A SHAP-guided heterogeneous ensemble defense framework for financial risk assessment under white-box adversarial attacks
- Published
- Record updated
Summary
Researchers evaluated a three-layer ensemble defense for deep learning credit risk models, combining MLP, ResNet-1D and TabTransformer architectures with PGD adversarial training and SHAP-based routing. On German Credit and Lending Club under FGSM, PGD and CW attacks across five seeds, the defended AUCs reached 0.758 and 0.723, and the default-class attack success rate fell from 0.52 to 0.19 and from 0.55 to 0.21. SHAP attribution consistency also improved, with Spearman correlation rising from 0.42 to 0.87 between clean and defended explanations.
Mitigation
The defense framework itself is the proposed mitigation: a three-layer heterogeneous ensemble with PGD adversarial training and SHAP-based routing. The source does not describe a separate patch, fixed version or configuration change.
Topics
Related items
- InfoDoes Target Alignment Mean Target Recovery? An Evidence-Ladder Study of Adversarial Claims on Contrastive EncodersSimilar attack · Arxiv (cs.RO + cs.CV security)
- InfoBRANCH: Bypassing Multi-Scanner AI GuardrailsSimilar attack · Arxiv (cs.CR + cs.CL + cs.LG)
- InfoDetecting Adversarial Images through Response Profiles of Vision-Language ModelsSimilar attack · Arxiv (cs.RO + cs.CV security)
- InfoGraphRectify: Graph-Based Transfer of Adversarial Example Detectors Across Neural NetworksSimilar attack · Arxiv (cs.RO + cs.CV security)
- InfoVCR-Bench: A Modular Open-Source Benchmark for Video Classification RobustnessSimilar attack · Arxiv (cs.RO + cs.CV security)