On the Adversarial Robustness of Decision Trees and a Symmetry Defense

dc.contributorAalto-yliopistofi
dc.contributorAalto Universityen
dc.contributor.authorLindqvist, Blerta
dc.contributor.departmentDepartment of Computer Scienceen
dc.contributor.groupauthorProfessorship Ylä-Jääski A.en
dc.date.accessioned2025-03-19T06:17:53Z
dc.date.available2025-03-19T06:17:53Z
dc.date.issued2025
dc.descriptionPublisher Copyright: © 2013 IEEE.
dc.description.abstractGradient-boosting decision tree classifiers (GBDTs) are susceptible to adversarial perturbation attacks that change inputs slightly to cause misclassification. GBDTs are customarily used on non-image datasets that lack inherent symmetries, which might be why data symmetry in the context of GBDT classifiers has not received much attention. In this paper, we show that GBDTs can classify symmetric samples differently, which means that GBDTs lack invariance with respect to symmetry. Based on this, we defend GBDTs against adversarial perturbation attacks using symmetric adversarial samples in order to obtain correct classification. We apply and evaluate the symmetry defense against six adversarial perturbation attacks on the GBDT classifiers of nine datasets with a threat model that ranges from zero-knowledge to perfect-knowledge adversaries. Against zero-knowledge adversaries, we use the feature inversion symmetry and exceed the accuracies of default and robust classifiers by up to 100% points. Against perfect-knowledge adversaries for the GBDT classifier of the F-MNIST dataset, we use the feature inversion and horizontal flip symmetries and exceed the accuracies of default and robust classifiers by up to 96% points. Finally, we show that the current definition of adversarial robustness based on the minimum perturbation values of misclassifying adversarial samples might be inadequate for two reasons. First, this definition assumes that attacks mostly succeed, failing to consider the case when attacks are unable to construct misclassifying adversarial samples against a classifier. Second, GBDT adversarial robustness as currently defined can decrease by training with additional samples, even training samples, which counters the common wisdom that more training samples should increase robustness. With the current definition of GBDT adversarial robustness, we can make GBDTs more adversarially robust by training them with fewer samples! The code is publicly available at https://github.com/blertal/xgboost-symmetry-defense.en
dc.description.versionPeer revieweden
dc.format.extent13
dc.format.mimetypeapplication/pdf
dc.identifier.citationLindqvist, B 2025, 'On the Adversarial Robustness of Decision Trees and a Symmetry Defense', IEEE Access, vol. 13, pp. 16120-16132. https://doi.org/10.1109/ACCESS.2025.3530695en
dc.identifier.doi10.1109/ACCESS.2025.3530695
dc.identifier.issn2169-3536
dc.identifier.otherPURE UUID: 4319b094-b339-42dc-808c-a3aa4ca2c876
dc.identifier.otherPURE ITEMURL: https://research.aalto.fi/en/publications/4319b094-b339-42dc-808c-a3aa4ca2c876
dc.identifier.otherPURE LINK: http://www.scopus.com/inward/record.url?scp=85215979138&partnerID=8YFLogxK
dc.identifier.otherPURE FILEURL: https://research.aalto.fi/files/176541217/On_the_Adversarial_Robustness_of_Decision_Trees_and_a_Symmetry_Defense.pdf
dc.identifier.urihttps://aaltodoc.aalto.fi/handle/123456789/134678
dc.identifier.urnURN:NBN:fi:aalto-202503192924
dc.language.isoenen
dc.publisherIEEE
dc.relation.ispartofseriesIEEE Accessen
dc.relation.ispartofseriesVolume 13, pp. 16120-16132en
dc.rightsopenAccessen
dc.rightsCC BY
dc.rights.urihttps://creativecommons.org/licenses/by/4.0/
dc.subject.keywordAdversarial perturbation attacks
dc.subject.keywordadversarial robustness
dc.subject.keywordequivariance
dc.subject.keywordgradient-boosting decision trees
dc.subject.keywordinvariance
dc.subject.keywordsymmetry defense
dc.subject.keywordXGBoost
dc.titleOn the Adversarial Robustness of Decision Trees and a Symmetry Defenseen
dc.typeA1 Alkuperäisartikkeli tieteellisessä aikakauslehdessäfi
dc.type.versionpublishedVersion

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
On_the_Adversarial_Robustness_of_Decision_Trees_and_a_Symmetry_Defense.pdf
Size:
1.88 MB
Format:
Adobe Portable Document Format