From: Feature partitioning for robust tree ensembles and their certification in adversarial scenarios
k=1 | k=2 | k=3 | |||||||
---|---|---|---|---|---|---|---|---|---|
b | \(\phantom {\dot {i}\!}ACC_{A_{1}}\) | \(\phantom {\dot {i}\!}ACC_{A_{1}}^{ELB}\) | \(\phantom {\dot {i}\!}ACC_{A_{1}}^{FLB}\) | \(\phantom {\dot {i}\!}ACC_{A_{2}}\) | \(\phantom {\dot {i}\!}ACC_{A_{2}}^{ELB}\) | \(\phantom {\dot {i}\!}ACC_{A_{2}}^{FLB}\) | \(\phantom {\dot {i}\!}ACC_{A_{3}}\) | \(\phantom {\dot {i}\!}ACC_{A_{3}}^{ELB}\) | \(\phantom {\dot {i}\!}ACC_{A_{3}}^{FLB}\) |
1 | 0.912 | 0.886 | 0.886 | 0.763 | 0 | 0 | 0.184 | 0 | 0 |
2 | 0.912 | 0.904 | 0.904 | 0.842 | 0.833 | 0.825 | 0.649 | 0 | 0 |
3 | 0.912 | 0.912 | 0.912 | 0.860 | 0.851 | 0.842 | 0.781 | 0.763 | 0.737 |
4 | 0.904 | 0.904 | 0.904 | 0.868 | 0.868 | 0.868 | 0.798 | 0.798 | 0.798 |
5 | 0.895 | 0.895 | 0.895 | 0.868 | 0.868 | 0.868 | 0.816 | 0.816 | 0.807 |