Enhancing Node-Level Adversarial Defenses by Lipschitz Regularization of Graph Neural Networks
Yaning Jia, Dongmian Zou, Hongfei Wang, Hai Jin
Abstract
Graph neural networks (GNNs) have shown considerable promise for graph-structured data. However, they are also known to be unstable and vulnerable to perturbations and attacks. Recently, the Lipschitz constant has been adopted as a control on the stability of Euclidean neural networks, but calculating the exact constant is also known to be difficult even for very shallow networks. In this paper, we extend the Lipschitz analysis to graphs by providing a systematic scheme for estimating upper bounds of the Lipschitz constants of GNNs. We also derive concrete bounds for widely used GNN architectures including GCN, GraphSAGE and GAT. We then use these Lipschitz bounds for regularized GNN training for improved stability. Our numerical results on Lipschitz regularization of GNNs not only illustrate enhanced test accuracy under random noise, but also show consistent improvement for state-of-the-art defense methods against adversarial attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 16518b15-e898-4278-bbfb-9c50873773deCited by top-tier papers8
- Aligning Relational Learning with Lipschitz FairnessYaning Jia, Chunhui Zhang, Soroush VosoughiICLR 2024 · 11 citations
- Mitigating Emergent Robustness Degradation while Scaling Graph LearningXiangchi Yuan, Chunhui Zhang, Yijun Tian, Yanfang Ye et al.ICLR 2024 · 10 citations
- When Witnesses Defend: A Witness Graph Topological Layer for Adversarial Graph LearningNaheed Anjum Arafat, Debabrota Basu, Yulia Gel, Yuzhou ChenAAAI 2025 · 6 citations
- Stable Fair Graph Representation Learning with Lipschitz ConstraintQiang Chen, Zhongze Wu, Xiu Su, Xi Lin et al.ICML 2025
- MemFreezing: A Novel Adversarial Attack on Temporal Graph Neural Networks under Limited Future KnowledgeYue Dai, Liang Liu, Xulong Tang, Youtao Zhang et al.ICML 2025
Related papers
- On Lipschitz Regularization of Convolutional Layers using Toeplitz Matrix TheoryAlexandre Araujo, Benjamin Négrevergne, Yann Chevaleyre, Jamal AtifAAAI 2021 · 31 citations
- Adversarial Training for Graph Neural Networks: Pitfalls, Solutions, and New DirectionsLukas Gosch, Simon Geisler, Daniel Sturm, Bertrand Charpentier et al.NeurIPS 2023 · 19 citations
- Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary PerturbationsJiate Li, Meng Pang, Yun Dong, Binghui WangCVPR 2025
- AGNNCert: Defending Graph Neural Networks against Arbitrary Perturbations with Deterministic CertificationJiate Li, Binghui WangUSENIX Security 2025
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang et al.KDD 2020 · 604 citations
