{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/randomized-message-interception-smoothing","title":"Randomized Message-Interception Smoothing: Gray-box Certificates for Graph Neural Networks","arxiv_id":"2301.02039","date":"2023-01-05","proceeding":null,"authors":["Yan Scholten","Jan Schuchardt","Simon Geisler","Aleksandar Bojchevski","Stephan Günnemann"],"abstract":"Randomized smoothing is one of the most promising frameworks for certifying the adversarial robustness of machine learning models, including Graph Neural Networks (GNNs). Yet, existing randomized smoothing certificates for GNNs are overly pessimistic since they treat the model as a black box, ignoring the underlying architecture. To remedy this, we propose novel gray-box certificates that exploit the message-passing principle of GNNs: We randomly intercept messages and carefully analyze the probability that messages from adversarially controlled nodes reach their target nodes. Compared to existing certificates, we certify robustness to much stronger adversaries that control entire nodes in the graph and can arbitrarily manipulate node features. Our certificates provide stronger guarantees for attacks at larger distances, as messages from farther-away nodes are more likely to get intercepted. We demonstrate the effectiveness of our method on various models and datasets. Since our gray-box certificates consider the underlying graph structure, we can significantly improve certifiable robustness by applying graph sparsification.","url_abs":"https://arxiv.org/abs/2301.02039v2","url_pdf":"https://arxiv.org/pdf/2301.02039v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"randomized-message-interception-smoothing","repo_url":"https://github.com/yascho/interception_smoothing","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-robustness","task_name":"Adversarial Robustness"}],"methods":[{"method_slug":"randomized-smoothing","method_name":"Randomized Smoothing"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2301.02039","atlas_url":"https://app.syntology.ai/?focus=2301.02039","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2301.02039"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/yascho/interception_smoothing","reach":null}],"summary":{"ran_fixture":1,"ran_honours":1,"ran_draft_wrong":1},"by_repo_kind":{"listed":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"2faf5c28fa14d6ea","entry":"compute_bounds","repo":"yascho/interception_smoothing","repo_kind":"listed","path":"interception_smoothing/cert.py","file_url":"https://github.com/yascho/interception_smoothing/blob/HEAD/interception_smoothing/cert.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"2faf5c28fa14d6ea"}},{"code_sha256_prefix":"bb3352d62f54167c","entry":"compute_delta_single_source","repo":"yascho/interception_smoothing","repo_kind":"listed","path":"interception_smoothing/cert.py","file_url":"https://github.com/yascho/interception_smoothing/blob/HEAD/interception_smoothing/cert.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"bb3352d62f54167c"}},{"code_sha256_prefix":"644cb644cd0d6d27","entry":"get_paths","repo":"yascho/interception_smoothing","repo_kind":"listed","path":"interception_smoothing/cert.py","file_url":"https://github.com/yascho/interception_smoothing/blob/HEAD/interception_smoothing/cert.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"644cb644cd0d6d27"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}