<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>systematic fooling of 3D AI models &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/systematic-fooling-of-3d-ai-models/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Thu, 01 Oct 2026 07:57:52 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>systematic fooling of 3D AI models &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>Twisting Molecules Just Enough: Physically Valid Adversarial Attacks Expose Weak Spots in 3D AI Chemistry Models</title>
		<link>https://scienmag.com/twisting-molecules-just-enough-physically-valid-adversarial-attacks-expose-weak-spots-in-3d-ai-chemistry-models/</link>
		
		<dc:creator><![CDATA[Bethany Barker]]></dc:creator>
		<pubDate>Thu, 01 Oct 2026 07:57:52 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[3D molecular prediction]]></category>
		<category><![CDATA[3D molecular property prediction]]></category>
		<category><![CDATA[3D molecular structure validation]]></category>
		<category><![CDATA[adversarial attacks in chemistry]]></category>
		<category><![CDATA[adversarial examples]]></category>
		<category><![CDATA[adversarial examples in molecular modeling]]></category>
		<category><![CDATA[AI model robustness in chemistry]]></category>
		<category><![CDATA[chemically realistic adversarial examples]]></category>
		<category><![CDATA[computational chemistry]]></category>
		<category><![CDATA[drug discovery]]></category>
		<category><![CDATA[equivariant neural networks]]></category>
		<category><![CDATA[force fields]]></category>
		<category><![CDATA[geometric neural networks for molecules]]></category>
		<category><![CDATA[Graph Neural Networks]]></category>
		<category><![CDATA[Machine learning]]></category>
		<category><![CDATA[molecular conformers]]></category>
		<category><![CDATA[molecular geometry perturbation]]></category>
		<category><![CDATA[physically plausible molecule distortions]]></category>
		<category><![CDATA[QM9]]></category>
		<category><![CDATA[robustness benchmark]]></category>
		<category><![CDATA[robustness of machine learning in drug discovery]]></category>
		<category><![CDATA[systematic fooling of 3D AI models]]></category>
		<category><![CDATA[torsion perturbations]]></category>
		<category><![CDATA[vulnerability of AI chemistry models]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=221206</guid>

					<description><![CDATA[Researchers have developed an adversarial attack framework that rotates molecular torsion angles within strict physical validity constraints, revealing consistent vulnerabilities in leading 3D molecular prediction models.]]></description>
										<content:encoded><![CDATA[<p>Machine learning models that predict the properties of molecules in three dimensions have become indispensable tools in modern chemistry and drug discovery. These networks take the coordinates of atoms, the bonds between them, and increasingly sophisticated geometric architectures, and from that information they estimate everything from quantum-chemical energies to biological activity. But a new study published in the International Journal of Machine Learning and Cybernetics raises an uncomfortable question: how well do these models hold up when the molecules they are shown are subtly, yet legitimately, distorted? Junhyeong Lee of the Ground Operations Command of the Republic of Korea Army and Hyun Kwon of the Korea Military Academy present a framework for generating adversarial examples for 3D molecular predictors that remain physically plausible, and their results suggest that even chemically realistic perturbations can systematically fool state-of-the-art architectures.</p>
<p>Adversarial examples are a well-known phenomenon in computer vision, where imperceptible changes to an image can cause a neural network to misclassify it with high confidence. In molecular machine learning, the analogue would be a molecule whose geometry has been nudged in ways that do not change its chemical identity but that cause a property predictor to produce wildly wrong answers. Previous work on adversarial attacks in this domain has typically taken one of two routes: applying unconstrained perturbations to atomic coordinates, or modifying the discrete molecular graph itself by adding, deleting, or rewiring bonds. Both approaches have a serious flaw. The resulting structures are often chemically nonsensical, with atoms overlapping, bonds stretched to impossible lengths, or molecular frameworks that could never exist. If an attack produces an implausible molecule, the question arises whether the model&#8217;s failure is meaningful at all, since such a structure would never appear in real applications.</p>
<p>Lee and Kwon&#8217;s contribution is to constrain the attack to a space that chemists trust: torsion angles. Molecules are not rigid objects; they have rotatable bonds, and rotating around a single bond changes the molecule&#8217;s conformation without altering its atom types or its bond connectivity. This is precisely the degree of freedom that distinguishes, for example, an extended from a folded conformer of the same molecule. The researchers use RDKit, the widely adopted open-source cheminformatics toolkit, to identify rotatable bonds, and their attacks operate exclusively by rotating these bonds. The molecular graph remains untouched. Every adversarial example they generate is, by construction, the same molecule, merely presented in a different geometric arrangement that a real molecule could plausibly adopt.</p>
<p>Plausibility, however, is not guaranteed by torsion-only perturbation alone. Rotating a bond can swing one part of a molecule into another, creating steric clashes where atoms occupy the same space, or producing conformations so strained that they would never be populated at any reasonable temperature. To prevent this, the authors enforce hard validity constraints drawn from classical computational chemistry. The first is a van der Waals steric check, which verifies that no two non-bonded atoms come closer than physically permitted given their van der Waals radii, the standard measure of atomic size used since the mid-twentieth century. The second is an energy budget evaluated with established molecular mechanics force fields, MMFF94 and UFF. These force fields assign an energy to any 3D structure based on bond lengths, angles, torsions, and non-bonded interactions, and the attack rejects any candidate conformer whose energy exceeds a defined threshold. The result is that every adversarial example remains thermodynamically accessible, meaning it corresponds to a geometry a real molecule could realistically sample.</p>
<p>Within this constrained framework, the researchers develop two white-box attacks, so called because the attacker has full access to the model&#8217;s internals and gradients. The first, WB-PGD, is a momentum-based projected gradient descent adapted to torsion space. Gradient descent is the workhorse of neural network training, but here it is turned against the model: instead of adjusting parameters to reduce error, the attack adjusts torsion angles to maximize the model&#8217;s prediction error, while a projection step with backtracking pulls any proposed update back into the physically valid region whenever it violates the steric or energetic constraints. The momentum term accumulates gradient information across steps, a technique known to stabilize and strengthen adversarial optimization. The second method, WB-Manifold, serves as a validity-filtered random search baseline: it samples torsion perturbations at random, keeps only those that pass the physical validity filters, and retains whichever candidate most damages the model&#8217;s prediction. Comparing a gradient-guided method against a search-based one reveals how much of the attack&#8217;s power comes from exploiting model gradients rather than simply exploring the conformational space.</p>
<p>The evaluation covers four prominent architectures for 3D molecular property prediction: EGNN, the E(n)-equivariant graph neural network; InvMPNN, an invariant message-passing network; SchNet, a continuous-filter convolutional network that models quantum interactions; and PaiNN, a polarizable attention network that tracks both scalar and vectorial features. These models represent the leading families of geometric deep learning applied to molecules, differing in how they handle rotational symmetry and directional information. The benchmark is derived from QM9, a standard dataset of quantum-chemical properties for small organic molecules, and the authors take particular care to use leak-free data splits, ensuring that the same molecule does not appear in both training and test sets in different conformations, a subtle form of data leakage that can inflate reported performance.</p>
<p>The findings are striking in their consistency. Across all four architectures, prediction error grows steadily as the torsion perturbation budget increases. At a modest budget of 10 degrees of torsional rotation, the mean damage to predictions is already measurable, at roughly 0.01 to 0.02. When the budget is relaxed to 60 degrees, still well within the range of conformational flexibility that real molecules exhibit, the mean damage climbs to 0.04 to 0.05. Meanwhile, the attack success rate, the fraction of molecules for which the attack produces a prediction error above a defined threshold, rises from nearly zero at small budgets to between 15 and 17 percent at the largest budgets tested. Notably, this degradation occurs even though every adversarial conformer passed the steric and energetic validity checks, meaning the models are not simply being shown impossible molecules.</p>
<p>The central lesson the authors draw is that physical constraints alone do not protect 3D molecular predictors from adversarial failure. One might have hoped that restricting attacks to chemically valid conformations would neutralize the threat, since valid conformers of the same molecule should, in principle, be handled correctly by a model that has truly learned the relationship between structure and property. Instead, the consistent error amplification across architectures suggests that these networks rely on geometric cues in ways that are fragile under realistic conformational change. This has practical implications for drug discovery and materials design pipelines, where molecular property predictions guide expensive experimental decisions. A model that is sensitive to which conformer it happens to be shown could produce unreliable rankings of candidate compounds, and adversarial robustness testing offers a way to probe that sensitivity before deployment.</p>
<p>Beyond diagnosing vulnerability, the study establishes torsion-space attacks as a principled robustness benchmark for the field. Because the attacks preserve chemical identity and enforce thermodynamic accessibility, they isolate a specific and meaningful failure mode: sensitivity to conformational geometry within the physically realizable manifold. The authors suggest that future work on 3D molecular machine learning should incorporate such physically valid adversarial evaluation alongside standard accuracy metrics, and that defenses, such as training on diverse conformations or enforcing invariance across the conformational ensemble, can be measured against these attacks. The work was supported by a National Research Foundation of Korea grant funded by the Korean government, and the authors report no competing interests. As machine learning continues to permeate computational chemistry, studies like this one serve as a reminder that the reliability of a predictor cannot be judged by its accuracy on clean data alone; it must also withstand the geometric variability that real molecules present every day.</p>
<p><strong>Subject of Research:</strong> Physically valid adversarial attacks on 3D molecular property prediction models using torsion-space perturbations</p>
<p><strong>Article Title:</strong> Physically valid adversarial examples for 3D molecular prediction</p>
<p><strong>Article References:</strong> Physically valid adversarial examples for 3D molecular prediction. (n.d.). <a href="https://doi.org/10.1007/s13042-026-03321-z" rel="noopener noreferrer">https://doi.org/10.1007/s13042-026-03321-z</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s13042-026-03321-z" rel="noopener noreferrer">10.1007/s13042-026-03321-z</a></p>
<p><strong>Keywords:</strong> adversarial examples, 3D molecular prediction, torsion perturbations, graph neural networks, equivariant neural networks, molecular conformers, force fields, QM9, robustness benchmark, machine learning, computational chemistry, drug discovery</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">221206</post-id>	</item>
	</channel>
</rss>
