arXiv:2507.10048cs.LG2025-07

提升对抗鲁棒决策树训练效率,优化每一步流程

On the Efficiency of Training Robust Decision Trees

  • 自动选择数据集适配的扰动大小,减少试错成本
  • 验证阶段耗时与训练时间无关,可并行优化
  • 适合关注模型可信性与训练效率的研究者

随着机器学习在工业界快速应用,可信性愈发重要。然而,鲁棒训练流程的效率与可持续性仍需提升。本文研究一种训练对抗鲁棒决策树的简单流程,包含三个阶段:首先,为每个数据集自动确定扰动大小,提出一种无需依赖经验或先前工作的算法,并证明可用较小模型预估该值,显著提升效率;其次,采用当前最优的对抗训练方法,评估其训练时间和对抗准确率;最后,对所得模型进行鲁棒性认证,考察认证所需时间。结果发现,认证时间与训练时间无相关性,这对整体流程效率具有关键意义。

原文摘要 · Abstract (English)

As machine learning gets adopted into the industry quickly, trustworthiness is increasingly in focus. Yet, efficiency and sustainability of robust training pipelines still have to be established. In this work, we consider a simple pipeline for training adversarially robust decision trees and investigate the efficiency of each step. Our pipeline consists of three stages. Firstly, we choose the perturbation size automatically for each dataset. For that, we introduce a simple algorithm, instead of relying on intuition or prior work. Moreover, we show that the perturbation size can be estimated from smaller models than the one intended for full training, and thus significant gains in efficiency can be achieved. Secondly, we train state-of-the-art adversarial training methods and evaluate them regarding both their training time and adversarial accuracy. Thirdly, we certify the robustness of each of the models thus obtained and investigate the time required for this. We find that verification time, which is critical to the efficiency of the full pipeline, is not correlated with training time.

决策树对抗鲁棒训练效率

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。