arXiv:2509.22850cs.LGcs.AI2025-09被引 1

针对表格数据提出高效黑盒攻击,仅用少量查询即可突破多数模型

Boundary on the Table: Efficient Black-Box Decision-Based Attacks for Structured Data

  • 结合无梯度方向估计与边界搜索,适应离散连续混合特征空间
  • 攻击成功率超90%,单样本平均查询次数极少
  • 适用于传统模型和大模型管道,揭示表格系统安全短板

与视觉和语言领域相比,结构化数据的对抗鲁棒性仍是一个未充分探索的前沿。本文提出一种新型黑盒、基于决策的表格数据对抗攻击方法。该方法结合无梯度方向估计与迭代边界搜索,在极少查询次数下实现对离散与连续特征空间的有效导航。大量实验表明,该方法在多种模型上几乎攻破全部测试集,涵盖经典机器学习分类器到大型语言模型(LLM)驱动的流水线。令人瞩目的是,攻击成功率稳定高于90%,且每实例所需查询数极低。结果凸显了表格模型在对抗扰动下的严重脆弱性,强调了在真实决策系统中亟需强化防御措施。

原文摘要 · Abstract (English)

Adversarial robustness in structured data remains an underexplored frontier compared to vision and language domains. In this work, we introduce a novel black-box, decision-based adversarial attack tailored for tabular data. Our approach combines gradient-free direction estimation with an iterative boundary search, enabling efficient navigation of discrete and continuous feature spaces under minimal oracle access. Extensive experiments demonstrate that our method successfully compromises nearly the entire test set across diverse models, ranging from classical machine learning classifiers to large language model (LLM)-based pipelines. Remarkably, the attack achieves success rates consistently above 90%, while requiring only a small number of queries per instance. These results highlight the critical vulnerability of tabular models to adversarial perturbations, underscoring the urgent need for stronger defenses in real-world decision-making systems.

黑盒攻击表格数据对抗样本模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。