Collective Robustness Certificates: Exploiting Interdependence in Graph Neural Networks
Jan Schuchardt, Aleksandar Bojchevski, Johannes Klicpera, Stephan Günnemann
摘要
In tasks like node classification, image segmentation, and named-entity recognition we have a classifier that simultaneously outputs multiple predictions (a vector of labels) based on a single input, i.e. a single graph, image, or document respectively. Existing adversarial robustness certificates consider each prediction independently and are thus overly pessimistic for such tasks. They implicitly assume that an adversary can use different perturbed inputs to attack different predictions, ignoring the fact that we have a single shared input. We propose the first collective robustness certificate which computes the number of predictions that are simultaneously guaranteed to remain stable under perturbation, i.e. cannot be attacked. We focus on Graph Neural Networks and leverage their locality property - perturbations only affect the predictions in a close neighborhood - to fuse multiple single-node certificates into a drastically stronger collective certificate. For example, on the Citeseer dataset our collective certificate for node classification increases the average number of certifiable feature perturbations from to .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- On Collective Robustness of Bagging Against Data PoisoningRuoxin Chen, Zenan Li, Jie Li, Junchi Yan 等ICML 2022 · 被引用 25 次
- Randomized Message-Interception Smoothing: Gray-box Certificates for Graph Neural NetworksYan Scholten, Jan Schuchardt, Simon Geisler, Aleksandar Bojchevski 等NeurIPS 2022 · 被引用 20 次
- Provable Training for Graph Contrastive LearningYue Yu, Xiao Wang, Mengmei Zhang, Nian Liu 等NeurIPS 2023 · 被引用 19 次
- Adversarial Training for Graph Neural Networks: Pitfalls, Solutions, and New DirectionsLukas Gosch, Simon Geisler, Daniel Sturm, Bertrand Charpentier 等NeurIPS 2023 · 被引用 19 次
- Bounding the Expected Robustness of Graph Neural Networks Subject to Node Feature AttacksYassine Abbahaddou, Sofiane Ennadir, Johannes F. Lutzeyer, Michalis Vazirgiannis 等ICLR 2024 · 被引用 15 次
它引用的顶会 Paper5
- Efficient Robustness Certificates for Discrete Data: Sparsity-Aware Randomized Smoothing for Graphs, Images and MoreAleksandar Bojchevski, Johannes Klicpera, Stephan GünnemannICML 2020 · 被引用 95 次
- Reliable Graph Neural Networks via Robust AggregationSimon Geisler, Daniel Zügner, Stephan GünnemannNeurIPS 2020 · 被引用 95 次
- Dynamic Divide-and-Conquer Adversarial Training for Robust Semantic SegmentationXiaogang Xu, Hengshuang Zhao, Jiaya JiaICCV 2021 · 被引用 47 次
- Certifiable Robustness of Graph Convolutional Networks under Structure PerturbationsDaniel Zügner, Stephan GünnemannKDD 2020 · 被引用 44 次
- Adversarial Attack and Defense of Structured Prediction ModelsWenjuan Han, Liwen Zhang, Yong Jiang, Kewei TuEMNLP 2020 · 被引用 32 次
相关 Paper
- Localized Randomized Smoothing for Collective Robustness CertificationJan Schuchardt, Tom Wollschläger, Aleksandar Bojchevski, Stephan GünnemannICLR 2023
- AGNNCert: Defending Graph Neural Networks against Arbitrary Perturbations with Deterministic CertificationJiate Li, Binghui WangUSENIX Security 2025
- GNNCert: Deterministic Certification of Graph Neural Networks against Adversarial PerturbationsZaishuo Xia, Han Yang, Binghui Wang, Jinyuan JiaICLR 2024 · 被引用 14 次
- Collective Certified Robustness against Graph Injection AttacksYuni Lai, Bailin Pan, Kaihuang Chen, Yancheng Yuan 等ICML 2024 · 被引用 4 次
- Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary PerturbationsJiate Li, Meng Pang, Yun Dong, Binghui WangCVPR 2025
