TabAttackBench: A Benchmark for Adversarial Attacks on Tabular Data

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: He, Zhipeng, Ouyang, Chun, Wen, Lijie, Liu, Cong, Moreira, Catarina
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909946976665600
author He, Zhipeng
Ouyang, Chun
Wen, Lijie
Liu, Cong
Moreira, Catarina
author_facet He, Zhipeng
Ouyang, Chun
Wen, Lijie
Liu, Cong
Moreira, Catarina
contents Adversarial attacks pose a significant threat to machine learning models by inducing incorrect predictions through imperceptible perturbations to input data. While these attacks are well studied in unstructured domains such as images, their behaviour on tabular data remains underexplored due to mixed feature types and complex inter-feature dependencies. This study introduces a comprehensive benchmark that evaluates adversarial attacks on tabular datasets with respect to both effectiveness and imperceptibility. We assess five white-box attack algorithms (FGSM, BIM, PGD, DeepFool, and C\&W) across four representative models (LR, MLP, TabTransformer and FT-Transformer) using eleven datasets spanning finance, energy, and healthcare domains. The benchmark employs four quantitative imperceptibility metrics (proximity, sparsity, deviation, and sensitivity) to characterise perturbation realism. The analysis quantifies the trade-off between these two aspects and reveals consistent differences between attack types, with $\ell_\infty$-based attacks achieving higher success but lower subtlety, and $\ell_2$-based attacks offering more realistic perturbations. The benchmark findings offer actionable insights for designing more imperceptible adversarial attacks, advancing the understanding of adversarial vulnerability in tabular machine learning.
format Preprint
id arxiv_https___arxiv_org_abs_2505_21027
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle TabAttackBench: A Benchmark for Adversarial Attacks on Tabular Data
He, Zhipeng
Ouyang, Chun
Wen, Lijie
Liu, Cong
Moreira, Catarina
Machine Learning
Artificial Intelligence
Adversarial attacks pose a significant threat to machine learning models by inducing incorrect predictions through imperceptible perturbations to input data. While these attacks are well studied in unstructured domains such as images, their behaviour on tabular data remains underexplored due to mixed feature types and complex inter-feature dependencies. This study introduces a comprehensive benchmark that evaluates adversarial attacks on tabular datasets with respect to both effectiveness and imperceptibility. We assess five white-box attack algorithms (FGSM, BIM, PGD, DeepFool, and C\&W) across four representative models (LR, MLP, TabTransformer and FT-Transformer) using eleven datasets spanning finance, energy, and healthcare domains. The benchmark employs four quantitative imperceptibility metrics (proximity, sparsity, deviation, and sensitivity) to characterise perturbation realism. The analysis quantifies the trade-off between these two aspects and reveals consistent differences between attack types, with $\ell_\infty$-based attacks achieving higher success but lower subtlety, and $\ell_2$-based attacks offering more realistic perturbations. The benchmark findings offer actionable insights for designing more imperceptible adversarial attacks, advancing the understanding of adversarial vulnerability in tabular machine learning.
title TabAttackBench: A Benchmark for Adversarial Attacks on Tabular Data
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2505.21027