Temporal Graph Neural Networks (TGNNs) are powerful tools for capturing intrinsic interactions among entities in real-world scenarios. However, numerous studies have shown that TGNNs are vulnerable to adversarial perturbations. While robustness certification has been extensively applied to fixed-dimensional models, such as Graph Neural Networks (GNNs), TGNNs have received significantly less attention in terms of robustness analysis. To bridge this gap, we propose an input-dependent randomized smoothing method called IDRS. Specifically, the IDRS method serves as a robustness certification framework tailored for temporal link prediction (TLP) models against modification and injection attacks. Furthermore, we theoretically certify the robustness radius of a TLP model when subjected to perturbations measured by edit distance. Experimental results on the WIKI, REDDIT, and MOOC datasets demonstrate that the proposed method achieves higher clean accuracy than the baseline while maintaining comparable robustness certification performance.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

IDRS: An Input-Dependent Randomized Smoothing Method Certifying the Robustness of Temporal Link Prediction Models

  • Yuheng Wang,
  • Qiang Liu,
  • Xiaojie Wu,
  • Weizhen Zhang

摘要

Temporal Graph Neural Networks (TGNNs) are powerful tools for capturing intrinsic interactions among entities in real-world scenarios. However, numerous studies have shown that TGNNs are vulnerable to adversarial perturbations. While robustness certification has been extensively applied to fixed-dimensional models, such as Graph Neural Networks (GNNs), TGNNs have received significantly less attention in terms of robustness analysis. To bridge this gap, we propose an input-dependent randomized smoothing method called IDRS. Specifically, the IDRS method serves as a robustness certification framework tailored for temporal link prediction (TLP) models against modification and injection attacks. Furthermore, we theoretically certify the robustness radius of a TLP model when subjected to perturbations measured by edit distance. Experimental results on the WIKI, REDDIT, and MOOC datasets demonstrate that the proposed method achieves higher clean accuracy than the baseline while maintaining comparable robustness certification performance.