[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118094-en":3,"doc-seo-118094-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118094,4398048950312,"Violet","https://ap-avatar.wpscdn.com/avatar/400002538284de19e3c?_k=1778320343897328908",8,"Research & Report","Towards Robust Machine Learning with Graph Neural Networks - Thesis","The thesis addresses robustness of neural networks against adversarial attacks in safety-critical applications such as healthcare and autonomous driving. Adversarial attacks introduce small, carefully chosen perturbations to natural images that remain imperceptible to humans, yet can cause high-accuracy models to misclassify many perturbed inputs. The work proposes multiple GNN-driven methods: more efficient adversarial example generation using a stand-alone GNN attack, learning from unsuccessful restarts via GNN-based attention to reduce search space, and graph-neural-network-assisted formal neural network verification through dual solutions of convex relaxations to obtain sound and complete robustness proofs.","Towards Robust Machine Learning with Graph Neural  \nNetworks  \nFlorian Jaeckle  \nWadham College  \nUniversity of Oxford  \nA thesis submitted for the degree of Doctor of Philosophy  \nTrinity 2022  \nAbstract  \nIn order to apply Neural Networks in safety-critical settings, such as healthcare or autonomous driving, we need to be able to analyse their robustness against adversarial attacks. These attacks perturb natural images by adding small, carefully chosen perturbations to them that are imperceptible to the human eye. Trained neural networks with high training and validation accuracy often misclassify a large number of these perturbed images. In this thesis we propose several new methods aimed at analysing the robustness of trained neural networks to adversarial attacks.  \nIn the first part, we improve upon existing methods to generate adversarial examples more efficiently. We note that past work in this field has relied on optimization methods that ignore the inherent structure of the problem and data, or generative methods that rely purely on learning and often fail to generate adversarial examples where they are hard to find. To alleviate these deficiencies, we propose a novel stand-alone attack based on a GNN that takes advantage of the strengths of both approaches. Our GNN computes descent directions to guide an iterative procedure towards adversarial examples.  \nOur next contribution is inspired by the observation that many state-of-theart adversarial attacks require many random restarts to generate adversarial examples. Each time we perform a restart we ignore all previous unsuccessful runs. In order to alleviate this deficiency, we propose a method that learns from its mistakes. Specifically, our method uses GNNs as an attention, to greatly reduce the search space for future iterations of the attacks.  \nFor our final contribution, we note that adversarial attacks may fail, even where adversarial examples exist. We thus focus on formal complete neural network verification which returns a sound and complete proof of robustness. Recent years have witnessed the deployment of branch-and-bound (BaB) frameworks for formal verification in deep learning. The main computational bottleneck of BaB is the estimation of lower bounds. Past work in this field has relied on traditional optimization algorithms whose inefficiencies have limited their scope. To alleviate this deficiency, we propose a novel graph neural network (GNN) based approach. Our GNN aims to compute a dual solution of the convex relaxation, thereby providing a valid lower bound, which, if positive, proves robustness.  \nTowards Robust Machine Learning with Graph Neural Networks  \nFlorian Jaeckle  \nWadham College University of Oxford  \nSupervised by Prof M. Pawan Kumar  \nA thesis submitted for the degree of Doctor of Philosophy  \nTrinity 2022  \nii  \nAbstract  \nIn order to apply Neural Networks in safety-critical settings, such as healthcare or autonomous driving, we need to be able to analyse their robustness against adversarial attacks. These attacks perturb natural images by adding small, carefully chosen perturbations to them that are imperceptible to the human eye. Trained neural networks with high training and validation accuracy often misclassify a large number of these perturbed images. In this thesis we propose several new methods aimed at analysing the robustness of trained neural networks to adversarial attacks.  \nIn the first part, we improve upon existing methods to generate adversarial examples more efficiently. We note that past work in this field has relied on optimization methods that ignore the inherent structure of the problem and data, or generative methods that rely purely on learning and often fail to generate adversarial examples where they are hard to find. To alleviate these deficiencies, we propose a novel stand-alone attack based on a GNN that takes advantage of the strengths of both approaches. Our GNN computes descent directions to guide an i","cbCaic8dGMHjvJaX","https://ap.wps.com/l/cbCaic8dGMHjvJaX","pdf",5350679,1,173,"English","en",105,"# Abstract\n# Proposed Methods for Robustness Analysis\n## Efficient Adversarial Example Generation\n## Learning from Random Restarts\n## Sound and Complete Neural Network Verification\n# Acknowledgements","[{\"question\":\"Why is neural network robustness important in safety-critical settings mentioned in the thesis?\",\"answer\":\"The thesis targets applications like healthcare and autonomous driving, where models must remain reliable under adversarial attacks that can cause misclassification despite high accuracy.\"},{\"question\":\"What is the role of the proposed GNN stand-alone attack in generating adversarial examples?\",\"answer\":\"The GNN computes descent directions that guide an iterative procedure toward adversarial examples, aiming to generate them more efficiently than prior approaches.\"},{\"question\":\"How does the thesis improve adversarial attacks that require many random restarts?\",\"answer\":\"It proposes a method that learns from past failures by using GNNs as attention, reducing the search space for subsequent attack iterations.\"}]","Towards Robust Machine Learning with Graph Neural Networks - Thesis | PDF",1785681501,436,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"towards-robust-machine-learning-with-graph-neural-networks-thesis","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/towards-robust-machine-learning-with-graph-neural-networks-thesis/118094/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why is neural network robustness important in safety-critical settings mentioned in the thesis?","Question",{"text":75,"@type":76},"The thesis targets applications like healthcare and autonomous driving, where models must remain reliable under adversarial attacks that can cause misclassification despite high accuracy.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What is the role of the proposed GNN stand-alone attack in generating adversarial examples?",{"text":80,"@type":76},"The GNN computes descent directions that guide an iterative procedure toward adversarial examples, aiming to generate them more efficiently than prior approaches.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the thesis improve adversarial attacks that require many random restarts?",{"text":84,"@type":76},"It proposes a method that learns from past failures by using GNNs as attention, reducing the search space for subsequent attack iterations.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]