Skip to content
InfoResearchPeer-reviewed

A SHAP-guided heterogeneous ensemble defense framework for financial risk assessment under white-box adversarial attacks

Published
Record updated
View JSON

Summary

Researchers evaluated a three-layer ensemble defense for deep learning credit risk models, combining MLP, ResNet-1D and TabTransformer architectures with PGD adversarial training and SHAP-based routing. On German Credit and Lending Club under FGSM, PGD and CW attacks across five seeds, the defended AUCs reached 0.758 and 0.723, and the default-class attack success rate fell from 0.52 to 0.19 and from 0.55 to 0.21. SHAP attribution consistency also improved, with Spearman correlation rising from 0.42 to 0.87 between clean and defended explanations.

Mitigation

The defense framework itself is the proposed mitigation: a three-layer heterogeneous ensemble with PGD adversarial training and SHAP-based routing. The source does not describe a separate patch, fixed version or configuration change.