Improving the Robustness of Financial Models through Identification of the Minimal Vulnerable Feature Set
Anubha Pandey, Himanshu Chaudhary, Alekhya Bhatraju, Deepak Bhatt, Maneet Singh · 2023
Research in adversarial robustness has primarily focused on neural networks in domains like computer vision, neglecting heterogeneous tabular datasets prevalent in finance. The financial domain, in particular, faces a heightened risk, where malicious actors may exploit ML model vulnerabilities to manipulate transactions and gain unauthorized access. To address this gap, we aim to simulate the adversaries’ intentions using heterogeneous tabular data and focus on identifying a minimal vulnerable set of features that are most susceptible to an external attack. Identifying such features can enable developers to safeguard their models against adversarial attacks by updating or refining the rules of deployed models. To this effect, a GAN-based architecture, termed as the Feature Selector Network, has been proposed for learning the minimal vulnerable feature set. Experimental evaluation shows a significant reduction in attack generation time and the number of queries. The proposed method is tested using attack imperceptibility performance metrics, the number of queries, and the time to generate attacks using existing state-of-the-art attack algorithms. We observed up to a reduction in the number of queries and in overall attack generation time, along with a significant improvement in imperceptibility metrics like the Norm of perturbations and distance to closest neighbor while achieving a good success rate. Further experimental analysis suggested that the model trained on the adversaries generated using the proposed pipeline resulted in more than a decrease in the adversarial attack success rate on the test set, thus allowing developers a robust technique for safeguarding ML models.