Backdoor Attacks on Transformers for Tabular Data

An Empirical Study

Conference Paper (2026)
Author(s)

Bart Pleiter (Radboud Universiteit Nijmegen)

Behrad Tajalli (Radboud Universiteit Nijmegen)

Stefanos Koffas (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Gorka Abad (University of Bergen, Radboud Universiteit Nijmegen)

Jing Xu (TU Delft - Electrical Engineering, Mathematics and Computer Science)

Martha Larson (TU Delft - Electrical Engineering, Mathematics and Computer Science, Radboud Universiteit Nijmegen)

Stjepan Picek (University of Zagreb, TU Delft - Electrical Engineering, Mathematics and Computer Science, Radboud Universiteit Nijmegen, University of Bergen)

Research Group
Cyber Security
DOI related publication
https://doi.org/10.1007/978-3-032-16092-8_21 Final published version
More Info
expand_more
Publication Year
2026
Language
English
Research Group
Cyber Security
Pages (from-to)
377-396
Publisher
Springer Science and Business Media Deutschland GmbH
ISBN (print)
9783032160911
Event
30th European Symposium on Research in Computer Security, ESORICS 2025 (2025-09-22 - 2025-09-24), Toulouse, France
Downloads counter
16
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Deep Neural Networks (DNNs) have shown great promise in various domains. However, vulnerabilities associated with DNN training, such as backdoor attacks, are a significant concern. These attacks involve the subtle insertion of triggers during model training, allowing for manipulated predictions. More recently, DNNs used with tabular data have gained increasing attention due to the rise of transformer models. Our research presents a comprehensive analysis of backdoor attacks on tabular data using DNNs, mainly focusing on transformers. We propose a novel approach for trigger construction: in-bounds attack, which provides excellent attack performance while maintaining stealthiness. Through systematic experimentation across benchmark datasets, we uncover that transformer-based DNNs for tabular data are highly susceptible to backdoor attacks, even with minimal feature value alterations. We also verify that these attacks can be generalized to other models, like XGBoost and DeepFM. Our results demonstrate up to 100% attack success rate with negligible clean accuracy drop. Furthermore, we evaluate several defenses against these attacks, identifying Spectral Signatures as the most effective. Still, our findings highlight the need to develop tabular data-specific countermeasures to defend against backdoor attacks.

Files

978-3-032-16092-8_21.pdf
(pdf | 1.76 Mb)
– Personal use only – Dutch Copyright Act (Article 25fa)
warning

File under embargo until 02-11-2026