针对图神经网络的抗干扰能力,提出分路自适应融合新方法。
Adaptive Branch Specialization in Spectral-Spatial Graph Neural Networks for Certified Robustness
- 分路分别防御边翻转和特征扰动,针对性增强鲁棒性。
- 在真实数据集上实现最高分类准确率与更优的认证鲁棒性。
- 动态路由机制让每个节点自动选择更可靠的分支预测结果。
近期图神经网络采用谱-空间架构以提升表征能力,但对认证鲁棒性的关注仍不足,尤其缺乏训练策略与理论依据。本文明确对各分支进行专业化设计:谱支路训练以抵御l0边翻转并捕捉同质结构,空间支路则针对linf特征扰动和异质模式。通过上下文感知门控网络动态融合两路表示,按需将每节点预测路由至更可靠分支。该方案采用分支特异性内最大化(结构攻击与特征攻击)与统一对齐目标。理论证明:(i) 门控机制超越1-WL表达能力,(ii) 谱-空间频率偏差,(iii) 可提供认证鲁棒性且存在权衡。实验表明,SpecSphere在真实基准上达到最先进的节点分类精度,并实现更紧的认证鲁棒性。
原文摘要 · Abstract (English)
Recent Graph Neural Networks (GNNs) combine spectral-spatial architectures for enhanced representation learning. However, limited attention has been paid to certified robustness, particularly regarding training strategies and underlying rationale. In this paper, we explicitly specialize each branch: the spectral network is trained to withstand l0 edge flips and capture homophilic structures, while the spatial part is designed to resist linf feature perturbations and heterophilic patterns. A context-aware gating network adaptively fuses the two representations, dynamically routing each node's prediction to the more reliable branch. This specialized adversarial training scheme uses branch-specific inner maximization (structure vs feature attacks) and a unified alignment objective. We provide theoretical guarantees: (i) expressivity of the gating mechanism beyond 1-WL, (ii) spectral-spatial frequency bias, and (iii) certified robustness with trade-off. Empirically, SpecSphere attains state-of-the-art node classification accuracy and offers tighter certified robustness on real-world benchmarks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。