Feature partitioning for robust tree ensembles and their certification in adversarial scenarios

被引:0
|
作者
Stefano Calzavara
Claudio Lucchese
Federico Marcuzzi
Salvatore Orlando
机构
[1] Ca’ Foscari University of Venice,Department of Environmental Sciences, Informatics and Statistics
关键词
Adversarial machine learning; Evasion attack; Forests of decision trees;
D O I
暂无
中图分类号
学科分类号
摘要
Machine learning algorithms, however effective, are known to be vulnerable in adversarial scenarios where a malicious user may inject manipulated instances. In this work, we focus on evasion attacks, where a model is trained in a safe environment and exposed to attacks at inference time. The attacker aims at finding a perturbation of an instance that changes the model outcome.We propose a model-agnostic strategy that builds a robust ensemble by training its basic models on feature-based partitions of the given dataset. Our algorithm guarantees that the majority of the models in the ensemble cannot be affected by the attacker. We apply the proposed strategy to decision tree ensembles, and we also propose an approximate certification method for tree ensembles that efficiently provides a lower bound of the accuracy of a forest in the presence of attacks on a given dataset avoiding the costly computation of evasion attacks.Experimental evaluation on publicly available datasets shows that the proposed feature partitioning strategy provides a significant accuracy improvement with respect to competitor algorithms and that the proposed certification method allows ones to accurately estimate the effectiveness of a classifier where the brute-force approach would be unfeasible.
引用
收藏
相关论文
共 50 条
  • [1] Feature partitioning for robust tree ensembles and their certification in adversarial scenarios
    Calzavara, Stefano
    Lucchese, Claudio
    Marcuzzi, Federico
    Orlando, Salvatore
    [J]. EURASIP JOURNAL ON INFORMATION SECURITY, 2021, 2021 (01)
  • [2] Relational tree ensembles and feature rankings
    Petkovic, Matej
    Ceci, Michelangelo
    Pio, Gianvito
    Skrlj, Blaz
    Kersting, Kristian
    Dzeroski, Sago
    [J]. KNOWLEDGE-BASED SYSTEMS, 2022, 251
  • [3] Verifiable Learning for Robust Tree Ensembles
    Calzavara, Stefano
    Cazzaro, Lorenzo
    Pibiri, Giulio Ermanno
    Prezza, Nicola
    [J]. PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 1850 - 1864
  • [4] Robust Counterfactual Explanations for Tree-Based Ensembles
    Dutta, Sanghamitra
    Long, Jason
    Mishra, Saumitra
    Tilli, Cecilia
    Magazzeni, Daniele
    [J]. INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [5] A Robust Framework for Adaptive Selection of Filter Ensembles to Detect Adversarial Inputs
    Roy, Arunava
    Dasgupta, Dipankar
    [J]. 52ND ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOP VOLUME (DSN-W 2022), 2022, : 59 - 67
  • [6] Robust feature learning for adversarial defense via hierarchical feature alignment
    Zhang, Xiaoqin
    Wang, Jinxin
    Wang, Tao
    Jiang, Runhua
    Xu, Jiawei
    Zhao, Li
    [J]. INFORMATION SCIENCES, 2021, 560 : 256 - 270
  • [7] A NEW FEATURE SET PARTITIONING METHOD FOR NEAREST MEAN CLASSIFIER ENSEMBLES
    Abdullah
    Ku-Mahamud, Ku Ruhana
    Sediyono, Agung
    [J]. COMPUTING & INFORMATICS, 4TH INTERNATIONAL CONFERENCE, 2013, 2013, : 39 - +
  • [8] Application Partitioning on FPGA Clusters: Inference over Decision Tree Ensembles
    Owaida, Muhsen
    Alonso, Gustavo
    [J]. 2018 28TH INTERNATIONAL CONFERENCE ON FIELD PROGRAMMABLE LOGIC AND APPLICATIONS (FPL), 2018, : 295 - 300
  • [9] NON-UNIFORM FEATURE SAMPLING FOR DECISION TREE ENSEMBLES
    Kyrillidis, Anastasios
    Zouzias, Anastasios
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2014,
  • [10] Debiasing MDI Feature Importance and SHAP Values in Tree Ensembles
    Loecher, Markus
    [J]. MACHINE LEARNING AND KNOWLEDGE EXTRACTION, CD-MAKE 2022, 2022, 13480 : 114 - 129