Mitigating Emergent Robustness Degradation while Scaling Graph Learning
Xiangchi Yuan, Chunhui Zhang, Yijun Tian, Yanfang Ye, Chuxu Zhang
摘要
While graph neural networks have exhibited remarkable performance in various graph tasks, a significant concern is their vulnerability to adversarial attacks. Consequently, many defense methods have been proposed to alleviate the deleterious effects of adversarial attacks and learn robust graph representations. However, most of them are difficult to simultaneously avoid two major limitations: 1) an emergent and severe degradation in robustness when exposed to very intense attacks, and 2) heavy computation complexity hinders them from scaling to large graphs. In response to these challenges, we introduce an innovative graph defense method for unpredictable real-world scenarios by designing a graph robust learning framework that is resistant to robustness degradation and refraining from the unscalable designs with heavy computation: specifically, our method employs a denoising module, which eliminates edges that are associated with attacked nodes to reconstruct a cleaner graph; Then, it applies Mixture-of-Experts to select differentially private noises with varying magnitudes to counteract the hidden features attacked at different intensities toward robust predictions; Moreover, our overall design avoids the reliance on heavy adjacency matrix computations, such as SVD, thus facilitating its applicability even on large graphs. Comprehensive experiments have been conducted to demonstrate the anti-degraded robustness and scalability of our method, as compared to popular graph adversarial learning methods, under diverse attack intensities and various datasets of different sizes.
- Xiangchi is mentored by Chunhui; both contributed equally and are listed alphabetically by last name.
Published as a conference paper at ICLR 2024 GNNGuard (Zhang & Zitnik, 2020), which require dense adjacency matrix computations. This can result in substantial computational overhead, as shown in the experiment section, leading to out-of-memory problems when applied to larger datasets like Flick, Reddit, and AMiner, especially when using a 32 GB GPU. These challenges necessitate innovative solutions to enhance the robustness and scalability of GNNs against adversarial attacks. 0 100 200 300 400 500 600 700
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Graph Defense Diffusion ModelXin He, Wenqi Fan, Yili Wang, Chengyi Liu 等KDD 2026 · 被引用 3 次
- Generalizing GNNs with Tokenized Mixture of ExpertsXiaoguang Guo, Zehong Wang, Jiazheng Li, Shawn Spitzel 等KDD 2026 · 被引用 1 次
- A Cognac Shot To Forget Bad Memories: Corrective Unlearning for Graph Neural NetworksVarshita Kolipaka, Akshit Sinha, Debangan Mishra, Sumit Kumar 等ICML 2025
- Certified Signed Graph UnlearningJunpeng Zhao, Lin Li, Yu Yang, Kaixi Hu 等KDD 2026
它引用的顶会 Paper26
- Graph Contrastive Learning with AugmentationsYuning You, Tianlong Chen, Yongduo Sui, Ting Chen 等NeurIPS 2020 · 被引用 3,042 次
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang 等KDD 2020 · 被引用 604 次
- Graph Random Neural Networks for Semi-Supervised Learning on GraphsWenzheng Feng, Jie Zhang, Yuxiao Dong, Yu Han 等NeurIPS 2020 · 被引用 526 次
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 被引用 416 次
相关 Paper
- Robustness Inspired Graph Backdoor DefenseZhiwei Zhang, Minhua Lin, Junjie Xu, Zongyu Wu 等ICLR 2025
- Chasing All-Round Graph Representation Robustness: Model, Training, and OptimizationChunhui Zhang, Yijun Tian, Mingxuan Ju, Zheyuan Liu 等ICLR 2023
- HyperDefender: A Robust Framework for Hyperbolic GNNsNikita Malik, Rahul Gupta, Sandeep KumarAAAI 2025 · 被引用 6 次
- AGNNCert: Defending Graph Neural Networks against Arbitrary Perturbations with Deterministic CertificationJiate Li, Binghui WangUSENIX Security 2025
- Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary PerturbationsJiate Li, Meng Pang, Yun Dong, Binghui WangCVPR 2025
