Row Selection in Context-Label Attacks on Tabular Foundation Models
Abstract
A tabular foundation model uses labeled context rows to predict new rows. Changing a small number of context labels can therefore affect many predictions. We study how the choice of rows changes this damage. We compare neighbor-degree, mean-distance, and query-coverage selectors across TabPFNv2-12L, TabICLv2, and Mitra. Class-matched random controls separate total corruption damage from the additional damage due to row selection. Hub attacks span five count budgets and four percentage budgets. Their total loss grows with corruption, while additional damage depends on geometry and budget. On eight external datasets, representation hubs and random selection have equivalent normalized loss at 25 labels within a margin of 0.005. At 15%, input hubs and mean-distance selection add 4.16 and 2.60 percentage points of accuracy loss relative to their respective controls. Input anti-hubs, which appear in few neighbor sets, add 1.00 percentage point at 5% and retain additional loss under coverage matching, repeated tie choices, and row permutations. In an exploratory single-label analysis, query coverage has a clearer association with influence than neighbor degree. Selecting high-coverage rows adds 1.38 percentage points of accuracy loss at 5%. Together, these results identify how selection geometry, attack size, and the prediction measure shape context-label attacks.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.