A SHAP-guided heterogeneous ensemble defense framework for financial risk assessment under white-box adversarial attacks
Deep learning models in financial risk assessment are vulnerable to adversarial perturbations with economic and regulatory consequences. We evaluate a three-layer ensemble defense integrating heterogeneous architectures (MLP, ResNet-1D, TabTransformer), PGD adversarial training, and SHAP-based routing. On German Credit and Lending Club, under FGSM, PGD, and CW attacks across five seeds, the framework achieved defended AUCs of \(0.758 \pm 0.016\) and \(0.723 \pm 0.018\) , respectively, and reduced the default-class attack success rate (ASR) from 0.52 to 0.19 and from 0.55 to 0.21. As a secondary reference-normalized metric, these defended AUCs correspond to 84.9% and 92.9% MLP-reference recovery under the stated convention. A supplementary routing-evasion proxy served as a sensitivity check for the proposed configuration. Under PGD transferability evaluation, cross-architecture transferability averaged 29.5% (95% CI: [28.1%, 30.9%]), supporting heterogeneous ensemble design. SHAP analysis showed improved attribution consistency: Spearman correlation between clean and defended explanations increased from \(\rho = 0.42\) to \(\rho = 0.87\) , and cosine similarity from 0.51 to 0.91. Sequential ablation suggested incremental gains from adversarial training, architectural diversity, and SHAP routing along the evaluated path.
Authors
- Chengye Yan (ORCID: https://orcid.org/0009-0009-7429-8413)
Institutions
- Shanxi University of Finance and Economics (CN)
Publication Details
- Journal
- Scientific Reports
- Published
- 2026-10-04
- DOI
- https://doi.org/10.1038/s41598-026-72297-1
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00