From: Feature partitioning for robust tree ensembles and their certification in adversarial scenarios
b | Ak | Number of rounds r | ||
---|---|---|---|---|
1 | 15 | 30 | ||
f-FPF algorithm | ||||
1 | 0 | 0.956 | 0.939 | 0.939 |
1 | 0.842 | 0.921 | 0.921 | |
2 | 0.000 | 0.675 | 0.719 | |
3 | 0.000 | 0.114 | 0.158 | |
2 | 0 | 0.93 | 0.939 | 0.939 |
1 | 0.904 | 0.930 | 0.930 | |
2 | 0.754 | 0.842 | 0.842 | |
3 | 0.123 | 0.404 | 0.474 | |
3 | 0 | 0.947 | 0.939 | 0.939 |
1 | 0.912 | 0.921 | 0.921 | |
2 | 0.833 | 0.86 | 0.86 | |
3 | 0.675 | 0.772 | 0.763 | |
4 | 0 | 0.956 | 0.939 | 0.939 |
1 | 0.895 | 0.904 | 0.904 | |
2 | 0.825 | 0.868 | 0.868 | |
3 | 0.728 | 0.807 | 0.807 | |
5 | 0 | 0.930 | 0.939 | 0.930 |
1 | 0.912 | 0.895 | 0.895 | |
2 | 0.842 | 0.860 | 0.868 | |
3 | 0.746 | 0.816 | 0.816 | |
h-FPF Algorithm | ||||
1 | 0 | 0.956 | 0.956 | 0.947 |
1 | 0.842 | 0.912 | 0.921 | |
2 | 0.000 | 0.658 | 0.421 | |
3 | 0.000 | 0.07 | 0.079 | |
2 | 0 | 0.93 | 0.939 | 0.939 |
1 | 0.904 | 0.930 | 0.930 | |
2 | 0.754 | 0.833 | 0.851 | |
3 | 0.123 | 0.351 | 0.377 | |
3 | 0 | 0.947 | 0.939 | 0.939 |
1 | 0.912 | 0.921 | 0.930 | |
2 | 0.833 | 0.860 | 0.877 | |
3 | 0.675 | 0.772 | 0.772 | |
4 | 0 | 0.956 | 0.930 | 0.930 |
1 | 0.895 | 0.904 | 0.904 | |
2 | 0.825 | 0.860 | 0.868 | |
3 | 0.728 | 0.798 | 0.816 | |
5 | 0 | 0.930 | 0.939 | 0.921 |
1 | 0.912 | 0.895 | 0.895 | |
2 | 0.842 | 0.868 | 0.877 | |
3 | 0.746 | 0.816 | 0.825 |