Adversarial Training for Graph Neural Networks: Pitfalls, Solutions, and New Directions
Lukas Gosch, Simon Geisler, Daniel Sturm, Bertrand Charpentier, Daniel Zügner, Stephan Günnemann
Abstract
Despite its success in the image domain, adversarial training did not (yet) stand out as an effective defense for Graph Neural Networks (GNNs) against graph structure perturbations. In the pursuit of fixing adversarial training (1) we show and overcome fundamental theoretical as well as practical limitations of the adopted graph learning setting in prior work; (2) we reveal that flexible GNNs based on learnable graph diffusion are able to adjust to adversarial perturbations, while the learned message passing scheme is naturally interpretable; (3) we introduce the first attack for structure perturbations that, while targeting multiple nodes at once, is capable of handling global (graph-level) as well as local (node-level) constraints. Including these contributions, we demonstrate that adversarial training is a state-of-the-art defense against adversarial structure perturbations. 1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7fad4cd6-59f2-4cbf-b42c-fe8d1e31f8e4Cited by top-tier papers21
- Hierarchical Randomized SmoothingYan Scholten, Jan Schuchardt, Aleksandar Bojchevski, Stephan GünnemannNeurIPS 2023 · 14 citations
- Node-aware Bi-smoothing: Certified Robustness against Graph Injection AttacksYuni Lai, Yulin Zhu, Bailin Pan, Kai ZhouS&P 2024 · 11 citations
- Can Large Language Models Improve the Adversarial Robustness of Graph Neural Networks?Zhongjian Zhang, Xiao Wang, Huichi Zhou, Yue Yu et al.KDD 2025 · 11 citations
- Enhancing Robustness of Graph Neural Networks on Social Media with Explainable Inverse Reinforcement LearningYuefei Lyu, Chaozhuo Li, Sihong Xie, Xi ZhangNeurIPS 2024 · 8 citations
- Collective Certified Robustness against Graph Injection AttacksYuni Lai, Bailin Pan, Kaihuang Chen, Yancheng Yuan et al.ICML 2024 · 4 citations
Builds on18
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- Graph Random Neural Networks for Semi-Supervised Learning on GraphsWenzheng Feng, Jie Zhang, Yuxiao Dong, Yu Han et al.NeurIPS 2020 · 526 citations
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 416 citations
- Convolutional Neural Networks on Graphs with Chebyshev Approximation, RevisitedMingguo He, Zhewei Wei, Ji-Rong WenNeurIPS 2022 · 220 citations
- Robustness of Graph Neural Networks at ScaleSimon Geisler, Tobias Schmidt, Hakan Sirin, Daniel Zügner et al.NeurIPS 2021 · 189 citations
Related papers
- AGNNCert: Defending Graph Neural Networks against Arbitrary Perturbations with Deterministic CertificationJiate Li, Binghui WangUSENIX Security 2025
- Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary PerturbationsJiate Li, Meng Pang, Yun Dong, Binghui WangCVPR 2025
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang et al.KDD 2020 · 604 citations
- Graph Defense Diffusion ModelXin He, Wenqi Fan, Yili Wang, Chengyi Liu et al.KDD 2026 · 3 citations
- Graph Neural Network Explanations are FragileJiate Li, Meng Pang, Yun Dong, Jinyuan Jia et al.ICML 2024 · 20 citations
