Efficient Robustness Certificates for Discrete Data: Sparsity-Aware Randomized Smoothing for Graphs, Images and More

08/29/2020
by   Aleksandar Bojchevski, et al.
0

Existing techniques for certifying the robustness of models for discrete data either work only for a small class of models or are general at the expense of efficiency or tightness. Moreover, they do not account for sparsity in the input which, as our findings show, is often essential for obtaining non-trivial guarantees. We propose a model-agnostic certificate based on the randomized smoothing framework which subsumes earlier work and is tight, efficient, and sparsity-aware. Its computational complexity does not depend on the number of discrete categories or the dimension of the input (e.g. the graph size), making it highly scalable. We show the effectiveness of our approach on a wide variety of models, datasets, and tasks – specifically highlighting its use for Graph Neural Networks. So far, obtaining provable guarantees for GNNs has been difficult due to the discrete and non-i.i.d. nature of graph data. Our method can certify any GNN and handles perturbations to both the graph structure and the node attributes.

READ FULL TEXT
research
08/24/2020

Certified Robustness of Graph Neural Networks against Adversarial Structural Perturbation

Graph neural networks (GNNs) have recently gained much attention for nod...
research
01/05/2023

Randomized Message-Interception Smoothing: Gray-box Certificates for Graph Neural Networks

Randomized smoothing is one of the most promising frameworks for certify...
research
09/06/2021

Pointspectrum: Equivariance Meets Laplacian Filtering for Graph Representation Learning

Graph Representation Learning (GRL) has become essential for modern grap...
research
10/30/2022

When Do We Need GNN for Node Classification?

Graph Neural Networks (GNNs) extend basic Neural Networks (NNs) by addit...
research
12/14/2021

Robust Graph Neural Networks via Probabilistic Lipschitz Constraints

Graph neural networks (GNNs) have recently been demonstrated to perform ...
research
05/31/2023

Incremental Randomized Smoothing Certification

Randomized smoothing-based certification is an effective approach for ob...
research
10/28/2022

Localized Randomized Smoothing for Collective Robustness Certification

Models for image segmentation, node classification and many other tasks ...

Please sign up or login with your details

Forgot password? Click here to reset