DefenseVGAE: Defending Against Adversarial Attacks on Graph Data via a Variational Graph Autoencoder
摘要
Graph neural networks (GNNs) achieve remarkable performances for the tasks on graph data. However, recent studies uncover that they are extremely vulnerable to adversarial structural perturbations, leading to their outcomes unreliable. In this paper, we propose DefenseVGAE, a novel defense method for leveraging variational graph autoencoders (VGAEs) to defend GNNs against such attacks. Specifically, DefenseVGAE is trained to reconstruct the graph structure of the graph data in which the reconstructed adjacency matrix is sparse and can reduce the effects of adversarial perturbations and boost the performance of GCN when facing the adversarial attacks. Our experiments on three typical datasets demonstrate that DefenseVGAE is effective under various threat models and even outperforms the existing defense strategies in certain settings.