Adversarial Robustness in Two-Stage Learning-to-Defer: Algorithms and Guarantees
Yannis Montreuil, Axel Carlier, Lai Xing Ng, Wei Tsang Ooi
Abstract
Two-stage Learning-to-Defer (L2D) enables optimal task delegation by assigning each input to either a fixed main model or one of several offline experts, supporting reliable decision-making in complex, multi-agent environments. However, existing L2D frameworks assume clean inputs and are vulnerable to adversarial perturbations that can manipulate query allocation-causing costly misrouting or expert overload. We present the first comprehensive study of adversarial robustness in two-stage L2D systems. We introduce two novel attack strategies-untargeted and targeted-which respectively disrupt optimal allocations or force queries to specific agents. To defend against such threats, we propose SARD, a convex learning algorithm built on a family of surrogate losses that are provably Bayes-consistent and (R, G)-consistent. These guarantees hold across classification, regression, and multi-task settings. Empirical results demonstrate that SARD significantly improves robustness under adversarial attacks while maintaining strong clean performance, marking a critical step toward secure and trustworthy L2D deployment.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bd1c5163-9cc8-46d6-8e36-ee8bb551ceaaCited by top-tier papers11
- Universal Model Routing for Efficient LLM InferenceWittawat Jitkrittum, Harikrishna Narasimhan, Ankit Singh Rawat, Jeevesh Juneja et al.ICLR 2026 · 99 citations
- Cost-Aware Contrastive Routing for LLMsReza Shirkavand, Shangqian Gao, Peiran Yu, Heng HuangNeurIPS 2025 · 19 citations
- Deferring Concept Bottleneck Models: Learning to Defer Interventions to Inaccurate ExpertsAndrea Pugnana, Riccardo Massidda, Francesco Giannini, Pietro Barbiero et al.NeurIPS 2025 · 11 citations
- Why Ask One When You Can Ask k? Learning-to-Defer to the Top-k ExpertsYannis Montreuil, Axel Carlier, Lai Xing Ng, Wei Tsang OoiICLR 2026 · 7 citations
- Linear-Core Surrogates: Smooth Loss Functions with Linear Rates for Classification and Structured PredictionMehryar Mohri, Yutao ZhongICML 2026 · 7 citations
Builds on21
- Cross-Entropy Loss Functions: Theoretical Analysis and ApplicationsAnqi Mao, Mehryar Mohri, Yutao ZhongICML 2023 · 790 citations
- Consistent Estimators for Learning to Defer to an ExpertHussein Mozannar, David A. SontagICML 2020 · 267 citations
- Two-Stage Learning to Defer with Multiple ExpertsAnqi Mao, Christopher Mohri, Mehryar Mohri, Yutao ZhongNeurIPS 2023 · 98 citations
- Post-hoc estimators for learning to defer to an expertHarikrishna Narasimhan, Wittawat Jitkrittum, Aditya Krishna Menon, Ankit Singh Rawat et al.NeurIPS 2022 · 66 citations
- Calibration and Consistency of Adversarial Surrogate LossesPranjal Awasthi, Natalie Frank, Anqi Mao, Mehryar Mohri et al.NeurIPS 2021 · 59 citations
Related papers
- A Two-Stage Learning-to-Defer Approach for Multi-Task LearningYannis Montreuil, Yeo Shu Heng, Axel Carlier, Lai Xing Ng et al.ICML 2025
- Exploiting Human-AI Dependence for Learning to DeferZixi Wei, Yuzhou Cao, Lei FengICML 2024 · 15 citations
- Mastering Multiple-Expert Routing: Realizable H-Consistency and Strong Guarantees for Learning to DeferAnqi Mao, Mehryar Mohri, Yutao ZhongICML 2025
- Regression with Multi-Expert DeferralAnqi Mao, Mehryar Mohri, Yutao ZhongICML 2024 · 31 citations
- Optimized Deferral for Imbalanced SettingsCorinna Cortes, Anqi Mao, Mehryar Mohri, Yutao ZhongICML 2026 · 7 citations
