Search-based adversarial testing and improvement of constrained credit scoring systems
Salah Ghamizi, Maxime Cordy, Martin Gubri, Mike Papadakis, Andrey Boytsov, Yves Le Traon, Anne Goujon
Abstract
Credit scoring systems are critical FinTech applications that concern the analysis of the creditworthiness of a person or organization. While decisions were previously based on human expertise, they are now increasingly relying on data analysis and machine learning. In this paper, we assess the ability of state-of-the-art adversarial machine learning to craft attacks on a real-world credit scoring system. Interestingly, we find that, while these techniques can generate large numbers of adversarial data, these are practically useless as they all violate domain-specific constraints. In other words, the generated examples are all false positives as they cannot occur in practice. To circumvent this limitation, we propose CoEvA2, a search-based method that generates valid adversarial examples (satisfying the domain constraints). CoEvA2 utilizes multi-objective search in order to simultaneously handle constraints, perform the attack and maximize the overdraft amount requested. We evaluate CoEvA2 on a major bank's real-world system by checking its ability to craft valid attacks. CoEvA2 generates thousands of valid adversarial examples, revealing a high risk for the banking system. Fortunately, by improving the system through adversarial training (based on the produced examples), we increase its robustness and make our attack fail.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f16803fe-ac8f-4230-bf2d-a1233a3401ebCited by top-tier papers7
- Adversarial Robustness in Multi-Task Learning: Promises and IllusionsSalah Ghamizi, Maxime Cordy, Mike Papadakis, Yves Le TraonAAAI 2022 · 25 citations
- Constrained Adaptive Attack: Effective Adversarial Attack Against Deep Neural Networks for Tabular DataThibault Simonetto, Salah Ghamizi, Maxime CordyNeurIPS 2024 · 18 citations
- Code integrity attestation for PLCs using black box neural network predictionsYuqi Chen, Christopher M. Poskitt, Jun SunFSE 2021 · 16 citations
- GAT: Guided Adversarial Training with Pareto-optimal Auxiliary TasksSalah Ghamizi, Jingfeng Zhang, Maxime Cordy, Mike Papadakis et al.ICML 2023 · 7 citations
- On The Empirical Effectiveness of Unrealistic Adversarial Hardening Against Realistic Adversarial AttacksSalijona Dyrmishi, Salah Ghamizi, Thibault Simonetto, Yves Le Traon et al.S&P 2023
Builds on1
Related papers
- On the Robustness of Domain ConstraintsRyan Sheatsley, Blaine Hoak, Eric Pauley, Yohan Beugin et al.CCS 2021 · 2 citations
- Composite Adversarial AttacksXiaofeng Mao, Yuefeng Chen, Shuhui Wang, Hang Su et al.AAAI 2021 · 60 citations
- CaFA: Cost-aware, Feasible Attacks With Database Constraints Against Neural Tabular ClassifiersMatan Ben-Tov, Daniel Deutch, Nave Frost, Mahmood SharifS&P 2024 · 7 citations
- Where and How to Attack? A Causality-Inspired Recipe for Generating Counterfactual Adversarial ExamplesRuichu Cai, Yuxuan Zhu, Jie Qiao, Zefeng Liang et al.AAAI 2024 · 7 citations
- Evolutionary Multi-objective Optimization for Contextual Adversarial Example GenerationShasha Zhou, Mingyu Huang, Yanan Sun, Ke LiFSE 2024 · 14 citations
