Skip to main content

Showing 1–5 of 5 results for author: Scholten, Y

.
  1. arXiv:2312.02708  [pdf, other

    cs.LG cs.CR stat.ML

    Provable Adversarial Robustness for Group Equivariant Tasks: Graphs, Point Clouds, Molecules, and More

    Authors: Jan Schuchardt, Yan Scholten, Stephan Günnemann

    Abstract: A machine learning model is traditionally considered robust if its prediction remains (almost) constant under input perturbations with small norm. However, real-world tasks like molecular property prediction or point cloud segmentation have inherent equivariances, such as rotation or permutation equivariance. In such tasks, even perturbations with large norm do not necessarily change an input's se… ▽ More

    Submitted 15 January, 2024; v1 submitted 5 December, 2023; originally announced December 2023.

    Comments: Accepted at NeurIPS 2023

  2. arXiv:2310.16221  [pdf, other

    cs.LG cs.AI cs.CV stat.ML

    Hierarchical Randomized Smoothing

    Authors: Yan Scholten, Jan Schuchardt, Aleksandar Bojchevski, Stephan Günnemann

    Abstract: Real-world data is complex and often consists of objects that can be decomposed into multiple entities (e.g. images into pixels, graphs into interconnected nodes). Randomized smoothing is a powerful framework for making models provably robust against small changes to their inputs - by guaranteeing robustness of the majority vote when randomly adding noise before classification. Yet, certifying rob… ▽ More

    Submitted 15 January, 2024; v1 submitted 24 October, 2023; originally announced October 2023.

  3. arXiv:2310.04285  [pdf, other

    cs.CV cs.AI cs.LG stat.ML

    Assessing Robustness via Score-Based Adversarial Image Generation

    Authors: Marcel Kollovieh, Lukas Gosch, Yan Scholten, Marten Lienen, Stephan Günnemann

    Abstract: Most adversarial attacks and defenses focus on perturbations within small $\ell_p$-norm constraints. However, $\ell_p$ threat models cannot capture all relevant semantic-preserving perturbations, and hence, the scope of robustness evaluations is limited. In this work, we introduce Score-Based Adversarial Generation (ScoreAG), a novel framework that leverages the advancements in score-based generat… ▽ More

    Submitted 6 October, 2023; originally announced October 2023.

  4. arXiv:2308.08173  [pdf, other

    cs.LG

    Expressivity of Graph Neural Networks Through the Lens of Adversarial Robustness

    Authors: Francesco Campi, Lukas Gosch, Tom Wollschläger, Yan Scholten, Stephan Günnemann

    Abstract: We perform the first adversarial robustness study into Graph Neural Networks (GNNs) that are provably more powerful than traditional Message Passing Neural Networks (MPNNs). In particular, we use adversarial robustness as a tool to uncover a significant gap between their theoretically possible and empirically achieved expressive power. To do so, we focus on the ability of GNNs to count specific su… ▽ More

    Submitted 3 July, 2024; v1 submitted 16 August, 2023; originally announced August 2023.

    Comments: Published in ${2}^{nd}$ AdvML Frontiers workshop at ${40}^{th}$ International Conference on Machine Learning (ICML)

    ACM Class: I.2.6

  5. arXiv:2301.02039  [pdf, other

    cs.LG

    Randomized Message-Interception Smoothing: Gray-box Certificates for Graph Neural Networks

    Authors: Yan Scholten, Jan Schuchardt, Simon Geisler, Aleksandar Bojchevski, Stephan Günnemann

    Abstract: Randomized smoothing is one of the most promising frameworks for certifying the adversarial robustness of machine learning models, including Graph Neural Networks (GNNs). Yet, existing randomized smoothing certificates for GNNs are overly pessimistic since they treat the model as a black box, ignoring the underlying architecture. To remedy this, we propose novel gray-box certificates that exploit… ▽ More

    Submitted 5 January, 2023; originally announced January 2023.