A journal of IEEE and CAA , publishes high-quality papers in English on original theoretical/experimental research and development in all areas of automation

IEEE/CAA Journal of Automatica Sinica

  • JCR Impact Factor: 18.3, Top 1 (SCI Q1)
    CiteScore: 28.2, Top 1% (Q1)
    Google Scholar h5-index: 95, TOP 5
Turn off MathJax
Article Contents
Z. Wang, J. Li, Z. Ye, L. Lin, M. Wang, and G. Wang, “Attribute-augmented PPR meets self-loops: Simple yet effective defending graph neural networks,” IEEE/CAA J. Autom. Sinica, early access, 2026. doi: 10.1109/JAS.2026.125990
Citation: Z. Wang, J. Li, Z. Ye, L. Lin, M. Wang, and G. Wang, “Attribute-augmented PPR meets self-loops: Simple yet effective defending graph neural networks,” IEEE/CAA J. Autom. Sinica, early access, 2026. doi: 10.1109/JAS.2026.125990

Attribute-Augmented PPR Meets Self-Loops: Simple Yet Effective Defending Graph Neural Networks

doi: 10.1109/JAS.2026.125990
Funds:  This work was supported by the National Natural Science Foundation of China (62402399), Natural Science Foundation of Chongqing, China (CSTB2025NSCQ-GPX1268 and CSTB2022NSCQ-MSX1588), and the Science and Technology Research Program of Chongqing Municipal Education Commission (KJQN202500647 and KJQN202400657)
More Information
  • Graph Neural Networks (GNNs) are effective in processing graph-structured data but are also known to be vulnerable to adversarial attacks. Limitations of existing defense methodologies include a suboptimal approach to edge and node weight assignment, as such methods generally focus on the graph’s topological structure or node attributes. This imbalance can lead to inaccurate assessments of the importance of neighboring nodes, especially those targeted by attacks. We posit that the model should diminish the influence of insignificant and contaminated neighboring nodes on graph representation learning, thereby mitigating the adverse effects of compromised neighbors. Hence, we propose a versatile GNN adversarial defense framework by combining a novel attribute-augmented Personalized PageRank (PPR) with an adaptive self-loop weight adjustment mechanism, coined GPROP, to defend against adversarial attacks. Specifically, the attribute-augmented PPR helps compute the node similarity more accurately based on global semantics, by considering multi-hop graph topology and node attributes. According to the similarity scores, GPROP assigns corresponding weights to edges and simultaneously prunes insignificant ones. When iteratively aggregating the neighbor information, the proposed self-loop mechanism dynamically adjusts the weight ratio of neighboring nodes and the nodes themselves based on the node’s degree. This strategy reduces the influence of neighboring nodes that may introduce unreliable or harmful information. Moreover, GPROP is model-agnostic and can be readily embedded into different GNN backbones, leading to a substantial improvement in resistance to adversarial perturbations. Experimental results across multiple benchmark datasets show that our proposal consistently outperforms existing approaches, providing enhanced resilience and accuracy.

     

  • loading
  • [1]
    J. Li, R. Zheng, H. Feng, M. Li, and X. Zhuang, “Permutation equivariant graph framelets for heterophilous graph learning,” IEEE Trans. Neural Networks Learn. Syst., vol. 35, no. 9, pp. 11634–11648, Sep. 2024. doi: 10.1109/TNNLS.2024.3370918
    [2]
    T. Liu, L. Lin, Y. Yu, X. Ou, Y. Zhang, Z. Ye, and T. Jia, “CoATA: Effective co-augmentation of topology and attribute for graph neural networks,” in Proc. Int. Conf. Multimedia Retrieval, Chicago, USA, 2025, pp. 851−860.
    [3]
    Z. Ye, L. Lin, J. Li, T. Liu, and Z. Wang, “GDBA: Defending graph neural networks via attribute debiasing,” Expert Syst. Appl., vol. 296, Art. no. 128983, Jan. 2026. doi: 10.1016/j.eswa.2025.128983
    [4]
    L. Lin and X. Luo, “Dual channel graph convolutional networks via personalized PageRank,” IEEE/CAA J. Autom. Sinica, vol. 13, no. 1, pp. 221–223, Jan. 2026. doi: 10.1109/JAS.2025.125492
    [5]
    M. Li, A. Micheli, Y. G. Wang, S. Pan, P. Lió, G. S. Gnecco, and M. Sanguineti, “Guest editorial: Deep neural networks for graphs: Theory, models, algorithms, and applications,” IEEE Trans. Neural Networks Learn. Syst., vol. 35, no. 4, pp. 4367–4372, Apr. 2024. doi: 10.1109/tnnls.2024.3371592
    [6]
    J. Chen, Y. Yuan, and X. Luo, “SDGNN: Symmetry-preserving dual-stream graph neural networks,” IEEE/CAA J. Autom. Sinica, vol. 11, no. 7, pp. 1717–1719, Jul. 2024. doi: 10.1109/JAS.2024.124410
    [7]
    X. Wang, S. Zhao, L. Guo, L. Zhu, C. Cui, and L. Xu, “GraphCA: Learning from graph counterfactual augmentation for knowledge tracing,” IEEE/CAA J. Autom. Sinica, vol. 10, no. 11, pp. 2108–2123, Nov. 2023. doi: 10.1109/JAS.2023.123678
    [8]
    L. Bai, L. Cui, Y. Wang, M. Li, J. Li, P. S. Yu, and E. R. Hancock, “HAQJSK: Hierarchical-aligned quantum Jensen-Shannon kernels for graph classification,” IEEE Trans. Knowl. Data Eng., vol. 36, no. 11, pp. 6370–6384, Nov. 2024. doi: 10.1109/TKDE.2024.3389966
    [9]
    Y. Yu, L. Lin, Q. Liu, Z. Wang, X. Ou, and T. Jia, “GSD-GNN: Generalizable and scalable algorithms for decoupled graph neural networks,” in Proc. Int. Conf. Multimedia Retrieval, Phuket, Thailand, 2024, pp. 64−72.
    [10]
    J. Gilmer, S. S. Schoenholz, P. F. Riley, O. Vinyals, and G. E. Dahl, “Neural message passing for quantum chemistry,” in Proc. 34th Int. Conf. Machine Learning, Sydney, Australia, 2017, pp. 1263−1272.
    [11]
    H. Huang, H. Shen, and Z. Meng, “Community-based influence maximization in attributed networks,” Appl. Intell., vol. 50, no. 2, pp. 354–364, Feb. 2020. doi: 10.1007/s10489-019-01529-x
    [12]
    H. Zhang, L. Xu, L. Lin, and X. Wang, “De-anonymizing social networks with edge-neighborhood graph attacks,” in Proc. First Int. Conf. Security and Privacy in Digital Economy, Quzhou, China, 2020, pp. 726−737.
    [13]
    X. Yue, Z. Wang, J. Huang, S. Parthasarathy, S. Moosavinasab, Y. Huang, S. M. Lin, W. Zhang, P. Zhang, and H. Sun, “Graph embedding on biomedical networks: Methods, applications and evaluations,” Bioinformatics, vol. 36, no. 4, pp. 1241–1251, Feb. 2020. doi: 10.1093/bioinformatics/btz718
    [14]
    X. Zhang and M. Zitnik, “GNNGuard: Defending graph neural networks against adversarial attacks,” in Proc. 34th Int. Conf. Neural Information Processing System, Vancouver, Canada, 2020, Art. no. 777.
    [15]
    D. Zhu, Z. Zhang, P. Cui, and W. Zhu, “Robust graph convolutional networks against adversarial attacks,” in Proc. 25th ACM SIGKDD Int. Conf. Knowledge Discovery & Data Mining, Anchorage, USA, 2019, pp. 1399−1407.
    [16]
    A. Liu, B. Li, T. Li, P. Zhou, and R. Wang, “AN-GCN: An anonymous graph convolutional network against edge-perturbing attacks,” IEEE Trans. Neural Networks Learn. Syst., vol. 35, no. 1, pp. 88–102, Jan. 2024. doi: 10.1109/TNNLS.2022.3172296
    [17]
    F. Liu, J. Tian, L. Miranda-Moreno, and L. Sun, “Adversarial danger identification on temporally dynamic graphs,” IEEE Trans. Neural Networks Learn. Syst., vol. 35, no. 4, pp. 4744–4755, Apr. 2024. doi: 10.1109/TNNLS.2023.3252175
    [18]
    Y. Rong, W. Huang, T. Xu, and J. Huang, “DropEdge: Towards deep graph convolutional networks on node classification,” in Proc. 8th Int. Conf. Learning Representations, Addis Ababa, Ethiopia, 2020.
    [19]
    C. Deng, X. Li, Z. Feng, and Z. Zhang, “GARNET: Reduced-rank topology learning for robust and scalable graph neural networks,” in Proc. First Learning on Graphs Conf., 2022, pp. 198: 3: 1−3: 23.
    [20]
    Z. Gao, S. Bhattacharya, L. Zhang, R. S. Blum, A. Ribeiro, and B. M. Sadler, “Training robust graph neural networks with topology adaptive edge dropping,” arXiv preprint arXiv: 2106.02892, 2021.
    [21]
    H. Jo, F. Bu, and K. Shin, “Robust graph clustering via meta weighting for noisy graphs,” in Proc. 32nd ACM Int. Conf. Information and Knowledge Management, Birmingham, UK, 2023, pp. 1035−1044.
    [22]
    Z. Wu, S. Pan, F. Chen, G. Long, C. Zhang, and P. S. Yu, “A comprehensive survey on graph neural networks,” IEEE Trans. Neural Networks Learn. Syst., vol. 32, no. 1, pp. 4–24, Jan. 2021. doi: 10.1109/TNNLS.2020.2978386
    [23]
    P. A. Lofgren, S. Banerjee, A. Goel, and S. Comandur, “FAST-PPR: Scaling personalized pagerank estimation for large graphs,” in Proc. 20th ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining, New York, USA, 2014, pp. 1436−1445.
    [24]
    P. Lofgren and A. Goel, “Personalized PageRank to a target node,” arXiv preprint arXiv: 1304.4658, 2013.
    [25]
    L. Lin, Y. Yu, Z. Wang, Z. Wang, Y. Zhao, J. Zhao, and T. Jia, “PSNE: Efficient spectral sparsification algorithms for scaling network embedding,” in Proc. 33rd ACM Int. Conf. Information and Knowledge Management, Boise, USA, 2024, pp. 1420−1429.
    [26]
    J. Zhou, M. Liao, R. H. Li, L. Lin, and G. Wang, “One index for all: Towards efficient personalized PageRank computation for every damping factor,” Proc. ACM Manag. Data, vol. 3, no. 4, Art. no. 258, Sep. 2025. doi: 10.1145/3749176
    [27]
    X. Ou, L. Lin, Z. Wang, P. Yuan, and R. H. Li, “Scalable similarity search over large attributed bipartite graphs,” IEEE Trans. Knowl. Data Eng., vol. 38, no. 5, pp. 3080–3094, May 2026. doi: 10.1109/TKDE.2026.3676380
    [28]
    Y. Yang, R. H. Li, M. Liao, L. Lin, and G. Wang, “Scaling up graph propagation computation on large graphs: A local Chebyshev approximation approach,” arXiv preprint arXiv: 2412.10789, 2024.
    [29]
    L. Page, S. Brin, R. Motwani, and T. Winograd, “The PageRank citation ranking: Bringing order to the web,” Stanford Digital Library Technologies Project, 1998.
    [30]
    D. Zűgner and S. Gűnnemann, “Adversarial attacks on graph neural networks via meta learning,” in Proc. 7th Int. Conf. Learning Representations, New Orleans, USA, 2019.
    [31]
    D. Zűgner, A. Akbarnejad, and S. Gűnnemann, “Adversarial attacks on neural networks for graph data,” in Proc. Twenty-Eighth Int. Joint Conf. Artificial Intelligence, Macao, China, 2019, pp. 6246−6250.
    [32]
    M. Waniek, T. P. Michalak, M. J. Wooldridge, and T. Rahwan, “Hiding individuals and communities in a social network,” Nat. Human Behav., vol. 2, no. 2, pp. 139–147, Jan. 2018. doi: 10.1038/s41562-017-0290-3
    [33]
    H. Dai, H. Li, T. Tian, X. Huang, L. Wang, J. Zhu, and L. Song, “Adversarial attack on graph structured data,” in Proc. 35th Int. Conf. Machine Learning, Stockholm, Sweden, 2018, pp. 1115−1124.
    [34]
    K. Xu, H. Chen, S. Liu, P. Y. Chen, T. W. Weng, M. Hong, and X. Lin, “Topology attack and defense for graph neural networks: An optimization perspective,” in Proc. Twenty-Eighth Int. Joint Conf. Artificial Intelligence, Macao, China, 2019, pp. 3961−3967.
    [35]
    F. Feng, X. He, J. Tang, and T. S. Chua, “Graph adversarial training: Dynamically regularizing based on graph structure,” IEEE Trans. Knowl. Data Eng., vol. 33, no. 6, pp. 2493–2504, Jun. 2021. doi: 10.1109/TKDE.2019.2957786
    [36]
    Y. Jia, D. Zou, H. Wang, and H. Jin, “Enhancing node-level adversarial defenses by Lipschitz regularization of graph neural networks,” in Proc. 29th ACM SIGKDD Conf. Knowledge Discovery and Data Mining, Long Beach, USA, 2023, pp. 951−963.
    [37]
    X. Tang, Y. Li, Y. Sun, H. Yao, P. Mitra, and S. Wang, “Transferring robustness for graph neural network against poisoning attacks,” in Proc. 13th Int. Conf. Web Search and Data Mining, Houston, USA, 2020, pp. 600−608.
    [38]
    N. Entezari, S. A. Al-Sayouri, A. Darvishzadeh, and E. E. Papalexakis, “All you need is low (rank): Defending against adversarial attacks on graphs,” in Proc. 13th Int. Conf. Web Search and Data Mining, Houston, USA, 2020, pp. 169−177.
    [39]
    W. Jin, Y. Ma, X. Liu, X. Tang, S. Wang, and J. Tang, “Graph structure learning for robust graph neural networks,” in Proc. 26th ACM SIGKDD Int. Conf. Knowledge Discovery & Data Mining, 2020, pp. 66−74.
    [40]
    S. Ennadir, Y. Abbahaddou, J. F. Lutzeyer, M. Vazirgiannis, and H. Bostrőm, “A simple and yet fairly effective defense for graph neural networks,” in Proc. Thirty-Eighth AAAI Conf. Artificial Intelligence, 2024, pp. 21063−21071.
    [41]
    C. Jinyin, H. Guohan, Z. Dunjie, Z. Xuhong, and J. Shouling, “GRD-GNN: Graph reconstruction defense for graph neural network,” J. Comput. Res. Dev., vol. 58, No. 5, pp. 1075−1091, 2021.
    [42]
    Y. Abbahaddou, S. Ennadir, J. F. Lutzeyer, M. Vazirgiannis, and H. Bostrőm, “Bounding the expected robustness of graph neural networks subject to node feature attacks,” in Proc. Twelfth Int. Conf. Learning Representations, Vienna, Austria, 2024.
    [43]
    P. Velickovic, G. Cucurull, A. Casanova, A. Romero, P. Liò, and Y. Bengio, “Graph attention networks,” in Proc. 6th Int. Conf. Learning Representations, Vancouver, Canada, 2018.
    [44]
    H. Wu, C. Wang, Y. Tyshetskiy, A. Docherty, K. Lu, and L. Zhu, “Adversarial examples for graph data: Deep insights into attack and defense,” in Proc. Twenty-Eighth Int. Joint Conf. Artificial Intelligence, Macao, China, 2019, pp. 4816−4823.
    [45]
    W. Jin, T. Derr, Y. Wang, Y. Ma, Z. Liu, and J. Tang, “Node similarity preserving graph convolutional networks,” in Proc. 14th ACM Int. Conf. Web Search and Data Mining, 2021, pp. 148−156.
    [46]
    L. Chen, J. Li, Q. Peng, Y. Liu, Z. Zheng, and C. Yang, “Understanding structural vulnerability in graph convolutional networks,” in Proc. Thirtieth Int. Joint Conf. Artificial Intelligence, Montreal, Canada, 2021, pp. 2249−2255.
    [47]
    Y. Meng, R. Li, L. Lin, X. Li, and G. Wang, “Topology-preserving graph coarsening: An elementary collapse-based approach,” Proc. VLDB Endow., vol. 17, no. 13, pp. 4760–4772, Sep. 2024. doi: 10.14778/3704965.3704981
    [48]
    W. L. Hamilton, Z. Ying, and J. Leskovec, “Inductive representation learning on large graphs,” in Proc. 31st Int. Conf. Neural Information Processing Systems, Long Beach, USA, 2017, pp. 1025−1035.
    [49]
    P. Sen, G. Namata, M. Bilgic, L. Getoor, B. Gallagher, and T. Eliassi-Rad, “Collective classification in network data,” AI Mag., vol. 29, no. 3, Art. no. 93, Sep. 2008.
    [50]
    Y. Wu, R. Jin, and X. Zhang, “Efficient and exact local search for random walk based top-K proximity query in large graphs,” IEEE Trans. Knowl. Data Eng., vol. 28, no. 5, pp. 1160–1174, May 2016. doi: 10.1109/TKDE.2016.2515579
    [51]
    Z. Liao, T. Liu, Y. He, and L. Lin, “Effective temporal graph learning via personalized PageRank,” Entropy, vol. 26, no. 7, Art. no. 588, Jul. 2024. doi: 10.3390/e26070588
    [52]
    M. Yang, H. Wang, Z. Wei, S. Wang, and J. R. Wen, “Efficient algorithms for personalized PageRank computation: A survey,” IEEE Trans. Knowl. Data Eng., vol. 36, no. 9, pp. 4582–4602, Sep. 2024. doi: 10.1109/TKDE.2024.3376000
    [53]
    S. Bubeck, “Convex optimization: Algorithms and complexity,” Found. Trends Mach. Learn., vol. 8, no. 3−4, pp. 231–357, Nov. 2015. doi: 10.1561/9781601988614
    [54]
    S. Ghadimi, G. Lan, and H. Zhang, “Mini-batch stochastic approximation methods for nonconvex stochastic composite optimization,” Math. Program., vol. 155, no. 1−2, pp. 267–305, Dec. 2016.
    [55]
    Y. Nesterov, Lectures on Convex Optimization. Cham, Switzerland: Springer, 2018.
    [56]
    J. Gasteiger, A. Bojchevski, and S. Gűnnemann, “Predict then propagate: Graph neural networks meet personalized PageRank,” in Proc. 7th Int. Conf. Learning Representations, New Orleans, USA, 2019.
    [57]
    Z. Yang, W. W. Cohen, and R. Salakhutdinov, “Revisiting semi-supervised learning with graph embeddings,” in Proc. 33rd Int. Conf. Machine Learning, New York, USA, 2016, pp. 40−48.
    [58]
    A. Bojchevski and S. Gűnnemann, “Adversarial attacks on node embeddings via graph poisoning,” in Proc. 36th Int. Conf. Machine Learning, Long Beach, USA, 2019, pp. 695−704.

Catalog

    通讯作者: 陈斌, bchen63@163.com
    • 1. 

      沈阳化工大学材料科学与工程学院 沈阳 110142

    1. 本站搜索
    2. 百度学术搜索
    3. 万方数据库搜索
    4. CNKI搜索

    Figures(7)  / Tables(5)

    Article Metrics

    Article views (305) PDF downloads(39) Cited by()

    /

    DownLoad:  Full-Size Img  PowerPoint
    Return
    Return