Reviews: Provably robust boosted decision stumps and trees against adversarial attacks

Neural Information Processing Systems 

As a main contribution, the authors derive an exact attack algorithm on ensembles of decision stumps for \ell_\infty perturbations. In contrast, this problem is known to be NP-Hard for trees with at least 3 internal nodes, via previous work by Kantchelian et.