Efficient Training of Robust Decision Trees Against Adversarial Examples
Daniël Vos, Sicco Verwer
摘要
In the present day we use machine learning for sensitive tasks that require models to be both understandable and robust. Although traditional models such as decision trees are understandable, they suffer from adversarial attacks. When a decision tree is used to differentiate between a user's benign and malicious behavior, an adversarial attack allows the user to effectively evade the model by perturbing the inputs the model receives. We can use algorithms that take adversarial attacks into account to fit trees that are more robust. In this work we propose an algorithm, GROOT, that is two orders of magnitude faster than the state-of-the-art-work while scoring competitively on accuracy against adversaries. GROOT accepts an intuitive and permissible threat model. Where previous threat models were limited to distance norms, we allow each feature to be perturbed with a user-specified parameter: either a maximum distance or constraints on the direction of perturbation. Previous works assumed that both benign and malicious users attempt model evasion but we allow the user to select which classes perform adversarial attacks. Additionally, we introduce a hyperparameter rho that allows GROOT to trade off performance in the regular and adversarial settings.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Robust Optimal Classification Trees against Adversarial ExamplesDaniël Vos, Sicco VerwerAAAI 2022 · 被引用 29 次
- Fast Provably Robust Decision Trees and BoostingJun-Qi Guo, Ming-Zhuo Teng, Wei Gao, Zhi-Hua ZhouICML 2022 · 被引用 16 次
- Prediction without Preclusion: Recourse Verification with Reachable SetsAvni Kothari, Bogdan Kulynych, Tsui-Wei Weng, Berk UstunICLR 2024 · 被引用 7 次
- (De-)Randomized Smoothing for Decision Stump EnsemblesMiklós Z. Horváth, Mark Niklas Müller, Marc Fischer, Martin T. VechevNeurIPS 2022 · 被引用 7 次
- Naive Bayes Classifiers over Missing Data: Decision and PoisoningSong Bian, Xiating Ouyang, Zhiwei Fan, Paraschos KoutrisICML 2024 · 被引用 5 次
相关 Paper
- Query Complexity of Adversarial AttacksGrzegorz Gluch, Rüdiger L. UrbankeICML 2021 · 被引用 9 次
- Cost-Aware Robust Tree Ensembles for Security ApplicationsYizheng Chen, Shiqi Wang, Weifan Jiang, Asaf Cidon 等USENIX Security 2021 · 被引用 26 次
- The Space of Adversarial StrategiesRyan Sheatsley, Blaine Hoak, Eric Pauley, Patrick D. McDanielUSENIX Security 2023
- Connecting Interpretability and Robustness in Decision Trees through SeparationMichal Moshkovitz, Yao-Yuan Yang, Kamalika ChaudhuriICML 2021 · 被引用 28 次
- Improving Robustness of ML Classifiers against Realizable Evasion Attacks Using Conserved FeaturesLiang Tong, Bo Li, Chen Hajaj, Chaowei Xiao 等USENIX Security 2019 · 被引用 95 次
