pruning with Latent Vulnerability SuppressionDivyam Madaan, Jinwoo Shin, Sung Ju HwangICML 2020 · 68 citations
- Characterizing the Evasion Attackability of Multi-label ClassifiersZhuo Yang, Yufei Han, Xiangliang ZhangAAAI 2021 · 11 citations
- Efficient Robustness Certificates for Discrete Data: Sparsity-Aware Randomized Smoothing for Graphs, Images and MoreAleksandar Bojchevski, Johannes Klicpera, Stephan GünnemannICML 2020 · 95 citations
