Skip to main navigation Skip to search Skip to main content

CiDer: A Black-box Approach to Classify Node with Certified Robustness Guarantees

  • Xiaoyu Liang
  • , Haohua Du*
  • , Wen Ma
  • , Ye Tian
  • , Xiaoya Xu
  • *Corresponding author for this work
  • Beihang University
  • University of Science and Technology of China
  • China Aerospace Science and Industry Corporation

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Due to the outstanding performance of graph node classification in tasks such as detecting illegal nodes in transaction networks, adversarial attacks aiming to perturb classification results have proliferated. Although current defenses based on randomized smoothing have shown some effectiveness, these approaches still require modifications to the classification model to ensure accuracy. Here, we propose a novel approach - CiDer, that theoretically guarantees the robustness of graph node classification results in a black-box setting, which means no assumptions on the form of attack and the classification model. The key idea behind our approach is to leverage the denoise capability of diffusion models on features to perform adversarial purification on the data. We then prove this stochastic purification method can ensure certified robustness under certain attack budgets. Our extensive experiments corroborate our theory and demonstrate that node classifiers worked with CiDer achieve significantly superior performance compared to state-of-the-art, e.g., the accuracy improves by 7% on Cora and the optimal result improves by 30% on PubMed.

Original languageEnglish
Title of host publicationINFOCOM 2025 - IEEE Conference on Computer Communications
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798331543051
DOIs
StatePublished - 2025
Event2025 IEEE Conference on Computer Communications, INFOCOM 2025 - London, United Kingdom
Duration: 19 May 202522 May 2025

Publication series

NameProceedings - IEEE INFOCOM
ISSN (Print)0743-166X

Conference

Conference2025 IEEE Conference on Computer Communications, INFOCOM 2025
Country/TerritoryUnited Kingdom
CityLondon
Period19/05/2522/05/25

Keywords

  • adversarial attack
  • diffusion model
  • graph node classification

Fingerprint

Dive into the research topics of 'CiDer: A Black-box Approach to Classify Node with Certified Robustness Guarantees'. Together they form a unique fingerprint.

Cite this