Faster Repeated Evasion Attacks in Tree Ensembles
Lorenzo Cascioli, Laurens Devos, Ondrej Kuzelka, Jesse Davis
Abstract
Tree ensembles are one of the most widely used model classes. However, these models are susceptible to adversarial examples, i.e., slightly perturbed examples that elicit a misprediction. There has been significant research on designing approaches to construct such examples for tree ensembles. But this is a computationally challenging problem that often must be solved a large number of times (e.g., for all examples in a training set). This is compounded by the fact that current approaches attempt to find such examples from scratch. In contrast, we exploit the fact that multiple similar problems are being solved. Specifically, our approach exploits the insight that adversarial examples for tree ensembles tend to perturb a consistent but relatively small set of features. We show that we can quickly identify this set of features and use this knowledge to speedup constructing adversarial examples.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Abstract Interpretation of Decision Tree Ensemble ClassifiersFrancesco Ranzato, Marco ZanellaAAAI 2020 · 50 citations
- Efficient Training of Robust Decision Trees Against Adversarial ExamplesDaniël Vos, Sicco VerwerICML 2021 · 48 citations
- An Efficient Adversarial Attack for Tree EnsemblesChong Zhang, Huan Zhang, Cho-Jui HsiehNeurIPS 2020 · 30 citations
- Robust Optimal Classification Trees against Adversarial ExamplesDaniël Vos, Sicco VerwerAAAI 2022 · 29 citations
Related papers
- Data-Aware and Scalable Sensitivity Analysis for Decision Tree EnsemblesNamrita Varshney, Ashutosh Gupta, Arhaan Ahmad, Tanay Vineet Tayal et al.ICLR 2026 · 2 citations
- To Tackle Adversarial Transferability: A Novel Ensemble Training Method with Fourier TransformationWanlin Zhang, Weichen Lin, Ruomin Huang, Shihong Song et al.ICLR 2025
- Counterfactual Explanations for Oblique Decision Trees: Exact, Efficient AlgorithmsMiguel Á. Carreira-Perpiñán, Suryabhan Singh HadaAAAI 2021 · 39 citations
- Free Lunch in the Forest: Functionally-Identical Pruning of Boosted Tree EnsemblesYoussouf Emine, Alexandre Forel, Idriss Malek, Thibaut VidalAAAI 2025 · 3 citations
- Quantifying Sensitivity for Tree Ensembles: A Symbolic and Compositional ApproachAjinkya Naik, Chaitanya Garg, S. Akshay, Ashutosh Gupta et al.CAV 2026
