[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-117103-en":3,"doc-seo-117103-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},117103,4398048949847,"Eliana","https://ap-avatar.wpscdn.com/avatar/400002536579ef2da7f?_k=1778318612642679267",8,"Research & Report","Robustness analysis of graph-based machine learning","Graph-based machine learning analyzes data modeled by pairwise relationships between entities, covering domains such as social networks, road networks, protein-protein interactions, and molecules. While many works design new models, limited attention is given to theoretical properties of existing methods. This thesis studies robustness of spectral graph filters and graph neural networks, emphasizing robustness to changes in graph topology. It establishes stability bounds, validates them experimentally, introduces query-efficient black-box adversarial attacks, and proposes refined robustness certificates for graph classifiers.","Robustness analysis of graph-based machine  \nlearning  \nHenry Kenlay Worcester College University of Oxford  \nA thesis submitted for the degree of Doctor of Philosophy  \n7th October, 2022  \nAbstract  \nGraph-based machine learning is an emerging approach to analysing data that is or can be well-modelled by pairwise relationships between entities. This includes examples such as social networks, road networks, protein-protein interaction networks and molecules. Despite the plethora of research dedicated to designing novel machine learning models, less attention has been paid to the theoretical properties of our existing tools. In this thesis, we focus on the robustness properties of graph-based machine learning models, in particular spectral graph filters and graph neural networks. Robustness is an essential property for dealing with noisy data, protecting a system against security vulnerabilities and, in some cases, necessary for transferability, amongst other things. We focus specifically on the challenging and combinatorial problem of robustness with respect to the topology of the underlying graph. The first part of this thesis proposes stability bounds to help understand to which topological changes graph-based models are robust. Beyond theoretical results, we conduct experiments to verify the intuition this theory provides. In the second part, we propose a flexible and query-efficient method to perform black-box adversarial attacks on graph classifiers. Adversarial attacks can be considered a search for model instability and provide an upper bound between an input and the decision boundary. In the third and final part of the thesis, we propose a novel robustness certificate for graph classifiers. Using a technique that can certify individual parts of the graph at varying levels of perturbation, we provide a refined understanding of the perturbations to which a given model is robust. We believe the findings in this thesis provide novel insight and motivate further research into both understanding stability and instability of graph-based machine learning models.  \nDedication  \nTo Grandma, who [always wanted a Dr. in](always wanted a Dr. in) the family.  \nDeclaration  \nI declare that this thesis is entirely my own work, and except where otherwise stated, describes my own research.  \nAcknowledgements  \nFirst and foremost, I would like to express my deepest gratitude to my supervisor, Xiaowen Dong. Your unwavering support, guidance, teachings, advice and encouragement have been instrumental in my journey. I feel privileged to have been among your first cohort of DPhil students. Whenever I visited your office feeling uncertain about my research capabilities, you consistently uplifted me and reinforced my confidence, convincing me that I could overcome any challenge. Your insights and expertise have been invaluable. I could not have completed this journey without you. Furthermore, I would like to thank Stephen Roberts, my co-supervisor, whose insightful discussions and encouragement, particularly in my first year of research, helped shape the direction of my work and inspired me.  \nThank you to all my collaborators and colleagues who played an essential part in the research that formed this thesis: Xiaowen Dong, my primary collaborator and source of inspiration; Dorina Thanou, whose expertise and guidance were invaluable; Pierre Osselin, Xingchen Wan, Robin Ru, Arno Blaas, and Michael Osborne, Deborah Sulem, and Mihai Cucuringu who provided critical insights and feedback.  \nThank you to the EPSRC and the AIMS CDT for the invaluable opportunity and funding of my studies. The EPSRC’s financial support allowed me to focus on my research without the burden of financial constraints. At the same time, the AIMS CDT’s interdisciplinary training program broadened my knowledge and skills, enhancing the quality of my research. In particular, I want to express my gratitude to Wendy Poole, the AIMS program administrator, for her unwavering supp","cbCaii1W0gRs88WS","https://ap.wps.com/l/cbCaii1W0gRs88WS","pdf",9425329,1,150,"English","en",105,"# Abstract\n## Dedication\n## Declaration\n## Acknowledgements","[{\"question\":\"What robustness aspects does the thesis study in graph-based machine learning?\",\"answer\":\"It focuses on robustness properties of spectral graph filters and graph neural networks, especially robustness with respect to the topology of the underlying graph.\"},{\"question\":\"How does the thesis connect theory with practical validation?\",\"answer\":\"The first part proposes stability bounds for topological changes, and experiments are conducted to verify the intuition provided by the theory.\"},{\"question\":\"What methods are proposed for adversarial robustness and certification?\",\"answer\":\"The second part introduces a flexible, query-efficient black-box method for adversarial attacks on graph classifiers, and the third part proposes a novel robustness certificate that can certify parts of a graph under varying perturbation levels.\"}]","Robustness analysis of graph-based machine learning | PDF",1785673763,378,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"robustness-analysis-of-graph-based-machine-learning","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/robustness-analysis-of-graph-based-machine-learning/117103/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-06","2026-08-02",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What robustness aspects does the thesis study in graph-based machine learning?","Question",{"text":76,"@type":77},"It focuses on robustness properties of spectral graph filters and graph neural networks, especially robustness with respect to the topology of the underlying graph.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the thesis connect theory with practical validation?",{"text":81,"@type":77},"The first part proposes stability bounds for topological changes, and experiments are conducted to verify the intuition provided by the theory.",{"name":83,"@type":74,"acceptedAnswer":84},"What methods are proposed for adversarial robustness and certification?",{"text":85,"@type":77},"The second part introduces a flexible, query-efficient black-box method for adversarial attacks on graph classifiers, and the third part proposes a novel robustness certificate that can certify parts of a graph under varying perturbation levels.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":46,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":46,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]