Randomized Message-Interception Smoothing: Gray-box Certificates for Graph Neural Networks
Yan Scholten, Jan Schuchardt, Simon Geisler, Aleksandar Bojchevski, Stephan Günnemann
Abstract
Randomized smoothing is one of the most promising frameworks for certifying the adversarial robustness of machine learning models, including Graph Neural Networks (GNNs). Yet, existing randomized smoothing certificates for GNNs are overly pessimistic since they treat the model as a black box, ignoring the underlying architecture. To remedy this, we propose novel gray-box certificates that exploit the message-passing principle of GNNs: We randomly intercept messages and carefully analyze the probability that messages from adversarially controlled nodes reach their target nodes. Compared to existing certificates, we certify robustness to much stronger adversaries that control entire nodes in the graph and can arbitrarily manipulate node features. Our certificates provide stronger guarantees for attacks at larger distances, as messages from farther-away nodes are more likely to get intercepted. We demonstrate the effectiveness of our method on various models and datasets. Since our gray-box certificates consider the underlying graph structure, we can significantly improve certifiable robustness by applying graph sparsification. 1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b7185d22-9e90-4549-b028-b4aa55c670a6Cited by top-tier papers12
- RS-Del: Edit Distance Robustness Certificates for Sequence Classifiers via Randomized DeletionZhuoqun Huang, Neil G. Marchant, Keane Lucas, Lujo Bauer et al.NeurIPS 2023 · 24 citations
- Adversarial Training for Graph Neural Networks: Pitfalls, Solutions, and New DirectionsLukas Gosch, Simon Geisler, Daniel Sturm, Bertrand Charpentier et al.NeurIPS 2023 · 19 citations
- Bounding the Expected Robustness of Graph Neural Networks Subject to Node Feature AttacksYassine Abbahaddou, Sofiane Ennadir, Johannes F. Lutzeyer, Michalis Vazirgiannis et al.ICLR 2024 · 15 citations
- GNNCert: Deterministic Certification of Graph Neural Networks against Adversarial PerturbationsZaishuo Xia, Han Yang, Binghui Wang, Jinyuan JiaICLR 2024 · 14 citations
- Hierarchical Randomized SmoothingYan Scholten, Jan Schuchardt, Aleksandar Bojchevski, Stephan GünnemannNeurIPS 2023 · 14 citations
Builds on18
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- How Attentive are Graph Attention Networks?Shaked Brody, Uri Alon, Eran YahavICLR 2022 · 1,717 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 416 citations
- Robustness of Graph Neural Networks at ScaleSimon Geisler, Tobias Schmidt, Hakan Sirin, Daniel Zügner et al.NeurIPS 2021 · 189 citations
Related papers
- Efficient Robustness Certificates for Discrete Data: Sparsity-Aware Randomized Smoothing for Graphs, Images and MoreAleksandar Bojchevski, Johannes Klicpera, Stephan GünnemannICML 2020 · 95 citations
- Certified Robustness of Graph Neural Networks against Adversarial Structural PerturbationBinghui Wang, Jinyuan Jia, Xiaoyu Cao, Neil Zhenqiang GongKDD 2021 · 50 citations
- Turning Strengths into Weaknesses: A Certified Robustness Inspired Attack Framework against Graph Neural NetworksBinghui Wang, Meng Pang, Yun DongCVPR 2023
- AuditVotes: Elevating Provable Defense for GNNs with Efficient Augmentation and Conditional SmoothingYuni Lai, Yulin Zhu, Yixuan Sun, Yulun Wu et al.CCS 2026
- Certifiable Robustness of Graph Convolutional Networks under Structure PerturbationsDaniel Zügner, Stephan GünnemannKDD 2020 · 44 citations
