Publication Date

Spring 2026

Degree Type

Master's Project

Degree Name

Master of Science in Computer Science (MSCS)

Department

Computer Science

First Advisor

Saptarshi Sengupta

Second Advisor

Katerina Potika

Third Advisor

Mohammad Masum

Keywords

Kolmogorov-Arnold Networks, Inference-Time Attacks, Adversarial Robustness, Interpretable Machine Learning, B-spline, Regression Models

Abstract

Kolmogorov-Arnold Networks (KANs) have been proposed as an alternative to Multi-Layer Perceptrons (MLPs). KANs replace scalar weights on edges with learnable univariate B-spline functions. Their design makes them inherently interpretable. KAN’s internal feature routing structure is directly readable from the spline coefficient. This property improves model interpretability. This work aims to study inference-time attacks on KAN architectures for regression tasks, comparing attack potency across two architectures (MLP and KAN), four datasets, three probing methods, and six hyperparameter configurations. The theoretical framework derives from the mathematical structure of the KAN training objective, which states that entropy regularization drives near-sparse feature routing as a consequence of the loss function itself. This sparse routing eliminates the compensating redundancy that limits attack damage in MLPs, where all-to-all connectivity ensures that poisoning one node leaves others carrying a backup signal. KANs consistently have higher MSE values against their MLP counterparts across all datasets and combinations tested. A separation score metric, measuring the degree of exclusive feature routing, does not show a rank correlation with attack potency across random seeds. Furthermore, an ablation study across six spline configurations tests the vulnerability of the KANs across different configurations.

Available for download on Saturday, May 22, 2027

Share

COinS