← Search

Lukas Gosch

4 accepted papers

2026

Certifying Graph Neural Networks Against Label and Structure Poisoning

ICML 2026poster

Robust machine learning for graph-structured data has made significant progress against test-time attacks, yet certified robustness to poisoning – where adversaries manipulate the training data – remains largely underexplored. For image data, state-of-the-art poisoning certificates rely on partition…

Cited by 0SourceScholar
2025

Exact Certification of (Graph) Neural Networks Against Label Poisoning

ICLR 2025spotlight

Machine learning models are highly vulnerable to label flipping, i.e., the adversarial modification (poisoning) of training labels to compromise performance. Thus, deriving robustness certificates is important to guarantee that test predictions remain unaffected and to understand worst-case robustne…

2023

Adversarial Training for Graph Neural Networks: Pitfalls, Solutions, and New Directions

NeurIPS 2023poster

Despite its success in the image domain, adversarial training did not (yet) stand out as an effective defense for Graph Neural Networks (GNNs) against graph structure perturbations. In the pursuit of fixing adversarial training (1) we show and overcome fundamental theoretical as well as practical l…

Cited by 34SourcePDFScholar