Adversarial Robustness in One-Stage Learning-to-Defer

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Montreuil, Yannis, Yu, Letian, Carlier, Axel, Ng, Lai Xing, Ooi, Wei Tsang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913171265028096
author Montreuil, Yannis
Yu, Letian
Carlier, Axel
Ng, Lai Xing
Ooi, Wei Tsang
author_facet Montreuil, Yannis
Yu, Letian
Carlier, Axel
Ng, Lai Xing
Ooi, Wei Tsang
contents Learning-to-Defer (L2D) enables hybrid decision-making by routing inputs either to a predictor or to external experts. While promising, L2D is highly vulnerable to adversarial perturbations, which can not only flip predictions but also manipulate deferral decisions. Prior robustness analyses focus solely on two-stage settings, leaving open the end-to-end (one-stage) case where predictor and allocation are trained jointly. We introduce the first framework for adversarial robustness in one-stage L2D, covering both classification and regression. Our approach formalizes attacks, proposes cost-sensitive adversarial surrogate losses, and establishes theoretical guarantees including $\mathcal{H}$, $(\mathcal{R }, \mathcal{F})$, and Bayes consistency. Experiments on benchmark datasets confirm that our methods improve robustness against untargeted and targeted attacks while preserving clean performance.
format Preprint
id arxiv_https___arxiv_org_abs_2510_10988
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Adversarial Robustness in One-Stage Learning-to-Defer
Montreuil, Yannis
Yu, Letian
Carlier, Axel
Ng, Lai Xing
Ooi, Wei Tsang
Machine Learning
Learning-to-Defer (L2D) enables hybrid decision-making by routing inputs either to a predictor or to external experts. While promising, L2D is highly vulnerable to adversarial perturbations, which can not only flip predictions but also manipulate deferral decisions. Prior robustness analyses focus solely on two-stage settings, leaving open the end-to-end (one-stage) case where predictor and allocation are trained jointly. We introduce the first framework for adversarial robustness in one-stage L2D, covering both classification and regression. Our approach formalizes attacks, proposes cost-sensitive adversarial surrogate losses, and establishes theoretical guarantees including $\mathcal{H}$, $(\mathcal{R }, \mathcal{F})$, and Bayes consistency. Experiments on benchmark datasets confirm that our methods improve robustness against untargeted and targeted attacks while preserving clean performance.
title Adversarial Robustness in One-Stage Learning-to-Defer
topic Machine Learning
url https://arxiv.org/abs/2510.10988