Kernel-Complexity Edge Sanitization (KCES), a training-free and model-agnostic framework for defending against structural attacks, provides a principled and efficient framework for securing GNNs.
Abstract
Graph Neural Networks (GNNs) have achieved remarkable success across diverse applications, yet they remain highly vulnerable to adversarial attacks that maliciously perturb graph structure. Existing defenses often lack rigorous theoretical grounding, rely on attack-specific heuristics, or require costly retraining procedures such as adversarial training. To address these limitations, we propose Kernel-Complexity Edge Sanitization (KCES), a training-free and model-agnostic framework for defending against structural attacks. KCES is built upon Graph Kernel Complexity (GKC), a principled metric derived from the graph Gram matrix that appears in a generalization upper bound on the GNN test error. From this bound, we define an edge-specific KC score that quantifies each edge's structural influence via its induced change in GKC. KCES then identifies and prunes high-KC edges, which are empirically enriched with adversarial perturbations under structural attacks, to mitigate their harmful impact. Computationally efficient and scalable, KCES operates as a lightweight preprocessing step without retraining and can be seamlessly integrated with existing defenses. Extensive experiments demonstrate that KCES consistently outperforms representative robust baselines across diverse attack settings and scales effectively to large graphs. Supported by theoretical analysis and extensive empirical validation, KCES provides a principled and efficient framework for securing GNNs. Our code is available at https://github.com/karpning/KCScore.
An active paradigm that repurposes the offensive tactic of node injection into a structural defense, ANIE significantly enhances GNN robustness, outperforming state-of-the-art defenses by up to 2× in classification accuracy under poisoning and evasion attacks.
Xiangchao Wen, Zhen Liu, Yunfei Liu· Proceedings of the 32nd ACM...· 0 citations
The proposed Collateral Damage Constrained Graph Backdoor Attack (CDCA) combines neighborhood-aware target node selection with a self-constrained trigger generation strategy to suppress trigger-induced propagation by enforcing prediction consistency on clean K -hop neighboring nodes.
Di Jin, Ze-Chuan Zhang, Bing-Dao Feng et al.· Proceedings of the Thirty-Fi...· 0 citations
Dagger, a novel two-phase decoupling-based attack framework that consistently outperforms state-of-the-art GNN stealing attacks, achieving up to 18.16\% higher fidelity while only utilizing 12.23$\times$ fewer queries than the strongest baseline.
This work designs a dual-consistency graph augmentation method that enriches the graph topology to mitigate structural vulnerabilities and presents an adversarial masked autoen-coder to mitigate model overfitting to the perturbed graph.
Qi-Qi Zhang, Chuan-Jin Liu, Gen Liu et al.· Proceedings of the Thirty-Fi...· 0 citations
This work proposes a transferable graph purification scheme, named ProGAP, to bridge adversarial defense knowledge via vulnerability-aware graph prompt learning, and achieves 1%-9% improvement, and reduces the time consumption by up to 2.2x.
Shuo-Min Xue, Jing-Yuan Li, Ju Jia et al.· 0 citations
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduSep 29, 2026
Professor Sherry Turkle’s new book, “Artificial Intimacy,” offers a withering critique of chatbots and the antisocial dynamics she believes they encourage.