Decision-based Evasion Attacks on Tree Ensemble Classifiers

Zhang Fuyong,Wang Yi,Liu Shigang,Wang Hua
DOI: https://doi.org/10.1007/s11280-020-00813-y
2020-01-01
World Wide Web
Abstract:Learning-based classifiers are found to be susceptible to adversarial examples. Recent studies suggested that ensemble classifiers tend to be more robust than single classifiers against evasion attacks. In this paper, we argue that this is not necessarily the case. In particular, we show that a discrete-valued random forest classifier can be easily evaded by adversarial inputs manipulated based only on the model decision outputs. The proposed evasion algorithm is gradient free and can be fast implemented. Our evaluation results demonstrate that random forests can be even more vulnerable than SVMs, either single or ensemble, to evasion attacks under both white-box and the more realistic black-box settings.
What problem does this paper attempt to address?