Life sciences · Preprint
arXiv · September 9, 2026
Early or partial results. Treat as a signal, not a conclusion.
This unreviewed benchmark demonstrates that adversarial training improves robustness to the attack it targets, with good transfer among gradient-based attacks but poor transfer to non-gradient noise corruption. Mixed-attack training delivered the most balanced defence across heterogeneous adversarial perturbations while preserving clean-test performance, suggesting that single-attack defences underestimate real-world vulnerability in credit scoring.
Computational benchmark study with stratified cross-validation. Large subset of Lending Club P2P lending applicants; self-reported credit application data with mutable features (those applicants can alter).. Intervention: Adversarial training regimes: single-attack defences (one per attack type) and mixed-attack training. Compared with: Undefended baseline models and single-attack defences evaluated against each other and against mixed-attack training.
Adversarial training sharply improves robustness against the attack it is trained on Gradient-based defences transfer well within the gradient family (FGSM, PGD, DeepFool) but transfer weakly to non-gradient corruption (Salt-and-Pepper noise) Mixed-attack training delivers the most balanced robustness across heterogeneous attacks while preserving clean-test performance
Safety was not reported in the material analysed. Check the source before drawing any conclusion about harm.
For credit-risk practitioners: adversarial training of credit-scoring models should account for multiple attack types rather than a single anticipated threat. Mixed-attack defences are recommended for governance stress testing, though this computational finding should be validated against real-world fraud patterns and lender policy before adoption.
A systematic benchmark study in an unreviewed preprint demonstrating adversarial training effects on tabular credit models, with sound methodology but no clinical or real-world validation of the governance recommendation.
As stated by the source record.
For credit-risk practitioners: adversarial training of credit-scoring models should account for multiple attack types rather than a single anticipated threat. Mixed-attack defences are recommended for governance stress testing, though this computational finding should be validated against real-world fraud patterns and lender policy before adoption.
Graded across the dimensions that decide whether you should act, each from what the source actually supports. There is no single score, and where a dimension was not assessed it says so.
What is missing. This record has no reported figures. That is a gap in the analysis, not a judgement about the study.
Machine learning-based credit scoring is increasingly central to Peer-to-Peer (P2P) lending, yet its resilience to adversarial manipulation, where applicants strategically alter self-reported inputs to secure favourable decisions, remains poorly understood. Most adversarial-robustness evidence comes from image and text domains and evaluates a single attack against a matching defence, offering little guidance on how defences generalise across attack types in tabular credit data. We address this with a systematic train-test robustness benchmark on a large Lending Club subset, spanning three model families (logistic regression, a feed-forward neural network, and a transformer for tabular data) and four attacks confined to applicant-mutable features: Fast Gradient Sign Method (FGSM), Projected Gradient Descent (PGD), Salt-and-Pepper (S&P) noise, and DeepFool, plus a mixed-attack regime. Across a full grid evaluated with stratified cross-validation, adversarial training sharply improves robustness against the attack it is trained on and transfers well within the gradient-based family, but transfers weakly to non-gradient corruption, so single-attack defences overstate real-world resilience. Mixed training delivers the most balanced robustness across heterogeneous attacks while preserving clean-test performance, supporting multi-attack stress testing in credit-model governance.
Taken from the source record, never inferred. Follow any of these and new work involving them reaches your briefing.