发表机构
University of Twente(特文特大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对P2P借贷表格信用评分,系统评估对抗训练在多种攻击下的鲁棒性,发现混合攻击训练能实现最均衡的防御并保持性能。
AI 中文摘要
基于机器学习的信用评分在点对点(P2P)借贷中日益核心,但其对对抗性操纵的韧性——即申请人策略性地改变自我报告输入以获得有利决策——仍鲜为人知。大多数对抗鲁棒性证据来自图像和文本领域,且仅评估针对匹配防御的单一攻击,对防御在表格信用数据中跨攻击类型的泛化能力提供的指导甚少。我们通过在大型Lending Club子集上进行系统的训练-测试鲁棒性基准来应对这一问题,涵盖三个模型家族(逻辑回归、前馈神经网络和用于表格数据的Transformer)以及四种限于申请人可变更特征的攻击:快速梯度符号法(FGSM)、投影梯度下降(PGD)、椒盐(S&P)噪声和DeepFool,外加一种混合攻击机制。在通过分层交叉验证评估的完整网格中,对抗训练显著提高了针对其训练攻击的鲁棒性,并在基于梯度的攻击家族内良好迁移,但对非梯度扰动的迁移较弱,因此单一攻击防御高估了现实世界的韧性。混合训练在异质攻击间提供了最均衡的鲁棒性,同时保持了干净测试性能,支持在信用模型治理中进行多攻击压力测试。
英文摘要
Machine learning-based credit scoring is increasingly central to Peer-to-Peer (P2P) lending, yet its resilience to adversarial manipulation, where applicants strategically alter self-reported inputs to secure favourable decisions, remains poorly understood. Most adversarial-robustness evidence comes from image and text domains and evaluates a single attack against a matching defence, offering little guidance on how defences generalise across attack types in tabular credit data. We address this with a systematic train-test robustness benchmark on a large Lending Club subset, spanning three model families (logistic regression, a feed-forward neural network, and a transformer for tabular data) and four attacks confined to applicant-mutable features: Fast Gradient Sign Method (FGSM), Projected Gradient Descent (PGD), Salt-and-Pepper (S&P) noise, and DeepFool, plus a mixed-attack regime. Across a full grid evaluated with stratified cross-validation, adversarial training sharply improves robustness against the attack it is trained on and transfers well within the gradient-based family, but transfers weakly to non-gradient corruption, so single-attack defences overstate real-world resilience. Mixed training delivers the most balanced robustness across heterogeneous attacks while preserving clean-test performance, supporting multi-attack stress testing in credit-model governance.