Pith. sign in

REVIEW 4 cited by

Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1906.04214 v3 pith:SGQFNSHC submitted 2019-06-10 cs.LG cs.CRcs.SIstat.ML

classification cs.LGcs.CRcs.SIstat.ML
keywords attackgraphgnnsadversarialclassificationnetworksneuraldata
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Graph neural networks (GNNs) which apply the deep neural networks to graph data have achieved significant performance for the task of semi-supervised node classification. However, only few work has addressed the adversarial robustness of GNNs. In this paper, we first present a novel gradient-based attack method that facilitates the difficulty of tackling discrete graph data. When comparing to current adversarial attacks on GNNs, the results show that by only perturbing a small number of edge perturbations, including addition and deletion, our optimization-based attack can lead to a noticeable decrease in classification performance. Moreover, leveraging our gradient-based attack, we propose the first optimization-based adversarial training for GNNs. Our method yields higher robustness against both different gradient based and greedy attack methods without sacrificing classification accuracy on original graph.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Attacking Graph Foundation Models Through Their Shared Representation

    cs.AI 2026-07 conditional novelty 6.0 of 10

    A shared representation layer in graph foundation models is a distinct attack surface: input edits break three of six models and one spectral tokenizer is uniquely fragile.

  2. EvA: Evolutionary Attacks on Graphs

    cs.LG 2025-07 conditional novelty 6.0 of 10

    EvA, an evolutionary search over edge flips, outperforms gradient-based attacks on GNNs and extends to breaking conformal and certificate guarantees.

  3. Robust Learning on Noisy Graphs via Latent Space Constraints with External Knowledge

    cs.LG 2025-07 conditional novelty 6.0 of 10

    LSC-GNN uses a clean external graph to regularize the latent representations of a noisy target graph, improving node classification under moderate edge noise.

  4. Unifying Adversarial Perturbation for Graph Neural Networks

    cs.LG 2025-08 reject novelty 3.0 of 10

    Adding perturbations directly to every hidden embedding of a GNN is claimed to subsume existing feature-, edge-, and weight-perturbation defenses, but the claim rests on simplifications that the experiments do not act...

Pith tools