arXiv:2506.02978cs.LG2025-06中稿 · publication at the…被引 4

发现表格基础模型易受测试时攻击,提出上下文对抗训练提升鲁棒性。

On the Robustness of Tabular Foundation Models: Test-Time Attacks and In-Context Defenses

  • 用结构化扰动攻击测试输入,可显著降低预测准确率。
  • 表格模型可生成迁移性对抗样本,威胁传统和深度表格式模型。
  • 无需更新权重,通过替换上下文实现对抗训练,提升多基准鲁棒性。

近期的表格基础模型(如 TabPFN、TabICL)利用上下文学习,在无需梯度更新或微调的情况下实现强性能。然而,其对对抗操纵的鲁棒性仍缺乏研究。本文在金融、网络安全和医疗三个基准上系统研究了表格基础模型的对抗脆弱性,发现即使训练上下文固定,对测试输入施加微小的结构化扰动,也会显著降低预测准确率。此外,我们证明这些模型可被重用于生成可迁移的逃避攻击,影响随机森林、XGBoost等传统模型,对深度表格式模型影响较小。为提升鲁棒性,我们提出优化权重(对抗微调)或上下文(对抗上下文学习)的鲁棒化方法。引入一种无需更新模型权重的上下文对抗训练策略,逐步用对抗扰动实例替换原始上下文。该方法在多个表格基准上有效提升了鲁棒性。结果表明,表格基础模型既是攻击目标,也是攻击工具,凸显了在此新兴范式中亟需建立鲁棒训练与评估实践。

原文摘要 · Abstract (English)

Recent tabular Foundational Models (FM) such as TabPFN and TabICL, leverage in-context learning to achieve strong performance without gradient updates or fine-tuning. However, their robustness to adversarial manipulation remains largely unexplored. In this work, we present a comprehensive study of the adversarial vulnerabilities of tabular FM, focusing on both their fragility to targeted test-time attacks and their potential misuse as adversarial tools. We show on three benchmarks in finance, cybersecurity and healthcare, that small, structured perturbations to test inputs can significantly degrade prediction accuracy, even when training context remain fixed. Additionally, we demonstrate that tabular FM can be repurposed to generate transferable evasion to conventional models such as random forests and XGBoost, and on a lesser extent to deep tabular models. To improve tabular FM, we formulate the robustification problem as an optimization of the weights (adversarial fine-tuning), or the context (adversarial in-context learning). We introduce an in-context adversarial training strategy that incrementally replaces the context with adversarial perturbed instances, without updating model weights. Our approach improves robustness across multiple tabular benchmarks. Together, these findings position tabular FM as both a target and a source of adversarial threats, highlighting the urgent need for robust training and evaluation practices in this emerging paradigm.

表格模型对抗攻击上下文学习鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。