← Search

Yan Scholten

8 accepted papers

2026

Certifying Graph Neural Networks Against Label and Structure Poisoning

ICML 2026poster

Robust machine learning for graph-structured data has made significant progress against test-time attacks, yet certified robustness to poisoning – where adversaries manipulate the training data – remains largely underexplored. For image data, state-of-the-art poisoning certificates rely on partition…

Cited by 0SourceScholar
2026

Model Collapse Is Not a Bug but a Feature in Machine Unlearning for LLMs

ICLR 2026poster

Current unlearning methods for LLMs optimize on the private information they seek to remove by incorporating it into their fine-tuning data. We argue this not only risks reinforcing exposure to sensitive data, it also fundamentally contradicts the principle of minimizing its use. As a remedy, we pro…

Cited by 0SourcecodeScholar
2026

Sampling-aware Adversarial Attacks Against Large Language Models

ICLR 2026poster

To guarantee safe and robust deployment of large language models (LLMs) at scale, it is critical to accurately assess their adversarial robustness. Existing adversarial attacks typically target harmful responses in single-point greedy generations, overlooking the inherently stochastic nature of LLMs…

Cited by 0SourceScholar
2025

A Probabilistic Perspective on Unlearning and Alignment for Large Language Models

ICLR 2025oral

Comprehensive evaluation of Large Language Models (LLMs) is an open research problem. Existing evaluations rely on deterministic point estimates generated via greedy decoding. However, we find that deterministic evaluations fail to capture the whole output distribution of a model, yielding inaccurat…

2025

Provably Reliable Conformal Prediction Sets in the Presence of Data Poisoning

ICLR 2025spotlight

Conformal prediction provides model-agnostic and distribution-free uncertainty quantification through prediction sets that are guaranteed to include the ground truth with any user-specified probability. Yet, conformal prediction is not reliable under poisoning attacks where adversaries manipulate bo…

Cited by 0SourcePDFScholar
2023

Provable Adversarial Robustness for Group Equivariant Tasks: Graphs, Point Clouds, Molecules, and More

NeurIPS 2023poster

A machine learning model is traditionally considered robust if its prediction remains (almost) constant under input perturbations with small norm. However, real-world tasks like molecular property prediction or point cloud segmentation have inherent equivariances, such as rotation or permutation equ…

Cited by 4SourcePDFScholar
2022

Randomized Message-Interception Smoothing: Gray-box Certificates for Graph Neural Networks

NeurIPS 2022accept

Randomized smoothing is one of the most promising frameworks for certifying the adversarial robustness of machine learning models, including Graph Neural Networks (GNNs). Yet, existing randomized smoothing certificates for GNNs are overly pessimistic since they treat the model as a black box, ignori…

Cited by 25SourcePDFScholar