Collective Robustness Certificates: Exploiting Interdependence in Graph Neural Networks
Jan Schuchardt, Aleksandar Bojchevski, Johannes Klicpera, Stephan Günnemann
Abstract
In tasks like node classification, image segmentation, and named-entity recognition we have a classifier that simultaneously outputs multiple predictions (a vector of labels) based on a single input, i.e. a single graph, image, or document respectively. Existing adversarial robustness certificates consider each prediction independently and are thus overly pessimistic for such tasks. They implicitly assume that an adversary can use different perturbed inputs to attack different predictions, ignoring the fact that we have a single shared input. We propose the first collective robustness certificate which computes the number of predictions that are simultaneously guaranteed to remain stable under perturbation, i.e. cannot be attacked. We focus on Graph Neural Networks and leverage their locality property - perturbations only affect the predictions in a close neighborhood - to fuse multiple single-node certificates into a drastically stronger collective certificate. For example, on the Citeseer dataset our collective certificate for node classification increases the average number of certifiable feature perturbations from to .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers15
- On Collective Robustness of Bagging Against Data PoisoningRuoxin Chen, Zenan Li, Jie Li, Junchi Yan et al.ICML 2022 · 25 citations
- Randomized Message-Interception Smoothing: Gray-box Certificates for Graph Neural NetworksYan Scholten, Jan Schuchardt, Simon Geisler, Aleksandar Bojchevski et al.NeurIPS 2022 · 20 citations
- Provable Training for Graph Contrastive LearningYue Yu, Xiao Wang, Mengmei Zhang, Nian Liu et al.NeurIPS 2023 · 19 citations
- Adversarial Training for Graph Neural Networks: Pitfalls, Solutions, and New DirectionsLukas Gosch, Simon Geisler, Daniel Sturm, Bertrand Charpentier et al.NeurIPS 2023 · 19 citations
- Bounding the Expected Robustness of Graph Neural Networks Subject to Node Feature AttacksYassine Abbahaddou, Sofiane Ennadir, Johannes F. Lutzeyer, Michalis Vazirgiannis et al.ICLR 2024 · 15 citations
Builds on5
- Efficient Robustness Certificates for Discrete Data: Sparsity-Aware Randomized Smoothing for Graphs, Images and MoreAleksandar Bojchevski, Johannes Klicpera, Stephan GünnemannICML 2020 · 95 citations
- Reliable Graph Neural Networks via Robust AggregationSimon Geisler, Daniel Zügner, Stephan GünnemannNeurIPS 2020 · 95 citations
- Dynamic Divide-and-Conquer Adversarial Training for Robust Semantic SegmentationXiaogang Xu, Hengshuang Zhao, Jiaya JiaICCV 2021 · 47 citations
- Certifiable Robustness of Graph Convolutional Networks under Structure PerturbationsDaniel Zügner, Stephan GünnemannKDD 2020 · 44 citations
- Adversarial Attack and Defense of Structured Prediction ModelsWenjuan Han, Liwen Zhang, Yong Jiang, Kewei TuEMNLP 2020 · 32 citations
Related papers
- Localized Randomized Smoothing for Collective Robustness CertificationJan Schuchardt, Tom Wollschläger, Aleksandar Bojchevski, Stephan GünnemannICLR 2023
- AGNNCert: Defending Graph Neural Networks against Arbitrary Perturbations with Deterministic CertificationJiate Li, Binghui WangUSENIX Security 2025
- GNNCert: Deterministic Certification of Graph Neural Networks against Adversarial PerturbationsZaishuo Xia, Han Yang, Binghui Wang, Jinyuan JiaICLR 2024 · 14 citations
- Collective Certified Robustness against Graph Injection AttacksYuni Lai, Bailin Pan, Kaihuang Chen, Yancheng Yuan et al.ICML 2024 · 4 citations
- Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary PerturbationsJiate Li, Meng Pang, Yun Dong, Binghui WangCVPR 2025
