Graph Adversarial Defense with Virtual Spectral Anchor Injection
Xiangchao Wen, Zhen Liu, Yunfei Liu
Abstract
Graph Neural Networks (GNNs) have demonstrated superior performance in various graph learning tasks such as node classification and link prediction. However, recent studies have shown that GNNs are highly vulnerable to graph adversarial attacks. To enhance the robustness of GNNs, existing defense strategies have primarily focused on adversarial training on graph data, graph purification, or certifiable robustness. Different from the conventional defense paradigms, we propose Anchor Node Injection Enhancement (ANIE), an active paradigm that repurposes the offensive tactic of node injection into a structural defense. ANIE injects virtual ''auxiliary anchor nodes'' to stabilize the graph's spectral manifold through Dirichlet energy minimization. By establishing robust class prototypes, ANIE reinforces class-wise structural stability and guides perturbed nodes back to correct manifolds. As an attack-agnostic and ''plug-and-play'' framework, ANIE requires no physical modification of the original graph and generalizes to both transductive and inductive settings. Empirical results across multiple benchmarks demonstrate that ANIE significantly enhances GNN robustness, outperforming state-of-the-art defenses by up to 2× in classification accuracy under poisoning and evasion attacks.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get b0eec188-01c2-47f3-8327-8ebe62f9044bRelated papers
- Fight Fire with Fire: Towards Robust Graph Neural Networks on Dynamic Graphs via Actively DefenseHaoyang Li, Shimin Di, Calvin Hong Yi Li, Lei Chen et al.VLDB 2024 · 6 citations
- Turning Strengths into Weaknesses: A Certified Robustness Inspired Attack Framework against Graph Neural NetworksBinghui Wang, Meng Pang, Yun DongCVPR 2023
- Node-aware Bi-smoothing: Certified Robustness against Graph Injection AttacksYuni Lai, Yulin Zhu, Bailin Pan, Kai ZhouS&P 2024 · 11 citations
- Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary PerturbationsJiate Li, Meng Pang, Yun Dong, Binghui WangCVPR 2025
- AGNNCert: Defending Graph Neural Networks against Arbitrary Perturbations with Deterministic CertificationJiate Li, Binghui WangUSENIX Security 2025
