From: Feature partitioning for robust tree ensembles and their certification in adversarial scenarios
Model | Parameters | Accuracy | |||||||
---|---|---|---|---|---|---|---|---|---|
b | r | p | ml | \(|{\mathcal {T}}|\) | \(\phantom {\dot {i}\!}ACC_{A_{0}}\) | k | \(\phantom {\dot {i}\!}ACC_{A_{k}}\) | Δ f-FPF | |
f-FPF | 3 | 42 | 8 | 300 | 0.939 | 1 | 0.912 | 0.000 | |
4 | 33 | 4 | 297 | 0.930 | 2 | 0.851 | 0.000 | ||
5 | 27 | 8 | 300 | 0.930 | 3 | 0.816 | 0.000 | ||
h-FPF | 3 | 42 | 8 | 300 | 0.939 | 1 | 0.912 | 0.000 | |
4 | 33 | 4 | 297 | 0.930 | 2 | 0.842 | −0.009 | ||
5 | 27 | 8 | 300 | 0.930 | 3 | 0.816 | 0.000 | ||
RSM | 0.2 | 16 | 300 | 0.956 | 1 | 0.912 | 0.000 | ||
0.2 | 16 | 300 | 0.956 | 2 | 0.833 | −0.018 | |||
0.2 | 16 | 300 | 0.956 | 3 | 0.658 | −0.158 | |||
RF | 4 | 300 | 0.930 | 1 | 0.877 | −0.035 | |||
8 | 300 | 0.947 | 2 | 0.842 | −0.009 | ||||
4 | 300 | 0.930 | 3 | 0.614 | −0.202 | ||||
RT | 1 | 4 | 300 | 0.923 | 1 | 0.562 | −0.350 | ||
1 | 4 | 300 | 0.923 | 2 | 0.505 | −0.346 | |||
1 | 4 | 300 | 0.923 | 3 | 0.454 | −0.362 |