An Efficient Adversarial Attack for Tree Ensembles
Chong Zhang, Huan Zhang, Cho-Jui Hsieh
Abstract
We study the problem of efficient adversarial attacks on tree based ensembles such as gradient boosting decision trees (GBDTs) and random forests (RFs). Since these models are non-continuous step functions and gradient does not exist, most existing efficient adversarial attacks are not applicable. Although decision-based black-box attacks can be applied, they cannot utilize the special structure of trees. In our work, we transform the attack problem into a discrete search problem specially designed for tree ensembles, where the goal is to find a valid "leaf tuple" that leads to mis-classification while having the shortest distance to the original input. With this formulation, we show that a simple yet effective greedy algorithm can be applied to iteratively optimize the adversarial example by moving the leaf tuple to its neighborhood within hamming distance 1. Experimental results on several large GBDT and RF models with up to hundreds of trees demonstrate that our method can be thousands of times faster than the previous mixed-integer linear programming (MILP) based approach, while also providing smaller (better) adversarial examples than decision-based black-box attacks on general p (p = 1, 2, ∞) norm perturbations. Our code is available at https://github.com/ chong-z/tree-ensemble-attack .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5938ed07-4fb2-4241-99b1-3c66afdeca84Cited by top-tier papers4
- The Power of Anomaly Detection in Predictive Maintenance: [Experiments & Analysis]Anastasios Papadopoulos, Apostolos Giannoulidis, Anastasios Gounaris, John PaparrizosSIGMOD 2026 · 4 citations
- Integrity Authentication in Tree ModelsWeijie Zhao, Yingjie Lao, Ping LiKDD 2022 · 3 citations
- Faster Repeated Evasion Attacks in Tree EnsemblesLorenzo Cascioli, Laurens Devos, Ondrej Kuzelka, Jesse DavisNeurIPS 2024 · 3 citations
- OC-space: a Unifying Perspective on Verification of Tree EnsemblesTimo Martens, Laurens Devos, Lorenzo Cascioli, Wannes Meert et al.ICML 2026
Builds on3
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Guessing Smart: Biased Sampling for Efficient Black-Box Adversarial AttacksThomas Brunner, Frederik Diehl, Michael Truong-Le, Alois C. KnollICCV 2019 · 127 citations
- On Lp-norm Robustness of Ensemble Decision Stumps and TreesYihan Wang, Huan Zhang, Hongge Chen, Duane S. Boning et al.ICML 2020 · 11 citations
Related papers
- Robust Optimal Classification Trees against Adversarial ExamplesDaniël Vos, Sicco VerwerAAAI 2022 · 29 citations
- Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial TransferabilityYifeng Xiong, Jiadong Lin, Min Zhang, John E. Hopcroft et al.CVPR 2022 · 124 citations
- Optimal Counterfactual Explanations in Tree EnsemblesAxel Parmentier, Thibaut VidalICML 2021 · 66 citations
- Abstract Interpretation of Decision Tree Ensemble ClassifiersFrancesco Ranzato, Marco ZanellaAAAI 2020 · 50 citations
- AutoDA: Automated Decision-based Iterative Adversarial AttacksQi-An Fu, Yinpeng Dong, Hang Su, Jun Zhu et al.USENIX Security 2022
