• 中国计算机学会会刊
  • 中国科技核心期刊
  • 中文核心期刊

Computer Engineering & Science ›› 2025, Vol. 47 ›› Issue (3): 434-447.

• Computer Network and Znformation Security • Previous Articles     Next Articles

RCGNN: Robustness certification for graph neural networks under graph injection attacks

WANG Yuheng,LIU Qiang,WU Xiaojie   

  1. (College of Computer Science and Technology,National University of Defense Technology,Changsha 410073,China)
  • Received:2024-07-04 Revised:2024-08-29 Online:2025-03-25 Published:2025-04-01

Abstract: In recent years, graph neural network (GNN) has been widely applied in fields such as anomaly detection, recommendation systems, and biomedicine. Despite their excellent performance in specific tasks, many studies have shown that GNN is susceptible to adversarial perturbations. To mitigate the vulnerability of GNN to adversarial examples, some researchers have proposed robustness certification defense techniques against graph modification attacks, aiming to enhance the ability of GNN models to resist malicious perturbations in this scenario. However, the robustness analysis of node classification models in the context of graph injection attack (GIA) has not been widely explored. Facing this challenge, we extend the sparse-aware randomized smoothing mechanism and design a robustness certification method, RCGNN, based on randomized smoothing for the GIA scenario. To align the noise perturbation space with GIA attack behaviors, we pre-inject malicious nodes and restrict perturbations near these nodes, and improve the noise perturbation function to increase the certification ratio and expand the maximum certification radius. Comparative experiments on real datasets demonstrate that RCGNN can achieve robustness certification for node classification tasks in the GIA scenario, and it outperforms the sparse-aware randomized smoothing mechanism in terms of certification ratio and maximum certification radius.

Key words: graph neural network (GNN), node classification, randomized smoothing, graph injection attack (GIA), robustness certification