arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

核复杂度边清洗:针对结构图攻击的无训练防御

Kernel-Complexity Edge Sanitization for Training-Free Defense against Structural Graph Attacks

Yaning Jia, Shenyang Deng, Yaoqing Yang, Chiyu Ma, Wenxuan Xu, Soroush Vosoughi

arXiv 2609.09698首次发表:更新:

发表机构

Dartmouth College(达特茅斯学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对图神经网络易受结构攻击的问题,提出无训练、模型无关的核复杂度边清洗(KCES)框架,基于图核复杂度量化边影响并剪除高KC边,实验证明其高效且优于现有防御。

AI 中文摘要

图神经网络(GNNs)在众多应用中取得了显著成功,但它们仍然极易受到恶意扰动图结构的对抗性攻击。现有防御方法往往缺乏严格的理论基础,依赖于针对特定攻击的启发式方法,或者需要诸如对抗训练等代价高昂的重新训练过程。为解决这些局限性,我们提出了核复杂度边清洗(KCES),一种用于防御结构攻击的无训练且模型无关的框架。KCES建立在图核复杂度(GKC)之上,GKC是一个源自图Gram矩阵的原理性度量,该矩阵出现在GNN测试误差的泛化上界中。基于这一上界,我们定义了一个边特定的KC分数,通过其引起的GKC变化来量化每条边的结构影响。KCES随后识别并剪除高KC边,这些边在结构攻击下经验上富含对抗性扰动,以减轻其有害影响。KCES计算高效且可扩展,作为一个轻量级预处理步骤运行,无需重新训练,并能与现有防御无缝集成。大量实验表明,KCES在各种攻击设置下持续优于代表性的稳健基线,并能有效扩展到大型图。在理论分析和广泛实证验证的支持下,KCES为保护GNNs提供了一个原理性且高效的框架。我们的代码可在以下网址获取:此https URL。

英文摘要

Graph Neural Networks (GNNs) have achieved remarkable success across diverse applications, yet they remain highly vulnerable to adversarial attacks that maliciously perturb graph structure. Existing defenses often lack rigorous theoretical grounding, rely on attack-specific heuristics, or require costly retraining procedures such as adversarial training. To address these limitations, we propose Kernel-Complexity Edge Sanitization (KCES), a training-free and model-agnostic framework for defending against structural attacks. KCES is built upon Graph Kernel Complexity (GKC), a principled metric derived from the graph Gram matrix that appears in a generalization upper bound on the GNN test error. From this bound, we define an edge-specific KC score that quantifies each edge's structural influence via its induced change in GKC. KCES then identifies and prunes high-KC edges, which are empirically enriched with adversarial perturbations under structural attacks, to mitigate their harmful impact. Computationally efficient and scalable, KCES operates as a lightweight preprocessing step without retraining and can be seamlessly integrated with existing defenses. Extensive experiments demonstrate that KCES consistently outperforms representative robust baselines across diverse attack settings and scales effectively to large graphs. Supported by theoretical analysis and extensive empirical validation, KCES provides a principled and efficient framework for securing GNNs. Our code is available at https://github.com/karpning/KCScore.

Comments12 pages. Accepted at the 35th ACM International Conference on Information and Knowledge Management (CIKM 2026)

DOI:10.1145/3799682.3841029

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑