Reject-to-Protect: Dynamic Decision-Aware Adversarial Training for Selective Molecular Prediction
Abstract
Selective prediction pairs each model output with an accept–defer decision, but most pipelines attach rejection rules to predictors trained independently for accuracy. In molecular property prediction, where structurally similar compounds can have very different prediction harms, such post-hoc strategies still accept risky analogues or reject reliable ones. We introduce Reject-to-Protect (R2P), a decision-aware adversarial training framework that directly optimizes the composed prediction–acceptance policy. R2P builds a frozen, structure-only candidate graph of chemically plausible neighbors. This restricts optimization to the local neighborhoods where selective errors are most likely to occur, and the search stays finite and auditable. Within this graph, a discrete inner maximization searches for two complementary failure modes. Unsafe acceptance (UA) occurs when a harmful prediction is accepted despite its error, while over-rejection (OR) defers a reliable prediction to expert review. An outer minimization then uses these fixed endpoints to train a risk head, and optionally the predictor, under an explicit target-coverage constraint. The risk head is supervised by scaffold out-of-fold prediction harm, and retrieval, supervision, and thresholding are each confined to their own data splits to prevent leakage. On nine MoleculeNet benchmarks at 80% coverage, R2P achieves the lowest mean selective risk on five of six classification tasks and two of three regression tasks, with up to a 33.6% reduction relative to full acceptance.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.