Transferable Adversarial Robustness for Categorical Data via Universal Robust Embeddings
Klim Kireev, Maksym Andriushchenko, Carmela Troncoso, Nicolas Flammarion
Abstract
Research on adversarial robustness is primarily focused on image and text data. Yet, many scenarios in which lack of robustness can result in serious risks, such as fraud detection, medical diagnosis, or recommender systems often do not rely on images or text but instead on tabular data. Adversarial robustness in tabular data poses two serious challenges. First, tabular datasets often contain categorical features, and therefore cannot be tackled directly with existing optimization procedures. Second, in the tabular domain, algorithms that are not based on deep networks are widely used and offer great performance, but algorithms to enhance robustness are tailored to neural networks (e.g. adversarial training). In this paper, we tackle both challenges. We present a method that allows us to train adversarially robust deep networks for tabular data and to transfer this robustness to other classifiers via universal robust embeddings tailored to categorical data. These embeddings, created using a bilevel alternating minimization framework, can be transferred to boosted trees or random forests making them robust without the need for adversarial training while preserving their high accuracy on tabular data. We show that our methods outperform existing techniques within a practical threat model suitable for tabular data. 1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 79bc916a-4ea4-419e-9d35-9539f49a757eCited by top-tier papers2
- Robust Fraud Transaction Detection: A Two-Player Game ApproachQi Tan, Yi Zhao, Laizhong Cui, Qi Li et al.NDSS 2026
- Probabilistic Hash Embeddings for Online Learning of Categorical FeaturesAodong Li, Abishek Sankararaman, Balakrishnan NarayanaswamyAAAI 2026
Builds on6
- TabNet: Attentive Interpretable Tabular LearningSercan Ö. Arik, Tomas PfisterAAAI 2021 · 2,148 citations
- Revisiting Deep Learning Models for Tabular DataYury Gorishniy, Ivan Rubachev, Valentin Khrulkov, Artem BabenkoNeurIPS 2021 · 1,847 citations
- Towards Robustness Against Natural Language Word SubstitutionsXinshuai Dong, Anh Tuan Luu, Rongrong Ji, Hong LiuICLR 2021 · 63 citations
- Cost-Aware Robust Tree Ensembles for Security ApplicationsYizheng Chen, Shiqi Wang, Weifan Jiang, Asaf Cidon et al.USENIX Security 2021 · 26 citations
- On Lp-norm Robustness of Ensemble Decision Stumps and TreesYihan Wang, Huan Zhang, Hongge Chen, Duane S. Boning et al.ICML 2020 · 11 citations
Related papers
- Adversarial Robustness for Tabular Data through Cost and Utility AwarenessKlim Kireev, Bogdan Kulynych, Carmela TroncosoNDSS 2023
- Fully Test-time Adaptation for Tabular DataZhi Zhou, Kun-Yang Yu, Lan-Zhe Guo, Yufeng LiAAAI 2025 · 11 citations
- Attack-free Evaluating and Enhancing Adversarial Robustness on Categorical DataYujun Zhou, Yufei Han, Haomin Zhuang, Hongyan Bao et al.ICML 2024 · 2 citations
- CatBack: Universal Backdoor Attacks on Tabular Data via Categorical EncodingBehrad Tajalli, Stefanos Koffas, Stjepan PicekNDSS 2026 · 1 citation
- Towards Robustness of Deep Neural Networks via RegularizationYao Li, Martin Renqiang Min, Thomas C. M. Lee, Wenchao Yu et al.ICCV 2021 · 8 citations
