Skip to main navigation Skip to search Skip to main content

Enhancing GCN robustness against structural attacks via adaptive spectrum filtering

Jin Fan, Zheyu Wang, Zehao Wang, Jiajun Yang, Huifeng Wu*, Jia Wu

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

Graph Convolutional Networks (GCNs) are currently the most widely used method for processing graph-structured data. However, recent research has revealed that the performance of GCNs dramatically decreases when confronted with adversarial attacks. This severely hinders their application in security-critical domains. Therefore, the development of GCNs that are resilient to adversarial attacks has emerged as a prominent research focus. Despite this, most current defense models with complex network architectures and optimization objectives are typically designed based on specific feature assumptions or attack manifestations, and do not enhance the inherent robustness of GCNs. They also overlook the changes induced by perturbations of varying intensities and the difference in attack phenomenon across different datasets. In response to this, we have delved into the impact of adversarial attacks on the spectrum, and propose an effective adaptive robust spectrum filter GCN (ASF-GCN). This approach enhances the robustness of GCN models through adaptive filtering without introducing additional conditional assumptions. We theoretically analyze that graphs have different robust frequency intervals under different conditions, validating the necessity of adaptive filtering. Additionally, we elucidate the role of degree distribution and maximum eigenvalue in adaptation. Extensive experiments on real-world graphs reveal that our model surpasses other defense models in overall performance.

Original languageEnglish
Pages (from-to)10668-10682
Number of pages15
JournalIEEE Transactions on Information Forensics and Security
Volume20
DOIs
Publication statusPublished - 2025

Fingerprint

Dive into the research topics of 'Enhancing GCN robustness against structural attacks via adaptive spectrum filtering'. Together they form a unique fingerprint.

Cite this