Mitigating Emergent Robustness Degradation while Scaling Graph Learning
Xiangchi Yuan, Chunhui Zhang, Yijun Tian, Yanfang Ye, Chuxu Zhang
Abstract
While graph neural networks have exhibited remarkable performance in various graph tasks, a significant concern is their vulnerability to adversarial attacks. Consequently, many defense methods have been proposed to alleviate the deleterious effects of adversarial attacks and learn robust graph representations. However, most of them are difficult to simultaneously avoid two major limitations: 1) an emergent and severe degradation in robustness when exposed to very intense attacks, and 2) heavy computation complexity hinders them from scaling to large graphs. In response to these challenges, we introduce an innovative graph defense method for unpredictable real-world scenarios by designing a graph robust learning framework that is resistant to robustness degradation and refraining from the unscalable designs with heavy computation: specifically, our method employs a denoising module, which eliminates edges that are associated with attacked nodes to reconstruct a cleaner graph; Then, it applies Mixture-of-Experts to select differentially private noises with varying magnitudes to counteract the hidden features attacked at different intensities toward robust predictions; Moreover, our overall design avoids the reliance on heavy adjacency matrix computations, such as SVD, thus facilitating its applicability even on large graphs. Comprehensive experiments have been conducted to demonstrate the anti-degraded robustness and scalability of our method, as compared to popular graph adversarial learning methods, under diverse attack intensities and various datasets of different sizes.
- Xiangchi is mentored by Chunhui; both contributed equally and are listed alphabetically by last name.
Published as a conference paper at ICLR 2024 GNNGuard (Zhang & Zitnik, 2020), which require dense adjacency matrix computations. This can result in substantial computational overhead, as shown in the experiment section, leading to out-of-memory problems when applied to larger datasets like Flick, Reddit, and AMiner, especially when using a 32 GB GPU. These challenges necessitate innovative solutions to enhance the robustness and scalability of GNNs against adversarial attacks. 0 100 200 300 400 500 600 700
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 17b81ec8-6721-4f3d-9e63-3600e58d628bCited by top-tier papers4
- Graph Defense Diffusion ModelXin He, Wenqi Fan, Yili Wang, Chengyi Liu et al.KDD 2026 · 3 citations
- Generalizing GNNs with Tokenized Mixture of ExpertsXiaoguang Guo, Zehong Wang, Jiazheng Li, Shawn Spitzel et al.KDD 2026 · 1 citation
- A Cognac Shot To Forget Bad Memories: Corrective Unlearning for Graph Neural NetworksVarshita Kolipaka, Akshit Sinha, Debangan Mishra, Sumit Kumar et al.ICML 2025
- Certified Signed Graph UnlearningJunpeng Zhao, Lin Li, Yu Yang, Kaixi Hu et al.KDD 2026
Builds on26
- Graph Contrastive Learning with AugmentationsYuning You, Tianlong Chen, Yongduo Sui, Ting Chen et al.NeurIPS 2020 · 3,042 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang et al.KDD 2020 · 604 citations
- Graph Random Neural Networks for Semi-Supervised Learning on GraphsWenzheng Feng, Jie Zhang, Yuxiao Dong, Yu Han et al.NeurIPS 2020 · 526 citations
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 416 citations
Related papers
- Robustness Inspired Graph Backdoor DefenseZhiwei Zhang, Minhua Lin, Junjie Xu, Zongyu Wu et al.ICLR 2025
- Chasing All-Round Graph Representation Robustness: Model, Training, and OptimizationChunhui Zhang, Yijun Tian, Mingxuan Ju, Zheyuan Liu et al.ICLR 2023
- HyperDefender: A Robust Framework for Hyperbolic GNNsNikita Malik, Rahul Gupta, Sandeep KumarAAAI 2025 · 6 citations
- AGNNCert: Defending Graph Neural Networks against Arbitrary Perturbations with Deterministic CertificationJiate Li, Binghui WangUSENIX Security 2025
- Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary PerturbationsJiate Li, Meng Pang, Yun Dong, Binghui WangCVPR 2025
