@inproceedings{09cf3402cc424ba38f30e4c823cb5c38,
title = "CiDer: A Black-box Approach to Classify Node with Certified Robustness Guarantees",
abstract = "Due to the outstanding performance of graph node classification in tasks such as detecting illegal nodes in transaction networks, adversarial attacks aiming to perturb classification results have proliferated. Although current defenses based on randomized smoothing have shown some effectiveness, these approaches still require modifications to the classification model to ensure accuracy. Here, we propose a novel approach - CiDer, that theoretically guarantees the robustness of graph node classification results in a black-box setting, which means no assumptions on the form of attack and the classification model. The key idea behind our approach is to leverage the denoise capability of diffusion models on features to perform adversarial purification on the data. We then prove this stochastic purification method can ensure certified robustness under certain attack budgets. Our extensive experiments corroborate our theory and demonstrate that node classifiers worked with CiDer achieve significantly superior performance compared to state-of-the-art, e.g., the accuracy improves by 7\% on Cora and the optimal result improves by 30\% on PubMed.",
keywords = "adversarial attack, diffusion model, graph node classification",
author = "Xiaoyu Liang and Haohua Du and Wen Ma and Ye Tian and Xiaoya Xu",
note = "Publisher Copyright: {\textcopyright} 2025 IEEE.; 2025 IEEE Conference on Computer Communications, INFOCOM 2025 ; Conference date: 19-05-2025 Through 22-05-2025",
year = "2025",
doi = "10.1109/INFOCOM55648.2025.11044537",
language = "英语",
series = "Proceedings - IEEE INFOCOM",
publisher = "Institute of Electrical and Electronics Engineers Inc.",
booktitle = "INFOCOM 2025 - IEEE Conference on Computer Communications",
address = "美国",
}