Reliable Graph Neural Networks via Robust Aggregation
Simon Geisler, Daniel Zügner, Stephan Günnemann
Abstract
Perturbations targeting the graph structure have proven to be extremely effective in reducing the performance of Graph Neural Networks (GNNs), and traditional defenses such as adversarial training do not seem to be able to improve robustness. This work is motivated by the observation that adversarially injected edges effectively can be viewed as additional samples to a node's neighborhood aggregation function, which results in distorted aggregations accumulating over the layers. Conventional GNN aggregation functions, such as a sum or mean, can be distorted arbitrarily by a single outlier. We propose a robust aggregation function motivated by the field of robust statistics. Our approach exhibits the largest possible breakdown point of 0.5, which means that the bias of the aggregation is bounded as long as the fraction of adversarial edges of a node is less than 50%. Our novel aggregation function, Soft Medoid, is a fully differentiable generalization of the Medoid and therefore lends itself well for end-to-end deep learning. Equipping a GNN with our aggregation improves the robustness with respect to structure perturbations on Cora ML by a factor of 3 (and 5.5 on Citeseer) and by a factor of 8 for low-degree nodes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 71fb9c46-0ebf-4a7d-859a-dfef0beee534Cited by top-tier papers21
- Robustness of Graph Neural Networks at ScaleSimon Geisler, Tobias Schmidt, Hakan Sirin, Daniel Zügner et al.NeurIPS 2021 · 189 citations
- Are Defenses for Graph Neural Networks Robust?Felix Mujkanovic, Simon Geisler, Stephan Günnemann, Aleksandar BojchevskiNeurIPS 2022 · 79 citations
- Reliable Representations Make A Stronger Defender: Unsupervised Structure Refinement for Robust GNNKuan Li, Yang Liu, Xiang Ao, Jianfeng Chi et al.KDD 2022 · 63 citations
- Defending Graph Convolutional Networks against Dynamic Graph Perturbations via Bayesian Self-SupervisionJun Zhuang, Mohammad Al HasanAAAI 2022 · 48 citations
- Collective Robustness Certificates: Exploiting Interdependence in Graph Neural NetworksJan Schuchardt, Aleksandar Bojchevski, Johannes Klicpera, Stephan GünnemannICLR 2021 · 29 citations
Builds on2
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Certifiable Robustness of Graph Convolutional Networks under Structure PerturbationsDaniel Zügner, Stephan GünnemannKDD 2020 · 44 citations
Related papers
- How does Heterophily Impact the Robustness of Graph Neural Networks?: Theoretical Connections and Practical ImplicationsJiong Zhu, Junchen Jin, Donald Loveland, Michael T. Schaub et al.KDD 2022 · 26 citations
- AGNNCert: Defending Graph Neural Networks against Arbitrary Perturbations with Deterministic CertificationJiate Li, Binghui WangUSENIX Security 2025
- Boosting the Adversarial Robustness of Graph Neural Networks: An OOD PerspectiveKuan Li, Yiwen Chen, Yang Liu, Jin Wang et al.ICLR 2024 · 13 citations
- Certified Robustness of Graph Neural Networks against Adversarial Structural PerturbationBinghui Wang, Jinyuan Jia, Xiaoyu Cao, Neil Zhenqiang GongKDD 2021 · 50 citations
- Robust Graph Neural Networks via Unbiased AggregationZhichao Hou, Ruiqi Feng, Tyler Derr, Xiaorui LiuNeurIPS 2024 · 11 citations
