acceptodds
Under review as a conference paper at ICLR 2027

GraphSieve: Graph Purification via Attack-Agnostic Calibration across Perturbation Severities

Abstract

Structural poisoning attacks degrade node classification in graph neural networks by editing edges before training. Purification defenses respond by editing the observed graph, and their test accuracy depends on both the editing rule and the procedure that selects its hyperparameters. We study that selection when it must be made without access to the evaluation attack instances. We introduce GraphSieve, a purification defense for homophilous graphs that prunes low-similarity edges and adds high-similarity absent edges. Its attack-agnostic calibration selects configurations by mean validation accuracy over a trusted clean graph and label-blind random perturbations at prespecified severities. The same procedure calibrates GraphSieve and the purification baselines, separating calibration from graph editing. A prespecified evaluation on three citation graphs identifies gains in attacked-graph test accuracy over the undefended GCN, RGCN, and GCN-SVD, with no statistically significant loss to RGCN or GCN-SVD. An attack that adapts to the published editing criterion leaves GraphSieve ahead of the undefended GCN in 20 of 36 cells, with no loss. Against equally calibrated GCN-Jaccard, which applies the pruning rule alone, the evaluation finds both gains and losses. In exploratory ablations, calibration also lifts the baselines, raising GCN-Jaccard's mean attacked-graph accuracy over clean-only tuning by +0.44 and +4.18 percentage points on the fresh and reproduction profiles, and the benefit extends to GCN-SVD and GraphSieve. Single-severity comparisons show that a selection rule must be reported with its severity distribution. A follow-up replication, run after the prespecified evaluation with new attack graphs and model seeds, reproduces the augmentation gains in the Cora deletion-Metattack conditions, where calibration disables pruning. The gains are +1.21 and +0.93 percentage points over calibrated GCN-Jaccard at deletion budgets of 15 and 25 percent, respectively. These gains identify a replicated use case for augmentation rather than a general benefit from edge addition. Recovery diagnostics show that most added edges had never been deleted. These results motivate a common calibration protocol for purification defenses and distinguish predictive augmentation from reconstruction of the original topology.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.