FraudBench: Protocol-Sensitive Benchmarking of Adversarial Robustness for Financial Risk Assessment

📅 2026-08-25
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出FraudBench,通过三种匹配协议评估金融欺诈和信用风险检测中机器学习模型的对抗鲁棒性,解决因领域特定约束、类别不平衡及攻击者能力不对称导致的鲁棒性评估难题。
📝 Abstract
Machine learning models are widely used in financial fraud and credit-risk detection, yet their adversarial robustness remains difficult to evaluate because financial tabular data involve domain-specific constraints, severe class imbalance, and asymmetric attacker capability. We argue that, in this setting, robustness is not only an attribute of the model, but also an attribute of the evaluation protocol. Different ways of enforcing constraints and capability can lead to substantially different robustness conclusions. This paper presents FraudBench, a protocol-sensitive benchmark for adversarial robustness evaluation in financial fraud and credit-risk detection. Rather than treating domain constraints as post-hoc validity checks, FraudBench evaluates the same dataset--model--attack--defence setting under three matched protocols: unconstrained attacks, post-hoc feasibility filtering, and deployment-aware constraint-integrated attacks. FraudBench covers four public financial datasets, and evaluates neural, tree-based, and ensemble models using three attack settings. Our results show that robustness conclusions are highly protocol-sensitive. On Lending Club Loan Data under the white-box setting, post-hoc filtering leaves only 3.7 feasible-flipped examples on average, whereas in-attack projection with attacker mutability masking produces 2,832.3 feasible-flipped examples under the same perturbation budget. The results on IEEE-CIS further show that feasibility and attacker capability are separate axes, while black-box evaluation shows that protocol choice can alter model-family rankings. These findings suggest that fraud robustness evaluation should report predictive degradation and attack feasibility jointly, and should incorporate domain constraints into attack generation rather than treating them as post-processing checks.
Problem

Research questions and friction points this paper is trying to address.

adversarial robustness
financial fraud
credit-risk detection
domain-specific constraints
class imbalance
Innovation

Methods, ideas, or system contributions that make the work stand out.

protocol-sensitive benchmarking
adversarial robustness
financial fraud detection
constraint-integrated attacks
feasibility filtering
X
Xitong Zeng
School of Electrical and Computer Engineering, The University of Sydney
Z
Zhaoge Bi
School of Electrical and Computer Engineering, The University of Sydney
Yitian Yang
Yitian Yang
AI4SG Lab, National University of Singapore
Human Computer InteractionHuman-centered AI
Huaming Chen
Huaming Chen
The University of Sydney
Trustworthy MLApplied Machine LearningData MiningService Computing
Q
Quan Z. Sheng
School of Computing, Macquarie University