Adversarially Robust Graph Neural Networks via Adaptive Multi-Frequency Filtering
Abstract
Graph Neural Networks (GNNs) have achieved remarkable success in various graph learning tasks. However, their vulnerability to adversarial attacks limits their trustworthy deployment in real-world applications. In recent years, spectral-based defense methods have provided a new perspective for enhancing the adversarial robustness of GNNs. However, existing methods typically adopt a single, fixed frequency response, which makes them difficult to adapt to spectral variations induced by adversarial attacks. Moreover, adversarial perturbations are often localized, whereas existing spectral filtering methods mainly rely on global spectral responses and lack the capability to capture localized graph variations, which compromises their adversarial robustness. To address these issues, we propose AdaMF, a dual-perspective robustness framework that captures localized graph variations and adaptively adjusts the spectral responses. Specifically, we construct learnable low-, high-, and mid-frequency filter bases with adaptive weighting coefficients to characterize diverse spectral shifts caused by adversarial perturbations, enabling flexible global spectral adaptation. Furthermore, we introduce framelet-based multi-resolution filtering to learn representations across different graph scales, enabling the model to preserve local structural details and global semantic information. Additionally, we employ prototype contrastive learning guided by pseudo-labels to further enhance the robustness of node representations. Extensive experiments on real-world datasets demonstrate that the proposed method achieves superior robustness against various adversarial attacks.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.