Skip to main content

Showing 1–5 of 5 results for author: Gosch, L

Searching in archive cs. Search in all archives.
.
  1. arXiv:2310.04285  [pdf, other

    cs.CV cs.AI cs.LG stat.ML

    Assessing Robustness via Score-Based Adversarial Image Generation

    Authors: Marcel Kollovieh, Lukas Gosch, Yan Scholten, Marten Lienen, Stephan Günnemann

    Abstract: Most adversarial attacks and defenses focus on perturbations within small $\ell_p$-norm constraints. However, $\ell_p$ threat models cannot capture all relevant semantic-preserving perturbations, and hence, the scope of robustness evaluations is limited. In this work, we introduce Score-Based Adversarial Generation (ScoreAG), a novel framework that leverages the advancements in score-based generat… ▽ More

    Submitted 6 October, 2023; originally announced October 2023.

  2. arXiv:2308.08173  [pdf, other

    cs.LG

    Expressivity of Graph Neural Networks Through the Lens of Adversarial Robustness

    Authors: Francesco Campi, Lukas Gosch, Tom Wollschläger, Yan Scholten, Stephan Günnemann

    Abstract: We perform the first adversarial robustness study into Graph Neural Networks (GNNs) that are provably more powerful than traditional Message Passing Neural Networks (MPNNs). In particular, we use adversarial robustness as a tool to uncover a significant gap between their theoretically possible and empirically achieved expressive power. To do so, we focus on the ability of GNNs to count specific su… ▽ More

    Submitted 3 July, 2024; v1 submitted 16 August, 2023; originally announced August 2023.

    Comments: Published in ${2}^{nd}$ AdvML Frontiers workshop at ${40}^{th}$ International Conference on Machine Learning (ICML)

    ACM Class: I.2.6

  3. arXiv:2306.15427  [pdf, other

    cs.LG

    Adversarial Training for Graph Neural Networks: Pitfalls, Solutions, and New Directions

    Authors: Lukas Gosch, Simon Geisler, Daniel Sturm, Bertrand Charpentier, Daniel Zügner, Stephan Günnemann

    Abstract: Despite its success in the image domain, adversarial training did not (yet) stand out as an effective defense for Graph Neural Networks (GNNs) against graph structure perturbations. In the pursuit of fixing adversarial training (1) we show and overcome fundamental theoretical as well as practical limitations of the adopted graph learning setting in prior work; (2) we reveal that more flexible GNNs… ▽ More

    Submitted 2 December, 2023; v1 submitted 27 June, 2023; originally announced June 2023.

    Comments: Published as a conference paper at NeurIPS 2023

  4. arXiv:2305.00851  [pdf, other

    cs.LG

    Revisiting Robustness in Graph Machine Learning

    Authors: Lukas Gosch, Daniel Sturm, Simon Geisler, Stephan Günnemann

    Abstract: Many works show that node-level predictions of Graph Neural Networks (GNNs) are unrobust to small, often termed adversarial, changes to the graph structure. However, because manual inspection of a graph is difficult, it is unclear if the studied perturbations always preserve a core assumption of adversarial examples: that of unchanged semantic content. To address this problem, we introduce a more… ▽ More

    Submitted 2 May, 2023; v1 submitted 1 May, 2023; originally announced May 2023.

    Comments: Published as a conference paper at ICLR 2023. Preliminary version accepted as an oral at the NeurIPS 2022 TSRML workshop and at the NeurIPS 2022 ML safety workshop

  5. arXiv:2301.00738  [pdf, other

    cs.LG cs.CR

    Training Differentially Private Graph Neural Networks with Random Walk Sampling

    Authors: Morgane Ayle, Jan Schuchardt, Lukas Gosch, Daniel Zügner, Stephan Günnemann

    Abstract: Deep learning models are known to put the privacy of their training data at risk, which poses challenges for their safe and ethical release to the public. Differentially private stochastic gradient descent is the de facto standard for training neural networks without leaking sensitive information about the training data. However, applying it to models for graph-structured data poses a novel challe… ▽ More

    Submitted 2 January, 2023; originally announced January 2023.

    Comments: Accepted at the Trustworthy and Socially Responsible Machine Learning Workshop of NeurIPS 2022