Adversarial Robustness in One-Stage Learning-to-Defer

Yannis Montreuil, Yu Letian, Axel Carlier, Lai Xing Ng, Wei Tsang Ooi
Proceedings of The 29th International Conference on Artificial Intelligence and Statistics, PMLR 300:2710-2718, 2026.

Abstract

Learning-to-Defer (L2D) enables hybrid decision-making by routing inputs either to a predictor or to external experts. While promising, L2D is highly vulnerable to adversarial perturbations, which can not only flip predictions but also manipulate deferral decisions. Prior robustness analyses focus solely on two-stage settings, leaving open the end-to-end (one-stage) case where predictor and allocation are trained jointly. We introduce the first framework for adversarial robustness in one-stage L2D, covering both classification and regression. Our approach formalizes attacks, proposes cost-sensitive adversarial surrogate losses, and establishes theoretical guarantees including $\mathcal{H}$, $(\mathcal{R }, \mathcal{F})$, and Bayes consistency. Experiments on benchmark datasets confirm that our methods improve robustness against untargeted and targeted attacks while preserving clean performance.

Cite this Paper


BibTeX
@InProceedings{pmlr-v300-montreuil26c, title = { Adversarial Robustness in One-Stage Learning-to-Defer }, author = {Montreuil, Yannis and Letian, Yu and Carlier, Axel and Ng, Lai Xing and Ooi, Wei Tsang}, booktitle = {Proceedings of The 29th International Conference on Artificial Intelligence and Statistics}, pages = {2710--2718}, year = {2026}, editor = {Khan, Emtiyaz and Li, Yingzhen and Solin, Arno and Ramdas, Aaditya}, volume = {300}, series = {Proceedings of Machine Learning Research}, month = {02--05 May}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v300/main/assets/montreuil26c/montreuil26c.pdf}, url = {https://proceedings.mlr.press/v300/montreuil26c.html}, abstract = { Learning-to-Defer (L2D) enables hybrid decision-making by routing inputs either to a predictor or to external experts. While promising, L2D is highly vulnerable to adversarial perturbations, which can not only flip predictions but also manipulate deferral decisions. Prior robustness analyses focus solely on two-stage settings, leaving open the end-to-end (one-stage) case where predictor and allocation are trained jointly. We introduce the first framework for adversarial robustness in one-stage L2D, covering both classification and regression. Our approach formalizes attacks, proposes cost-sensitive adversarial surrogate losses, and establishes theoretical guarantees including $\mathcal{H}$, $(\mathcal{R }, \mathcal{F})$, and Bayes consistency. Experiments on benchmark datasets confirm that our methods improve robustness against untargeted and targeted attacks while preserving clean performance. } }
Endnote
%0 Conference Paper %T Adversarial Robustness in One-Stage Learning-to-Defer %A Yannis Montreuil %A Yu Letian %A Axel Carlier %A Lai Xing Ng %A Wei Tsang Ooi %B Proceedings of The 29th International Conference on Artificial Intelligence and Statistics %C Proceedings of Machine Learning Research %D 2026 %E Emtiyaz Khan %E Yingzhen Li %E Arno Solin %E Aaditya Ramdas %F pmlr-v300-montreuil26c %I PMLR %P 2710--2718 %U https://proceedings.mlr.press/v300/montreuil26c.html %V 300 %X Learning-to-Defer (L2D) enables hybrid decision-making by routing inputs either to a predictor or to external experts. While promising, L2D is highly vulnerable to adversarial perturbations, which can not only flip predictions but also manipulate deferral decisions. Prior robustness analyses focus solely on two-stage settings, leaving open the end-to-end (one-stage) case where predictor and allocation are trained jointly. We introduce the first framework for adversarial robustness in one-stage L2D, covering both classification and regression. Our approach formalizes attacks, proposes cost-sensitive adversarial surrogate losses, and establishes theoretical guarantees including $\mathcal{H}$, $(\mathcal{R }, \mathcal{F})$, and Bayes consistency. Experiments on benchmark datasets confirm that our methods improve robustness against untargeted and targeted attacks while preserving clean performance.
APA
Montreuil, Y., Letian, Y., Carlier, A., Ng, L.X. & Ooi, W.T.. (2026). Adversarial Robustness in One-Stage Learning-to-Defer . Proceedings of The 29th International Conference on Artificial Intelligence and Statistics, in Proceedings of Machine Learning Research 300:2710-2718 Available from https://proceedings.mlr.press/v300/montreuil26c.html.

Related Material