Robust Heterogeneous Graph Neural Networks against Adversarial Attacks
Mengmei Zhang, Xiao Wang, Meiqi Zhu, Chuan Shi, Zhiqiang Zhang, Jun Zhou
Abstract
Heterogeneous Graph Neural Networks (HGNNs) have drawn increasing attention in recent years and achieved outstanding performance in many tasks. However, despite their wide use, there is currently no understanding of their robustness to adversarial attacks. In this work, we first systematically study the robustness of HGNNs and show that they can be easily fooled by adding the adversarial edge between the target node and large-degree node (i.e., hub). Furthermore, we show two key reasons for such vulnerability of HGNNs: one is perturbation enlargement effect, i.e., HGNNs, failing to encode transiting probability, will enlarge the effect of the adversarial hub in comparison of GCNs, and the other is soft attention mechanism, i.e., such mechanism assigns positive attention values to obviously unreliable neighbors. Based on the two facts, we propose a novel robust HGNN framework RoHe against topology adversarial attacks by equipping an attention purifier, which can prune malicious neighbors based on topology and feature. Specifically, to eliminate the perturbation enlargement, we introduce the metapath-based transiting probability as the prior criterion of the purifier, restraining the confidence of malicious neighbors from the adversarial hub. Then the purifier learns to mask out neighbors with low confidence, thus can effectively alleviate the negative effect of malicious neighbors in the soft attention mechanism. Extensive experiments on different benchmark datasets for multiple HGNNs are conducted, where the considerable improvement of HGNNs under adversarial attacks will demonstrate the effectiveness and generalization ability of our defense framework.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a9319a97-082c-41ea-a852-a4ca7c0a142bCited by top-tier papers7
- Federated Heterogeneous Graph Neural Network for Privacy-preserving RecommendationBo Yan, Yang Cao, Haoyu Wang, Wenchuan Yang et al.WWW 2024 · 62 citations
- Learning Efficient and Robust Multi-Agent Communication via Graph Information BottleneckShifei Ding, Wei Du, Ling Ding, Lili Guo et al.AAAI 2024 · 12 citations
- Can Large Language Models Improve the Adversarial Robustness of Graph Neural Networks?Zhongjian Zhang, Xiao Wang, Huichi Zhou, Yue Yu et al.KDD 2025 · 11 citations
- Rethinking Independent Cross-Entropy Loss For Graph-Structured DataRui Miao, Kaixiong Zhou, Yili Wang, Ninghao Liu et al.ICML 2024 · 5 citations
- Rethinking Byzantine Robustness in Federated Recommendation from Sparse Aggregation PerspectiveZhongjian Zhang, Mengmei Zhang, Xiao Wang, Lingjuan Lyu et al.AAAI 2025 · 5 citations
Builds on5
- MAGNN: Metapath Aggregated Graph Neural Network for Heterogeneous Graph EmbeddingXinyu Fu, Jiani Zhang, Ziqiao Meng, Irwin KingWWW 2020 · 1,149 citations
- Beyond Low-frequency Information in Graph Convolutional NetworksDeyu Bo, Xiao Wang, Chuan Shi, Huawei ShenAAAI 2021 · 773 citations
- Towards More Practical Adversarial Attacks on Graph Neural NetworksJiaqi Ma, Shuangrui Ding, Qiaozhu MeiNeurIPS 2020 · 160 citations
- Financial Defaulter Detection on Online Credit Payment via Multi-view Attributed Heterogeneous Information NetworkQiwei Zhong, Yang Liu, Xiang Ao, Binbin Hu et al.WWW 2020 · 133 citations
- Adversarial Attack on Community Detection by Hiding IndividualsJia Li, Honglei Zhang, Zhichao Han, Yu Rong et al.WWW 2020 · 106 citations
Related papers
- How does Heterophily Impact the Robustness of Graph Neural Networks?: Theoretical Connections and Practical ImplicationsJiong Zhu, Junchen Jin, Donald Loveland, Michael T. Schaub et al.KDD 2022 · 26 citations
- Self-supervised Adversarial Purification for Graph Neural NetworksWoohyun Lee, Hogun ParkICML 2025
- Understanding and Improving Graph Injection Attack by Promoting UnnoticeabilityYongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma et al.ICLR 2022 · 106 citations
- Robust Heterogeneous Graph Classification for Molecular Property Prediction with Information BottleneckZhibin Ni, Chang Liu, Hai Wan, Xibin ZhaoAAAI 2025 · 3 citations
- Transferable Hypergraph Attack via Injecting Nodes into Pivotal HyperedgesMeixia He, Peican Zhu, Le Cheng, Yangming Guo et al.AAAI 2026 · 1 citation
