arXiv:2511.00083cs.LGcs.AI2025-11

通过固定点迭代提升图卷积网络抗攻击能力

Fixed-point graph convolutional networks against adversarial attacks

  • 利用固定点迭代捕获高阶邻域信息,无需额外开销
  • 在多个基准数据集上对对抗攻击保持鲁棒性
  • 适合关注图神经网络安全性的研究人员

对抗攻击严重威胁图神经网络的完整性与性能,尤其在图结构和节点特征易受操纵的任务中。本文提出一种新模型——固定点迭代图卷积网络(Fix-GCN),通过有效捕捉图中更高阶的节点邻域信息,在不增加内存或计算复杂度的前提下实现对对抗扰动的鲁棒性。具体而言,我们引入一种通用的谱调制滤波器,并基于固定点迭代推导出模型的特征传播规则。与依赖附加设计元素的传统防御机制不同,所提出的图滤波器提供了一种灵活的通带过滤方式,可选择性地衰减高频成分,同时保留图信号中的低频结构信息。通过迭代更新节点表示,该模型提供了一个灵活高效的框架,可在减轻对抗操纵影响的同时保留关键图信息。我们在多个基准图数据集上进行了广泛实验,验证了该模型的有效性,展示了其对对抗攻击的强大抵抗力。

原文摘要 · Abstract (English)

Adversarial attacks present a significant risk to the integrity and performance of graph neural networks, particularly in tasks where graph structure and node features are vulnerable to manipulation. In this paper, we present a novel model, called fixed-point iterative graph convolutional network (Fix-GCN), which achieves robustness against adversarial perturbations by effectively capturing higher-order node neighborhood information in the graph without additional memory or computational complexity. Specifically, we introduce a versatile spectral modulation filter and derive the feature propagation rule of our model using fixed-point iteration. Unlike traditional defense mechanisms that rely on additional design elements to counteract attacks, the proposed graph filter provides a flexible-pass filtering approach, allowing it to selectively attenuate high-frequency components while preserving low-frequency structural information in the graph signal. By iteratively updating node representations, our model offers a flexible and efficient framework for preserving essential graph information while mitigating the impact of adversarial manipulation. We demonstrate the effectiveness of the proposed model through extensive experiments on various benchmark graph datasets, showcasing its resilience against adversarial attacks.

图神经网络对抗攻击鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。