1. Introduction
Graph neural networks (GNNs) have been widely applied to graph-structured data due to their strong capability to model relational dependencies and integrate node features with topological information, especially in node classification tasks [
1,
2]. However, recent studies have shown that their performance is sensitive to distribution shift, calibration, and uncertainty under changing graph structure [
3,
4,
5,
6]. Their reliance on topology also introduces a major security vulnerability: classic poisoning attacks demonstrate that small but carefully designed structural perturbations can significantly degrade predictive accuracy [
7,
8], while more recent studies have extended this concern to broader poisoning, certification, and robustness settings [
9,
10,
11]. In poisoning attacks, the adversary manipulates the graph before training, requiring the defender to purify the corrupted structure, learn a robust model, or combine both strategies [
8].
Most existing defenses are developed for a fixed poisoning setting and are typically trained or evaluated on a single poisoned graph [
12,
13,
14]. This design is effective when the attack pattern remains fixed, but it becomes brittle when the defender faces a mixture of perturbation budgets, targeted versus global attacks, or previously unseen poisoned graphs. In practice, poisoned graphs may vary not only in attack type but also in structural severity and local perturbation patterns, making it difficult for a static defense to remain reliable across settings. Our starting point is therefore not to train one static defense on one static graph, but to train a defense that learns from multiple graph realizations, captures complementary structural evidence across them, and can adaptively reweight its components at test time according to the reliability of the current graph.
This paper develops the above intuition into
GADD, a game-inspired adversarial distillation framework for robust graph defense. Unlike prior defenses that either purify a single graph, distill knowledge from a fixed teacher, or aggregate multiple models with static rules, GADD tightly couples three complementary mechanisms into one collaborative pipeline. First, we sample multiple graph views from several poisoned graphs. Positive views retain structurally plausible and feature-consistent edges, while negative views preserve suspicious edges that may encode adversarial perturbations. This design exposes the model to both purified and high-risk structural patterns. Second, instead of relying on an offline teacher, we train several lightweight GNNs online in a peer-distillation manner [
15,
16]. Each student learns global predictive knowledge from the remaining peers. In addition, we introduce an adversarial cyclic objective, which contrasts node representations from positive and negative graph views across students in a cyclic manner, encouraging the model to distinguish robust patterns from perturbations. Third, we avoid uniform averaging at inference time. We instead use an entropy-regularized aggregation rule, which assigns adaptive weights to students based on their prediction confidence and agreement with others, while an entropy term prevents the weights from collapsing to a single model.
Importantly, these three components are not isolated modules. The sampled graph views determine the structural discrepancies observed during distillation, while the adaptive aggregation mechanism continuously evaluates which students have successfully absorbed robust knowledge from those discrepancies. This coupling allows GADD to operate as a dynamic robustness-transfer framework rather than a conventional ensemble of independently trained defenses.
Experiments on Cora [
17], CiteSeer [
18], and PubMed [
18] show that GADD consistently improves robustness under Meta and Nettack attacks. The advantage over the strongest baseline becomes especially clear under high attack strengths in several settings. Additional experiments on ogbn-arxiv under PGD-based topology attack and random edge perturbation further indicate that GADD remains scalable on large graphs. We also observe that the full model is materially better than removing graph sampling, adversarial distillation, or adaptive aggregation; heterogeneous students outperform homogeneous ones; and a single GCN discriminator is sufficient in practice.
Our main contributions are as follows:
We propose GADD, a unified defense framework that combines graph sampling, online adversarial distillation, and entropy-regularized adaptive aggregation for robust graph defense.
We formulate a positive/negative graph-view construction procedure and design an adversarial cyclic distillation loss to transfer both global class knowledge and local structural knowledge across students.
We introduce an entropy-regularized weighting rule for ensemble aggregation that adapts to the current graph instead of using uniform averaging.
The remainder of the paper is organized as follows.
Section 2 reviews graph attacks, defenses, and graph distillation.
Section 3 presents GADD.
Section 4 reports the empirical study.
Section 5 concludes the paper.
2. Related Work
Recent studies related to robust GNNs can be broadly grouped into four directions: graph poisoning attacks, graph purification and robust learning, knowledge distillation on graphs, and calibration, uncertainty, and adaptive aggregation. These directions together motivate our design. Poisoning studies define the threat models to be handled, purification methods motivate the construction of cleaner graph views, graph distillation suggests knowledge transfer across models, and calibration- or uncertainty-aware aggregation highlights the need for graph-dependent reliability weighting.
Attacks on graph neural networks. Poisoning attacks manipulate the graph before model training and have become a standard evaluation setting for robust GNNs. Nettack is a representative targeted attack showing that only a small number of perturbations can already mislead node classification on attributed graphs [
7]. Meta Attack further extends this idea to global training-time poisoning by optimizing graph perturbations through meta-gradients [
8]. More recent work has expanded this line toward robustness analysis under node-feature attacks, certified robustness against adversarial perturbations, certification against label poisoning, and formal robustness verification for deep GNNs [
9,
19,
20,
21]. These studies indicate that graph poisoning is diverse in perturbation type and threat model, thereby motivating defenses that can generalize beyond a single fixed attack instance.
Graph purification and robust learning. Existing work relevant to defense mainly follows two lines. One line aims to purify or reconstruct topology before message passing. For example, Jaccard filtering removes suspicious edges according to feature similarity between connected nodes [
22], while ProGNN jointly learns a cleaner graph structure and the downstream classifier to improve robustness under perturbations [
23]. Another line improves robustness or reliability from the training or prediction side. Representative examples include adversarial defense via noise injection [
13], calibration methods for confidence correction [
3,
4,
24,
25], and uncertainty-aware modeling [
5,
26]. Although these methods improve robustness or reliability under graph shift, they are still typically built around a single graph view, a single learner, or a fixed correction mechanism.
Knowledge distillation on graphs. Knowledge distillation on graphs has evolved from conventional model compression toward denoising, selective transfer, and multi-source supervision. Adaptive denoising distillation explicitly reduces noisy teacher knowledge and structural noise during transfer [
15]. Partial-knowledge distillation further shows that transferring only part of the teacher information can be beneficial, rather than enforcing uniform transfer of all teacher signals [
27]. More recent graph distillation methods also explore dual-source supervision, such as robust dual knowledge distillation from LLMs and dual-teacher distillation settings [
16,
28]. However, these methods are generally not developed for graph poisoning defense under multiple attacked graph realizations. By contrast, GADD performs online peer distillation across sampled positive and negative graph views and couples it with adversarial local matching.
Calibration, uncertainty, and adaptive aggregation. Another related line studies graph-aware reliability estimation through calibration, uncertainty modeling, and adaptive aggregation. SimCalib and Moderate Message Passing improve confidence calibration by exploiting graph-aware similarity or message-passing behavior [
3,
4]. Balanced confidence calibration and ensemble temperature scaling further show that graph-aware calibration can benefit from balancing confidence bias and leveraging multiple experts [
24,
25]. Uncertainty-oriented methods estimate epistemic uncertainty or stochastic uncertainty in GNNs, providing a more principled basis for reliable prediction under structural shift [
5,
26]. In addition, unbiased aggregation methods redesign the message aggregation operator itself to improve adversarial robustness [
29]. Different from these studies, GADD integrates adaptive aggregation directly into the defense pipeline, so that student weights depend on reliability on the current poisoned graph and affect both inference and training.
Although prior studies motivate individual aspects of our design, existing methods typically optimize these components independently. Multi-view purification methods mainly focus on graph reconstruction, distillation methods usually transfer knowledge under fixed graph conditions, and ensemble defenses generally rely on static fusion strategies. In contrast, GADD explicitly couples graph-view generation, adversarial robustness transfer, and graph-adaptive weighting into a unified optimization process, enabling robustness knowledge learned from one perturbation pattern to dynamically influence representation learning and aggregation under other poisoned graphs.
Author Contributions
Conceptualization, Y.P. and K.L.; methodology, Y.P., C.Z. and K.L.; software, Y.P. and C.Z.; validation, Y.P., C.Z. and Y.L.; formal analysis, Y.P., Y.L. and F.Z.; investigation, Y.P. and C.Z.; resources, K.L., F.Z. and S.L.; data curation, Y.P. and C.Z.; writing—original draft preparation, Y.P.; writing—review and editing, C.Z., Y.L., K.L., F.Z. and S.L.; visualization, Y.P. and C.Z.; supervision, K.L., F.Z. and S.L.; project administration, K.L. and S.L.; funding acquisition, K.L. and S.L. All authors have read and agreed to the published version of the manuscript.
Funding
This research was funded by the Jiangsu Provincial Department of Science and Technology, grant number ZL042501; the SEU Innovation Capability Enhancement Plan for Doctoral Students, grant number CXJH_SEU_25245; and the Postgraduate Research & Practice Innovation Program of Jiangsu Province, grant number KYCX24_0478.
Institutional Review Board Statement
Not applicable.
Informed Consent Statement
Not applicable.
Data Availability Statement
Conflicts of Interest
The authors declare no conflict of interest.
References
- Kipf, T.N.; Welling, M. Semi-Supervised Classification with Graph Convolutional Networks. In Proceedings of the International Conference on Learning Representations, Toulon, France, 24–26 April 2017. [Google Scholar]
- Peng, Y.; Zhou, C.; Cui, H.; Duan, T.; Chen, H.; Zhang, F.; Liu, S. Resilient UAV Swarm with Fast Connectivity Recovery and Extensive Coverage. In Proceedings of the AAAI Conference on Artificial Intelligence, Singapore, 20–27 January 2026; Volume 40, pp. 917–925. [Google Scholar]
- Tang, B.; Wu, Z.; Wu, X.; Huang, Q.; Chen, J.; Lei, S.; Meng, H. SimCalib: Graph Neural Network Calibration Based on Similarity between Nodes. In Proceedings of the AAAI Conference on Artificial Intelligence, Vancouver, BC, Canada, 20–27 February 2024; Volume 38, pp. 15267–15275. [Google Scholar] [CrossRef]
- Wang, M.; Yang, H.; Huang, J.; Cheng, Q. Moderate Message Passing Improves Calibration: A Universal Way to Mitigate Confidence Bias in Graph Neural Networks. In Proceedings of the AAAI Conference on Artificial Intelligence, Vancouver, BC, Canada, 20–27 February 2024; Volume 38, pp. 21681–21689. [Google Scholar] [CrossRef]
- Trivedi, P.; Heimann, M.; Anirudh, R.; Koutra, D.; Thiagarajan, J.J. Accurate and Scalable Estimation of Epistemic Uncertainty for Graph Neural Networks. In Proceedings of the Twelfth International Conference on Learning Representations (ICLR), Vienna, Austria, 7–11 May 2024. [Google Scholar]
- Xiao, Z.; Zhou, Y.; Li, D.; Wang, K. Towards Fair Graph Neural Networks via Counterfactual and Balance. Information 2025, 16, 704. [Google Scholar] [CrossRef]
- Zügner, D.; Akbarnejad, A.; Günnemann, S. Adversarial Attacks on Neural Networks for Graph Data. In Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, London, UK, 19–23 August 2018; pp. 2847–2856. [Google Scholar] [CrossRef]
- Zügner, D.; Günnemann, S. Adversarial Attacks on Graph Neural Networks via Meta Learning. In Proceedings of the International Conference on Learning Representations, New Orleans, LA, USA, 6–9 May 2019. [Google Scholar]
- Xia, Z.; Yang, H.; Wang, B.; Jia, J. GNNCert: Deterministic Certification of Graph Neural Networks against Adversarial Perturbations. In Proceedings of the Twelfth International Conference on Learning Representations (ICLR), Vienna, Austria, 7–11 May 2024. [Google Scholar]
- Alom, M.Z.; Ngo, T.G.B.; Kantarcioglu, M.; Akçora, C.G. GOttack: Universal Adversarial Attacks on Graph Neural Networks via Graph Orbits Learning. In Proceedings of the Thirteenth International Conference on Learning Representations (ICLR), Singapore, 24–28 April 2025. [Google Scholar]
- Peng, Y.; Wu, J.; Duan, T.; Liu, Y.; Zhou, C.; Zhang, Z. Decentralized Topology Robustness Optimization for IoT via Multi-Agent Graph Reinforcement Learning. IEEE Trans. Mob. Comput. 2026, in press. [Google Scholar] [CrossRef]
- Li, K.; Chen, Y.; Liu, Y.; Wang, J.; He, Q.; Cheng, M.; Ao, X. Boosting the Adversarial Robustness of Graph Neural Networks: An OOD Perspective. In Proceedings of the Twelfth International Conference on Learning Representations (ICLR), Vienna, Austria, 7–11 May 2024. [Google Scholar]
- Ennadir, S.; Abbahaddou, Y.; Lutzeyer, J.F.; Vazirgiannis, M.; Boström, H. A Simple and Yet Fairly Effective Defense for Graph Neural Networks. In Proceedings of the AAAI Conference on Artificial Intelligence, Vancouver, BC, Canada, 20–27 February 2024; Volume 38, pp. 21063–21071. [Google Scholar] [CrossRef]
- Zhou, C.; Huang, W.; Miao, X.; Peng, Y.; Kong, X.; Cao, Y.; Chen, X. Fortifying graph neural networks against adversarial attacks via ensemble learning. Knowl.-Based Syst. 2025, 309, 112867. [Google Scholar] [CrossRef]
- Guo, Y.; Yang, C.; Shi, C.; Tu, K.; Wu, Z.; Zhang, Z.; Zhou, J. Adaptively Denoising Graph Neural Networks for Knowledge Distillation. In Proceedings of the Machine Learning and Knowledge Discovery in Databases: Research Track, Vilnius, Lithuania, 9–13 September 2024; pp. 253–269. [Google Scholar] [CrossRef]
- Huo, C.; Huang, X.; He, D.; Du, Y.; Lu, W.; Jin, D. DuoKD: Dual Knowledge Distillation from Large Language Models for Robust Graph Neural Networks. In Proceedings of the AAAI Conference on Artificial Intelligence, Singapore, 20–27 January 2026; Volume 40, pp. 14919–14927. [Google Scholar] [CrossRef]
- McCallum, A.K.; Nigam, K.; Rennie, J.; Seymore, K. Automating the Construction of Internet Portals with Machine Learning. Inf. Retr. 2000, 3, 127–163. [Google Scholar] [CrossRef]
- Sen, P.; Namata, G.; Bilgic, M.; Getoor, L.; Gallagher, B.; Eliassi-Rad, T. Collective Classification in Network Data. AI Mag. 2008, 29, 93–106. [Google Scholar] [CrossRef]
- Abbahaddou, Y.; Ennadir, S.; Lutzeyer, J.F.; Vazirgiannis, M.; Boström, H. Bounding the Expected Robustness of Graph Neural Networks Subject to Node Feature Attacks. In Proceedings of the Twelfth International Conference on Learning Representations (ICLR), Vienna, Austria, 7–11 May 2024. [Google Scholar]
- Sabanayagam, M.; Gosch, L.; Günnemann, S.; Ghoshdastidar, D. Exact Certification of (Graph) Neural Networks Against Label Poisoning. In Proceedings of the Thirteenth International Conference on Learning Representations (ICLR), Singapore, 24–28 April 2025. [Google Scholar]
- Zeng, X.; Li, H.; Qi, Q.; Wang, J.; Deng, H.; Sun, H.; Zhuang, Z.; Liao, J. Robustness Verification of Deep Graph Neural Networks Tightened by Linear Approximation. In Proceedings of the 18th ACM International Conference on Web Search and Data Mining, Hannover, Germany, 10–14 March 2025; pp. 281–289. [Google Scholar] [CrossRef]
- Wu, H.; Wang, C.; Tyshetskiy, Y.; Docherty, A.; Lu, K.; Zhu, L. Adversarial Examples for Graph Data: Deep Insights into Attack and Defense. In Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence (IJCAI-19), Macao, China, 10–16 August 2019; pp. 4816–4823. [Google Scholar] [CrossRef]
- Jin, W.; Ma, Y.; Liu, X.; Tang, X.; Wang, S.; Tang, J. Graph Structure Learning for Robust Graph Neural Networks. In Proceedings of the 26th ACM SIGKDD Conference on Knowledge Discovery & Data Mining, Virtual Conference, 23–27 August 2020; pp. 66–74. [Google Scholar] [CrossRef]
- Yang, H.; Wang, M.; Wang, Q.; Lao, M.; Zhou, Y. Balanced Confidence Calibration for Graph Neural Networks. In Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Barcelona, Spain, 25–29 August 2024; pp. 3747–3757. [Google Scholar] [CrossRef]
- Zhuang, D.; Jiang, C.; Zheng, Y.; Wang, S.; Zhao, J. GETS: Ensemble Temperature Scaling for Calibration in Graph Neural Networks. In Proceedings of the Thirteenth International Conference on Learning Representations (ICLR), Singapore, 24–28 April 2025. [Google Scholar]
- Bergna, R.; Calvo-Ordoñez, S.; Opolka, F.L.; Liò, P.; Hernández-Lobato, J.M. Uncertainty Modeling in Graph Neural Networks via Stochastic Differential Equations. In Proceedings of the Thirteenth International Conference on Learning Representations (ICLR), Singapore, 24–28 April 2025. [Google Scholar]
- Zhu, Y.; Li, J.; Chen, L.; Zheng, Z. The Devil is in the Data: Learning Fair Graph Neural Networks via Partial Knowledge Distillation. In Proceedings of the 17th ACM International Conference on Web Search and Data Mining, Mérida, Mexico, 4–8 March 2024; pp. 1012–1021. [Google Scholar] [CrossRef]
- Li, C.; Cheng, D.; Zhang, G.; Li, Y.; Zhang, S. Toward Fair Graph Neural Networks via Dual-Teacher Knowledge Distillation. Neural Netw. 2026, 194, 108184. [Google Scholar] [CrossRef] [PubMed]
- Hou, Z.; Feng, R.; Derr, T.; Liu, X. Robust Graph Neural Networks via Unbiased Aggregation. In Proceedings of the Advances in Neural Information Processing Systems, Vancouver, BC, Canada, 10–15 December 2024; Volume 37. [Google Scholar]
- Veličković, P.; Cucurull, G.; Casanova, A.; Romero, A.; Liò, P.; Bengio, Y. Graph Attention Networks. In Proceedings of the International Conference on Learning Representations, Vancouver, BC, Canada, 30 April–3 May 2018. [Google Scholar]
- Hamilton, W.L.; Ying, R.; Leskovec, J. Inductive Representation Learning on Large Graphs. In Proceedings of the Advances in Neural Information Processing Systems, Long Beach, CA, USA, 4–9 December 2017; Volume 30. [Google Scholar]
- Zhang, C.; Liu, J.; Dang, K.; Zhang, W. Multi-Scale Distillation from Multiple Graph Neural Networks. In Proceedings of the AAAI Conference on Artificial Intelligence, Virtual Event, 22 February–1 March 2022; Volume 36, pp. 4337–4344. [Google Scholar] [CrossRef]
- Guo, Z.; Zhang, C.; Fan, Y.; Tian, Y.; Zhang, C.; Chawla, N.V. Boosting Graph Neural Networks via Adaptive Knowledge Distillation. In Proceedings of the AAAI Conference on Artificial Intelligence, Washington, DC, USA, 7–14 February 2023; Volume 37, pp. 7793–7801. [Google Scholar] [CrossRef]
- Wu, L.; Lin, H.; Gao, Z.; Zhao, G.; Li, S.Z. A Teacher-Free Graph Knowledge Distillation Framework with Dual Self-Distillation. IEEE Trans. Knowl. Data Eng. 2024, 36, 4375–4385. [Google Scholar] [CrossRef]
- Zhou, C.; Peng, Y.; Huang, W.; Miao, X.; Cao, Y.; Wang, X.; Kong, X. A Dynamic Ensemble Learning Model for Robust Graph Neural Networks. Neural Netw. 2025, 191, 107810. [Google Scholar] [CrossRef] [PubMed]
- Jin, W.; Derr, T.; Wang, Y.; Ma, Y.; Liu, Z.; Tang, J. Node Similarity Preserving Graph Convolutional Networks. In Proceedings of the 14th ACM International Conference on Web Search and Data Mining, Virtual Event, Israel, 8–12 March 2021; pp. 148–156. [Google Scholar] [CrossRef]
- Jia, Y.; Zou, D.; Wang, H.; Jin, H. Enhancing Node-Level Adversarial Defenses by Lipschitz Regularization of Graph Neural Networks. In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Long Beach, CA, USA, 6–10 August 2023; pp. 951–963. [Google Scholar] [CrossRef]
- Hu, W.; Fey, M.; Zitnik, M.; Dong, Y.; Ren, H.; Liu, B.; Catasta, M.; Leskovec, J. Open Graph Benchmark: Datasets for Machine Learning on Graphs. In Proceedings of the Advances in Neural Information Processing Systems, Virtual Event, 6–12 December 2020; Volume 33, pp. 22118–22133. [Google Scholar]
- Xu, K.; Chen, H.; Liu, S.; Chen, P.Y.; Weng, T.W.; Hong, M.; Lin, X. Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective. In Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence, Macao, China, 10–16 August 2019; pp. 3961–3967. [Google Scholar]
- Deng, C.; Li, X.; Feng, Z.; Zhang, Z. GARNET: Reduced-Rank Topology Learning for Robust and Scalable Graph Neural Networks. In Proceedings of the First Learning on Graphs Conference, Virtual Event, 9–12 December 2022; PMLR, Proceedings of Machine Learning Research. Volume 198, pp. 3:1–3:23. [Google Scholar]
- Yang, Z.; Cohen, W.; Salakhudinov, R. Revisiting Semi-Supervised Learning with Graph Embeddings. In Proceedings of the 33rd International Conference on Machine Learning, New York City, NY, USA, 19–24 June 2016; PMLR, Proceedings of Machine Learning Research. Volume 48, pp. 40–48. [Google Scholar]
Figure 1.
Overview of the GADD framework. The method consists of three stages: homophily-aware graph sampling for constructing positive and negative graph views from multiple poisoned graphs, online adversarial distillation over heterogeneous student GNNs, and game-inspired adaptive aggregation for confidence- and consistency-aware prediction fusion.
Figure 2.
Mean node-classification accuracy under Meta poisoning across perturbation ratios on Cora, CiteSeer, and PubMed. Shaded bands indicate one standard deviation over repeated runs. In each panel, “Best baseline” denotes the strongest competing defense for that dataset and attack regime, as annotated inside the panel. GADD degrades more gracefully than both the undefended GCN and the strongest competing baseline as perturbation strength increases.
Figure 3.
Mean attacked-node accuracy under targeted Nettack poisoning across perturbation budgets on Cora, CiteSeer, and PubMed. Shaded bands indicate one standard deviation over repeated runs and attacked-target variation. In each panel, “Best baseline” denotes the strongest competing defense for that dataset and attack regime, as annotated inside the panel. GADD maintains the strongest robustness on Cora and PubMed as the targeted perturbation budget increases.
Figure 4.
Ablation study on Cora under Meta-0.25 and Nettack-5.0, where higher accuracy is better. Removing adversarial distillation or adaptive aggregation causes clear robustness loss, while the full GADD model performs best in both attack settings.
Figure 5.
Distribution of graph-level adaptive aggregation weights across student branches on Cora under Meta-0.25. In each boxplot, the box represents the interquartile range, the internal horizontal line denotes the median, the whiskers indicate the non-outlier range, and circles mark outliers.
Table 1.
Dataset statistics used in our experiments.
| Dataset | Nodes | Edges | Classes | Features |
|---|
| Cora | 2485 | 5069 | 7 | 1433 |
| CiteSeer | 2110 | 3668 | 6 | 3703 |
| PubMed | 19,717 | 31,396 | 3 | 500 |
Table 2.
Full defense performance against Meta (mean ± standard deviation accuracy in %). Best results are in bold, and second-best results are underlined. OOM indicates that ProGNN exceeds GPU memory due to its high computational cost.
| Dataset | Ptb. | GCN | Jaccard | ProGNN | SimP-GCN | GARNET | RCNLip | NoisyGNN | GADD |
|---|
| Cora | 0.00 | 83.83 ± 0.71 | 78.86 ± 0.57 | 83.82 ± 0.31 | 81.83 ± 0.68 | 81.83 ± 0.35 | 83.61 ± 0.71 | 78.73 ± 1.03 | 83.89 ± 0.77 |
| 0.05 | 78.93 ± 0.51 | 78.20 ± 0.49 | 79.44 ± 0.59 | 78.01 ± 1.06 | 79.45 ± 0.74 | 78.95 ± 0.38 | 77.77 ± 1.13 | 79.77 ± 0.78 |
| 0.10 | 72.88 ± 0.96 | 77.49 ± 0.91 | 69.56 ± 1.80 | 74.38 ± 2.86 | 79.48 ± 0.61 | 72.80 ± 0.52 | 76.24 ± 1.08 | 79.49 ± 0.69 |
| 0.15 | 67.99 ± 0.90 | 77.07 ± 0.91 | 64.19 ± 1.85 | 72.32 ± 3.51 | 78.59 ± 0.98 | 68.49 ± 0.62 | 76.15 ± 0.88 | 79.10 ± 0.67 |
| 0.20 | 58.11 ± 0.66 | 75.87 ± 1.10 | 54.58 ± 2.75 | 70.09 ± 4.62 | 76.29 ± 0.92 | 58.22 ± 0.55 | 76.28 ± 0.67 | 78.76 ± 0.41 |
| 0.25 | 52.98 ± 1.31 | 75.18 ± 0.46 | 49.30 ± 2.72 | 67.62 ± 6.13 | 74.47 ± 1.28 | 52.76 ± 0.53 | 73.63 ± 0.90 | 78.17 ± 0.69 |
| CiteSeer | 0.00 | 73.21 ± 0.37 | 71.42 ± 0.34 | 72.71 ± 0.57 | 73.58 ± 0.90 | 72.58 ± 0.47 | 72.87 ± 0.24 | 72.31 ± 0.32 | 75.28 ± 0.65 |
| 0.05 | 71.40 ± 1.63 | 71.39 ± 0.77 | 71.16 ± 1.25 | 72.95 ± 0.85 | 71.51 ± 0.33 | 72.07 ± 0.28 | 71.74 ± 0.38 | 74.22 ± 0.28 |
| 0.10 | 69.40 ± 1.01 | 71.45 ± 0.94 | 67.90 ± 0.69 | 72.81 ± 1.19 | 72.52 ± 0.76 | 68.97 ± 0.31 | 72.32 ± 0.25 | 73.39 ± 0.68 |
| 0.15 | 65.59 ± 0.96 | 69.73 ± 1.39 | 64.88 ± 1.30 | 72.39 ± 1.68 | 72.16 ± 0.39 | 65.47 ± 0.36 | 70.60 ± 1.51 | 73.43 ± 0.46 |
| 0.20 | 57.23 ± 1.22 | 69.98 ± 0.86 | 55.30 ± 1.31 | 71.28 ± 1.57 | 63.58 ± 0.76 | 56.23 ± 0.62 | 71.26 ± 0.52 | 72.94 ± 0.97 |
| 0.25 | 57.16 ± 1.49 | 69.34 ± 0.75 | 55.70 ± 1.50 | 72.75 ± 0.62 | 66.07 ± 0.75 | 58.33 ± 0.58 | 69.90 ± 1.15 | 73.62 ± 0.30 |
| PubMed | 0.00 | 86.26 ± 0.09 | 85.74 ± 0.05 | OOM | 86.50 ± 0.08 | 84.83 ± 0.21 | 85.78 ± 0.15 | 84.67 ± 0.07 | 86.60 ± 0.19 |
| 0.05 | 81.32 ± 0.16 | 85.53 ± 0.05 | OOM | 86.22 ± 0.11 | 82.83 ± 0.16 | 81.07 ± 0.14 | 84.47 ± 0.13 | 86.29 ± 0.17 |
| 0.10 | 78.16 ± 0.10 | 85.33 ± 0.03 | OOM | 85.65 ± 0.23 | 82.72 ± 0.31 | 77.74 ± 0.27 | 84.13 ± 0.08 | 86.11 ± 0.26 |
| 0.15 | 74.31 ± 0.18 | 84.81 ± 0.03 | OOM | 85.24 ± 0.22 | 82.95 ± 0.20 | 73.91 ± 0.17 | 83.63 ± 0.16 | 86.07 ± 0.26 |
| 0.20 | 71.11 ± 0.31 | 84.73 ± 0.05 | OOM | 84.74 ± 0.20 | 82.89 ± 0.14 | 71.17 ± 0.16 | 83.52 ± 0.09 | 86.03 ± 0.24 |
| 0.25 | 68.43 ± 0.19 | 84.55 ± 0.04 | OOM | 84.62 ± 0.40 | 82.87 ± 0.18 | 67.71 ± 0.13 | 83.19 ± 0.16 | 85.57 ± 0.19 |
Table 3.
Full defense performance against Nettack (mean ± standard deviation accuracy in %). Best results are in bold, and second-best results are underlined. OOM indicates that ProGNN exceeds GPU memory due to its high computational cost.
| Dataset | Ptb. | GCN | Jaccard | ProGNN | SimP-GCN | GARNET | RCNLip | NoisyGNN | GADD |
|---|
| Cora | 0.0 | 80.96 ± 2.59 | 75.18 ± 1.81 | 84.15 ± 1.57 | 80.60 ± 3.33 | 84.10 ± 0.91 | 81.20 ± 1.81 | 73.86 ± 1.28 | 86.39 ± 2.54 |
| 1.0 | 75.42 ± 1.72 | 73.01 ± 2.29 | 81.69 ± 1.57 | 77.23 ± 2.44 | 81.29 ± 1.43 | 77.11 ± 1.70 | 72.77 ± 1.16 | 81.81 ± 1.65 |
| 2.0 | 68.80 ± 2.23 | 70.96 ± 2.23 | 74.70 ± 1.90 | 73.01 ± 3.42 | 80.72 ± 1.20 | 71.69 ± 1.73 | 70.24 ± 1.40 | 81.69 ± 2.03 |
| 3.0 | 66.75 ± 2.42 | 72.89 ± 2.14 | 70.12 ± 1.32 | 69.16 ± 4.14 | 79.04 ± 1.72 | 66.39 ± 1.75 | 72.29 ± 0.80 | 81.33 ± 1.42 |
| 4.0 | 58.19 ± 2.61 | 67.23 ± 1.11 | 64.34 ± 1.83 | 65.42 ± 4.10 | 75.54 ± 1.87 | 61.93 ± 1.98 | 67.11 ± 1.14 | 80.12 ± 2.14 |
| 5.0 | 52.53 ± 3.22 | 67.71 ± 1.48 | 60.72 ± 2.64 | 58.31 ± 4.59 | 76.27 ± 1.21 | 55.90 ± 1.02 | 65.78 ± 2.79 | 79.69 ± 2.11 |
| CiteSeer | 0.0 | 80.48 ± 2.12 | 79.84 ± 1.99 | 80.63 ± 0.71 | 79.52 ± 2.04 | 83.02 ± 0.73 | 80.79 ± 0.50 | 84.13 ± 1.06 | 85.24 ± 1.07 |
| 1.0 | 77.62 ± 2.04 | 79.37 ± 0.75 | 78.41 ± 0.87 | 79.05 ± 1.46 | 81.75 ± 1.63 | 79.21 ± 0.50 | 82.22 ± 1.25 | 84.92 ± 0.84 |
| 2.0 | 72.54 ± 4.85 | 77.78 ± 2.59 | 74.92 ± 2.61 | 77.14 ± 1.34 | 81.27 ± 0.95 | 77.62 ± 2.04 | 83.33 ± 0.84 | 84.44 ± 0.67 |
| 3.0 | 66.98 ± 2.09 | 77.62 ± 3.03 | 55.56 ± 2.97 | 75.08 ± 3.51 | 80.48 ± 0.73 | 61.27 ± 1.86 | 83.97 ± 1.17 | 84.10 ± 1.01 |
| 4.0 | 57.78 ± 3.90 | 75.24 ± 4.44 | 61.59 ± 6.19 | 70.32 ± 4.49 | 81.59 ± 1.62 | 57.62 ± 1.31 | 83.02 ± 1.07 | 84.08 ± 0.82 |
| 5.0 | 51.43 ± 2.01 | 77.94 ± 3.21 | 48.57 ± 0.87 | 65.24 ± 5.42 | 80.01 ± 1.27 | 50.02 ± 2.62 | 83.17 ± 1.11 | 83.92 ± 0.84 |
| PubMed | 0.0 | 87.90 ± 0.58 | 87.80 ± 0.44 | OOM | 89.25 ± 0.25 | 88.12 ± 0.45 | 87.42 ± 0.58 | 86.24 ± 0.28 | 89.89 ± 0.71 |
| 1.0 | 84.78 ± 0.26 | 87.04 ± 0.17 | OOM | 84.73 ± 0.96 | 87.96 ± 0.55 | 83.66 ± 0.58 | 85.32 ± 0.51 | 89.09 ± 0.62 |
| 2.0 | 81.61 ± 0.42 | 87.47 ± 0.51 | OOM | 80.54 ± 1.01 | 87.58 ± 0.51 | 80.81 ± 0.36 | 85.22 ± 0.63 | 88.92 ± 0.52 |
| 3.0 | 74.95 ± 0.96 | 86.61 ± 0.17 | OOM | 74.73 ± 1.10 | 87.80 ± 0.59 | 78.01 ± 0.64 | 85.00 ± 0.82 | 88.25 ± 0.25 |
| 4.0 | 68.23 ± 1.23 | 85.59 ± 0.94 | OOM | 66.67 ± 1.04 | 85.43 ± 0.85 | 74.84 ± 0.42 | 83.98 ± 0.83 | 87.66 ± 0.31 |
| 5.0 | 62.85 ± 0.64 | 86.56 ± 0.01 | OOM | 67.63 ± 0.83 | 85.32 ± 0.64 | 69.14 ± 0.58 | 83.44 ± 0.79 | 87.21 ± 0.36 |
Table 4.
Student-number and student-type analysis (node classification accuracy in %).
| Setting | Attack | Accuracy |
|---|
| 1 model | Nettack-5.0 (PubMed) | 69.52 |
| 2 models | Nettack-5.0 (PubMed) | 75.38 |
| 3 models | Nettack-5.0 (PubMed) | 87.21 |
| 5 models | Nettack-5.0 (PubMed) | 87.96 |
| 10 models | Nettack-5.0 (PubMed) | 88.22 |
| 3 GCNs | Meta-0.25 (PubMed) | 84.02 |
| 3 GATs | Meta-0.25 (PubMed) | 84.56 |
| 3 GraphSAGE | Meta-0.25 (PubMed) | 85.07 |
| 3 mixed students | Meta-0.25 (PubMed) | 85.57 |
Table 5.
Discriminator study on CiteSeer (node classification accuracy in %).
| Discriminator | Meta-0.25 | Nettack-5.0 | Runtime (s) |
|---|
| MLP | 73.58 | 83.27 | 9.68 |
| GCN | 73.62 | 83.92 | 10.17 |
| GAT | 73.61 | 82.54 | 12.15 |
| GraphSAGE | 73.59 | 82.49 | 11.74 |
| 1 MLP | 73.58 | 83.27 | 9.68 |
| 3 MLPs | 73.60 | 83.89 | 10.17 |
| 1 GCN | 73.62 | 83.92 | 10.15 |
| 3 GCNs | 73.63 | 83.92 | 10.31 |
Table 6.
Joint multi-attack training versus per-attack training on PubMed.
| Category | Metric | Per-Attack Training | Joint Multi-Attack Training |
|---|
| Accuracy (%) | Meta-0.15 | 86.01 | 86.07 |
| Meta-0.25 | 85.64 | 85.57 |
| Nettack-1.0 | 89.12 | 89.09 |
| Nettack-2.0 | 88.89 | 88.92 |
| Nettack-4.0 | 87.64 | 87.66 |
| Runtime (s) | Data processing | | 88.42 |
| Model execution | | 20.11 |
| Total runtime | 211.76 | 108.53 |
Table 7.
Inductive generalization to unseen attacked graphs on PubMed (node classification accuracy in %).
| Graph | Transductive | Inductive |
|---|
| Clean | 86.60 | 86.47 |
| Meta-0.10 | 86.11 | 86.16 |
| Meta-0.20 | 86.03 | 85.23 |
| Nettack-3.0 | 88.25 | 87.44 |
| Nettack-5.0 | 87.21 | 86.52 |
Table 8.
Hyperparameter sensitivity analysis under different dataset–attack settings.
| Setup | Cora/Clean | CiteSeer/Meta-0.2 | PubMed/Nettack-3.0 |
|---|
| Setup 1 | | | |
| Setup 2 | | | |
| Setup 3 | | | |
Table 9.
Defense performance on ogbn-arxiv in terms of node classification accuracy (%). Bold values indicate the best performance in each column.
| Method | Clean | PGD Attack | Random Perturbation |
|---|
| 30% | 50% | 30% | 50% |
|---|
| GCN | | | | | |
| Jaccard | | | | | |
| ProGNN | OOM | OOM | OOM | OOM | OOM |
| SimP-GCN | | | | | |
| GARNET | | | | | |
| RCNLip | | | | | |
| NoisyGNN | | | | | |
| GADD | | | | | |
Table 10.
GPU memory usage on ogbn-arxiv.
| Method | GPU Memory (MB) |
|---|
| GCN | |
| Jaccard | |
| ProGNN | OOM |
| SimP-GCN | |
| GARNET | |
| RCNLip | |
| NoisyGNN | |
| GADD | |
| Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |