← 피드로
[Submitted on 29 Mar 2025 (v1), last revised 22 Jul 2026 (this version, v3)]
Abstract:Despite advancements in Graph Neural Networks (GNNs), adaptive attacks continue to challenge their robustness. Certified robustness via randomized smoothing offers provable guarantees but suffers from a severe accuracy-robustness trade-off, limiting its practical use. To bridge this gap, we introduce AuditVotes, the first framework that simultaneously achieves high clean accuracy and strong certified robustness. AuditVotes seamlessly integrates two novel components into the randomized smoothing pipeline: (1) graph rewiring augmentation, which denoises randomized graphs to recover data quality, and (2) conditional smoothing, which filters low-confidence votes to ensure prediction consistency. We establish a novel theoretical result, proving that certified robustness is preserved under arbitrary filtering functions. Designed for inductive learning, our framework generalizes to unseen nodes and applies broadly to other smoothing schemes, including de-randomized smoothing for graphs and Gaussian smoothing for images. Extensive experiments show AuditVotes delivers substantial gains: on Cora-ML under 20-edge attacks, it improves clean accuracy by 437.1% and certified accuracy by 409.3%, while maintaining comparable runtime to vanilla smoothing. As a widely applicable and efficient plug-in, AuditVotes offers higher accuracy and stronger guarantees, enabling the practical and certifiably robust GNNs in security-sensitive domains.
Submission history
From: Yuni Lai [view email]
[v1]
Sat, 29 Mar 2025 07:27:32 UTC (2,505 KB)
[v2]
Fri, 17 Jul 2026 09:01:13 UTC (1,195 KB)
[v3]
Wed, 22 Jul 2026 04:39:17 UTC (1,196 KB)
추출 본문 · 출처: arxiv.org · https://arxiv.org/abs/2503.22998
답글 남기기