PapersWithELO
← ICLR 2024 leaderboard

IDEA: Invariant Causal Defense for Graph Adversarial Robustness

Shuchang Tao, Qi Cao, Huawei Shen, Yunfan Wu, Bingbing Xu, Xueqi Cheng

fairness, safety & privacyInvariant Causal DefenseAdversarial RobustnessInvariant LearningGraph Neural Networks
88.30100
Fused
band ≈ ±15 pct pts (from σ = 0.31)
84.00100
Mimo
band ≈ ±21 pct pts (from σ = 0.43)
90.70100
DeepSeek
band ≈ ±22 pct pts (from σ = 0.44)

OpenReview ground truth

Rejected

TL;DR — To enhance adversarial robustness, we creatively propose IDEA defense method to learn causal features that exhibit strong and invariant predictability across attacks

Abstract

Despite the success of graph neural networks (GNNs), their vulnerability to adversarial attacks poses tremendous challenges for practical applications. Existing defense methods suffer from severe performance decline under some unknown attacks, due to either limited observed adversarial examples (adversarial training) or pre-defined heuristics (graph purification or robust aggregation). To address these limitations, we analyze the causalities in graph adversarial attacks and conclude that causal features are desirable to achieve graph adversarial robustness, owing to their determinedness for labels and invariance across attacks. To learn these causal features, we innovatively propose an Invariant causal DEfense method against adversarial Attacks (IDEA). We derive node-based and structurebased invariance objectives from an information-theoretic perspective. IDEA is provably a causally invariant defense across various attacks. Extensive experiments demonstrate that IDEA significantly outperforms all baselines under both poisoning and evasion attacks on five benchmark datasets, highlighting its strong and invariant predictability. The implementation of IDEA is available at https://anonymous.4open.science/r/IDEA_repo-666B.

Author context

Most prolific author: 4 submissions (credibility 1.00).

No mass-submission penalty for this paper (authors within normal submission volume).

Aggregate statistics only — no individual author rankings.

Ranking trajectory

Percentile by tournament round — convergence indicates rating stability.

Battle history — 36 comparisons

Ranked above opponent in 63% of matchups.

Judge assessments

Mean overall score 0.0 ± 0.0 (n = 36)