(Provable) Adversarial Robustness for Group Equivariant Tasks: Graphs, Point Clouds, Molecules, and More
Jan Schuchardt, Yan Scholten, Stephan Günnemann
Abstract
A machine learning model is traditionally considered robust if its prediction remains (almost) constant under input perturbations with small norm. However, real-world tasks like molecular property prediction or point cloud segmentation have inherent equivariances, such as rotation or permutation equivariance. In such tasks, even perturbations with large norm do not necessarily change an input's semantic content. Furthermore, there are perturbations for which a model's prediction explicitly needs to change. For the first time, we propose a sound notion of adversarial robustness that accounts for task equivariance. We then demonstrate that provable robustness can be achieved by (1) choosing a model that matches the task's equivariances (2) certifying traditional adversarial robustness. Certification methods are, however, unavailable for many models, such as those with continuous equivariances. We close this gap by developing the framework of equivariance-preserving randomized smoothing, which enables architecture-agnostic certification. We additionally derive the first architecture-specific graph edit distance certificates, i.e. sound robustness guarantees for isomorphism equivariant tasks like node classification. Overall, a sound notion of robustness is an important prerequisite for future work at the intersection of robust and geometric machine learning. decreases robustness to ℓ p perturbations and vice-versa [21] [22] [23] [24] [25] . Schuchardt and Günnemann [26] used knowledge about the invariances of point cloud classifiers to prove that they are constant within larger regions than could be shown using previous approaches. Group invariant distances. Recently, stability results for graph classifiers under isomorphism invariant optimal transport distances have been derived [27] [28] [29] . For point cloud classifiers, using the permutation invariant Chamfer or Hausdorff distance to craft attacks has been proposed [30, 31] . These works only focus on invariance and specific domains and do not consider that distances should be task-dependent: A rotation invariant distance for images may be desirable when segmenting cell nuclei, but not when classifying hand-written digits, since it would fail to distinguish 6 and 9. String edit distance. In concurrent work, Huang et al. [32] use randomized smoothing to prove robustness of classifiers w.r.t. string edit distance, i.e., the number of substitutions that are needed to convert one string from alphabet Σ ∪ ⊥ into another, up to insertion of alignment tokens ⊥. Their work further emphasizes the need for invariant distance functions in domains with symmetries, and the usefulness of randomized smoothing for proving robustness w.r.t. such distances. Robustness of models with equivariances. Aside from work that studies invariance and adversarial robustness jointly, there is a rich literature investigating the robustness of models that happen to have equivariances. This includes convolutions [5] [6] [7] 33] , transformers [34] [35] [36] [37] , point cloud models [30, 31, [38] [39] [40] [41] [42] [43] [44] [45] [46] and graph neural networks [8] [9] [10] [11] [12] [13] [14] [15] [16] [17] [47] [48] [49] [50] [51] [52] [53] [54] [55] . The models are however treated as a series of matrix multiplications and nonlinearities, without accounting for their equivariances or the equivariances of the tasks they are used for. Nevertheless, many methods can actually be reused for proving (non-)robustness under our proposed notion of adversarial robustness (see Section 5). Transformation-specific robustness. A subfield of robust machine learning focuses on robustness to unnoticeable parametric transformations (e.g. small rotations) [42, 46, [56] [57] [58] [59] [60] [61] [62] [63] [64] [65] . These works implicitly assume that large transformations lead to easily identifiable out-of-distribution samples. This is not the case with equivariant tasks: For instance, a molecule rotated by 180 • is still the same geometric object. Furthermore, they do not consider unstructured perturbations. Nevertheless, transformation-specific robustness can be framed as a special case of our proposed notion (see Appendix J). Semantics-aware robustness. Our work is closely related to different proposals to include ground truth labels in the definition of adversarial robustness [22, 52, [66] [67] [68] [69] [70] [71] . A problem is that the ground truth is usually unknown, which limits experimental evaluation to simple data generating distributions [52, 70] or using human study participants [22, 67, 71] . Geisler et al. [72] overcome this problem in the context of neural combinatorial optimization by using adversarial perturbations that are known to change the ground truth of a decision problem. Group equivariant tasks admit a similar approach, since we know how the ground truth changes for specific input transformations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 45d54311-26f0-4b3f-8e2c-9e07882bb106Cited by top-tier papers4
- RS-Del: Edit Distance Robustness Certificates for Sequence Classifiers via Randomized DeletionZhuoqun Huang, Neil G. Marchant, Keane Lucas, Lujo Bauer et al.NeurIPS 2023 · 24 citations
- Hierarchical Randomized SmoothingYan Scholten, Jan Schuchardt, Aleksandar Bojchevski, Stephan GünnemannNeurIPS 2023 · 14 citations
- Unified Mechanism-Specific Amplification by Subsampling and Group Privacy AmplificationJan Schuchardt, Mihail Stoian, Arthur Kosmala, Stephan GünnemannNeurIPS 2024 · 8 citations
- AdaptDel: Adaptable Deletion Rate Randomized Smoothing for Certified RobustnessZhuoqun Huang, Neil G. Marchant, Olga Ohrimenko, Benjamin I. P. RubinsteinNeurIPS 2025
Builds on54
- SE(3)-Transformers: 3D Roto-Translation Equivariant Attention NetworksFabian Fuchs, Daniel E. Worrall, Volker Fischer, Max WellingNeurIPS 2020 · 1,025 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- On the Robustness of Vision Transformers to Adversarial ExamplesKaleel Mahmood, Rigel Mahmood, Marten van DijkICCV 2021 · 261 citations
- Spherical Message Passing for 3D Molecular GraphsYi Liu, Limei Wang, Meng Liu, Yuchao Lin et al.ICLR 2022 · 256 citations
- Randomized Smoothing of All Shapes and SizesGreg Yang, Tony Duan, J. Edward Hu, Hadi Salman et al.ICML 2020 · 237 citations
Related papers
- Certified Defense to Image Transformations via Randomized SmoothingMarc Fischer, Maximilian Baader, Martin T. VechevNeurIPS 2020 · 78 citations
- Invariance-Aware Randomized Smoothing CertificatesJan Schuchardt, Stephan GünnemannNeurIPS 2022 · 8 citations
- Center Smoothing: Certified Robustness for Networks with Structured OutputsAounon Kumar, Tom GoldsteinNeurIPS 2021 · 23 citations
- A Framework for robustness Certification of Smoothed Classifiers using F-DivergencesKrishnamurthy (Dj) Dvijotham, Jamie Hayes, Borja Balle, J. Zico Kolter et al.ICLR 2020 · 74 citations
- PointGuard: Provably Robust 3D Point Cloud ClassificationHongbin Liu, Jinyuan Jia, Neil Zhenqiang GongCVPR 2021
