
Chengye Yan · Scientific Reports 2026 · 2026
DOI: 10.1038/s41598-026-72297-1
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Deep learning models in financial risk assessment are vulnerable to adversarial perturbations with economic and regulatory consequences. We evaluate a three-layer ensemble defense integrating heterogeneous architectures (MLP, ResNet-1D, TabTransformer), PGD adversarial training, and SHAP-based routing. On German Credit and Lending Club, under FGSM, PGD, and CW attacks across five seeds, the framework achieved defended AUCs of \(0.758 \pm 0.016\) and \(0.723 \pm 0.018\) , respectively, and reduced the default-class attack success rate (ASR) from 0.52 to 0.19 and from 0.55 to 0.21. As a secondary reference-normalized metric, these defended AUCs correspond to 84.9% and 92.9% MLP-reference recovery under the stated convention. A supplementary routing-evasion proxy served as a sensitivity check for the proposed configuration. Under PGD transferability evaluation, cross-architecture transferability averaged 29.5% (95% CI: [28.1%, 30.9%]), supporting heterogeneous ensemble design. SHAP analysis showed improved attribution consistency: Spearman correlation between clean and defended explanations increased from \(\rho = 0.42\) to \(\rho = 0.87\) , and cosine similarity from 0.51 to 0.91. Sequential ablation suggested incremental gains from adversarial training, architectural diversity, and SHAP routing along the evaluated path.
No comments yet — start the discussion below.