{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T03:45:14Z","timestamp":1784691914747,"version":"3.55.0"},"reference-count":159,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2024,2,8]],"date-time":"2024-02-08T00:00:00Z","timestamp":1707350400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,2,8]],"date-time":"2024-02-08T00:00:00Z","timestamp":1707350400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001775","name":"University of Technology Sydney","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100001775","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Artif Intell Rev"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Graph neural networks (GNNs) are models that capture the dependencies between graph data by passing messages between graph nodes\u00a0and they have been widely used to process graph data that contains relational information. Example application areas include social networks, recommendation systems, and life sciences. However, like all neural networks, there are underpinning\u00a0security and privacy\u00a0concerns associated with GNN deployments in practice. For example, attackers can perturb a graph\u2019s data to undermine a model\u2019s effectiveness, or they can steal the model\u2019s data and\/or parameters, thus threatening the privacy of the model. In this survey, we provide a comprehensive review of recent research efforts\u00a0on security and\/or privacy in GNNs. We also systematically describe the distinctions and relationships between security and privacy, as well as providing an outlook on future directions of research in this area.<\/jats:p>","DOI":"10.1007\/s10462-023-10656-4","type":"journal-article","created":{"date-parts":[[2024,2,8]],"date-time":"2024-02-08T13:02:46Z","timestamp":1707397366000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":34,"title":["Graph neural networks: a survey on the links between privacy and security"],"prefix":"10.1007","volume":"57","author":[{"given":"Faqian","family":"Guan","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tianqing","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wanlei","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kim-Kwang Raymond","family":"Choo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,2,8]]},"reference":[{"key":"10656_CR1","doi-asserted-by":"crossref","unstructured":"Abadi M, Chu A, Goodfellow IJ, McMahan HB, Mironov I, Talwar K, Zhang L (2016) Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, pp 308\u2013318","DOI":"10.1145\/2976749.2978318"},{"key":"10656_CR2","doi-asserted-by":"crossref","unstructured":"Backes M, Berrang P, Humbert M, Manoharan P (2016) Membership privacy in microrna-based studies. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, pp 319\u2013330","DOI":"10.1145\/2976749.2978355"},{"key":"10656_CR3","doi-asserted-by":"crossref","unstructured":"Backes M, Humbert M, Pang J, Zhang Y (2017) walk2friends: inferring social links from mobility profiles. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, CCS, pp 1943\u20131957","DOI":"10.1145\/3133956.3133972"},{"issue":"5439","key":"10656_CR4","doi-asserted-by":"publisher","first-page":"509","DOI":"10.1126\/science.286.5439.509","volume":"286","author":"A-L Barab\u00e1si","year":"1999","unstructured":"Barab\u00e1si A-L, Albert R (1999) Emergence of scaling in random networks. Science 286(5439):509\u2013512","journal-title":"Science"},{"key":"10656_CR5","unstructured":"Battaglia PW, Hamrick JB, Bapst V, Sanchez-Gonzalez A, Zambaldi VF, Malinowski M, Tacchetti A, Raposo D, Santoro A, Faulkner R, G\u00fcl\u00e7ehre \u00c7, Song HF, Ballard AJ, Gilmer J, Dahl GE, Vaswani A, Allen KR, Nash C, Langston V, Dyer C, Heess N, Wierstra D, Kohli P, Botvinick MM, Vinyals O, Li Y, Pascanu R (2018) Relational inductive biases, deep learning, and graph networks. CoRR arXiv:1806.01261"},{"key":"10656_CR6","unstructured":"Bojchevski A, G\u00fcnnemann S (2019) Adversarial attacks on node embeddings via graph poisoning. In: Proceedings of the 36th international conference on machine learning, ICML, vol 97, pp 695\u2013704"},{"key":"10656_CR7","unstructured":"Bojchevski A, G\u00fcnnemann S (2019) Certifiable robustness to graph perturbations. In: Advances in neural information processing systems 32: annual conference on neural information processing systems 2019, NeurIPS, pp 8317\u20138328"},{"key":"10656_CR8","unstructured":"Bose AJ, Cianflone A, Hamilton WL (2019) Generalizable adversarial attacks using generative models. CoRR arXiv:1905.10864"},{"key":"10656_CR9","doi-asserted-by":"crossref","unstructured":"Bourtoule L, Chandrasekaran V, Choquette-Choo C.A, Jia H, Travers A, Zhang B, Lie D, Papernot N (2021) Machine unlearning. In: 2021 IEEE symposium on security and privacy (SP). IEEE, pp 141\u2013159","DOI":"10.1109\/SP40001.2021.00019"},{"key":"10656_CR10","doi-asserted-by":"crossref","unstructured":"Cai Z, Xiong Z, Xu H, Wang P, Li W, Pan Y (2021) Generative adversarial networks: a survey towards private and secure applications. CoRR arXiv:2106.03785 (2021)","DOI":"10.1145\/3459992"},{"key":"10656_CR11","doi-asserted-by":"crossref","unstructured":"Cao X, Gong NZ (2017) Mitigating evasion attacks to deep neural networks via region-based classification. In: Proceedings of the 33rd annual computer security applications conference, pp 278\u2013287","DOI":"10.1145\/3134600.3134606"},{"key":"10656_CR12","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner DA (2017) Towards evaluating the robustness of neural networks. In: 2017 IEEE symposium on security and privacy, SP, pp 39\u201357","DOI":"10.1109\/SP.2017.49"},{"key":"10656_CR13","doi-asserted-by":"crossref","unstructured":"Chang H, Rong Y, Xu T, Huang W, Zhang H, Cui P, Zhu W, Huang J (2020) A restricted black-box adversarial framework towards attacking graph embedding models. In: The thirty-fourth AAAI conference on artificial intelligence, AAAI, pp 3389\u20133396","DOI":"10.1609\/aaai.v34i04.5741"},{"issue":"1","key":"10656_CR14","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1109\/TCSS.2020.3031596","volume":"8","author":"J Chen","year":"2021","unstructured":"Chen J, Chen Y, Chen L, Zhao M, Xuan Q (2021) Multiscale evolutionary perturbation attack on community detection. IEEE Trans Comput Soc Syst 8(1):62\u201375","journal-title":"IEEE Trans Comput Soc Syst"},{"key":"10656_CR15","doi-asserted-by":"crossref","unstructured":"Chen L, Li J, Peng Q, Liu Y, Zheng Z, Yang C (2021) Understanding structural vulnerability in graph convolutional networks. In: Proceedings of the thirtieth international joint conference on artificial intelligence, IJCAI, pp 2249\u20132255","DOI":"10.24963\/ijcai.2021\/310"},{"key":"10656_CR16","unstructured":"Chen Y, Yang H, Zhang Y, Ma K, Liu T, Han B, Cheng J (2022) Understanding and improving graph injection attack by promoting unnoticeability. In: International conference on learning representations"},{"key":"10656_CR17","doi-asserted-by":"crossref","unstructured":"Chen M, Zhang Z, Wang T, Backes M, Humbert M, Zhang Y (2022) Graph unlearning. In: Proceedings of the 2022 ACM SIGSAC conference on computer and communications security, pp 499\u2013513","DOI":"10.1145\/3548606.3559352"},{"key":"10656_CR18","doi-asserted-by":"crossref","unstructured":"Cho E, Myers SA, Leskovec J (2011) Friendship and mobility: user movement in location-based social networks. In: Proceedings of the 17th ACM SIGKDD international conference on knowledge discovery and data mining, pp 1082\u20131090","DOI":"10.1145\/2020408.2020579"},{"key":"10656_CR19","unstructured":"Cohen JM, Rosenfeld E, Kolter JZ (2019) Certified adversarial robustness via randomized smoothing. In: Proceedings of the 36th international conference on machine learning, ICML. Proceedings of machine learning research, vol 97, pp 1310\u20131320"},{"key":"10656_CR20","doi-asserted-by":"crossref","unstructured":"Dai E, Aggarwal C, Wang S (2021) NRGNN: learning a label noise resistant graph neural network on sparsely and noisily labeled graphs. In: KDD \u201921: the 27th ACM SIGKDD conference on knowledge discovery and data mining, virtual event, pp 227\u2013236","DOI":"10.1145\/3447548.3467364"},{"key":"10656_CR21","unstructured":"Dai H, Li H, Tian T, Huang X, Wang L, Zhu J, Song L (2018) Adversarial attack on graph structured data. In: Proceedings of the 35th international conference on machine learning, ICML, vol 80, pp 1123\u20131132"},{"key":"10656_CR22","unstructured":"Dai E, Zhao T, Zhu H, Xu J, Guo Z, Liu H, Tang J, Wang S (2022) A comprehensive survey on trustworthy graph neural networks: privacy, robustness, fairness, and explainability. CoRR arXiv:2204.08570 (2022)"},{"key":"10656_CR23","unstructured":"de Oc\u00e1riz\u00a0Borde HS, Kazi A, Barbero F, Li\u00f2 P (2023) Latent graph inference using product manifolds. In: The eleventh international conference on learning representations, ICLR 2023, Kigali, Rwanda, May 1\u20135, 2023"},{"key":"10656_CR24","doi-asserted-by":"crossref","unstructured":"Duddu V, Boutet A, Shejwalkar V (2020) Quantifying privacy leakage in graph embedding. In: MobiQuitous \u201920: computing, networking and services, virtual event, pp 76\u201385","DOI":"10.1145\/3448891.3448939"},{"key":"10656_CR25","doi-asserted-by":"crossref","unstructured":"Du W, Ma X, Dong W, Zhang D, Zhang C, Sun Q (2021) Calibrating privacy budgets for locally private graph neural networks. In: 2021 international conference on networking and network applications, pp 23\u201329","DOI":"10.1109\/NaNA53684.2021.00012"},{"key":"10656_CR26","doi-asserted-by":"crossref","unstructured":"Dwork C (2008) Differential privacy: a survey of results. In: Theory and applications of models of computation, 5th international conference, TAMC, vol 4978, pp 1\u201319","DOI":"10.1007\/978-3-540-79228-4_1"},{"issue":"3\u20134","key":"10656_CR27","first-page":"211","volume":"9","author":"C Dwork","year":"2014","unstructured":"Dwork C, Roth A (2014) The algorithmic foundations of differential privacy. Found Trends Theor Comput Sci 9(3\u20134):211\u2013407","journal-title":"Found Trends Theor Comput Sci"},{"key":"10656_CR28","unstructured":"Elinas P, Bonilla EV, Tiao LC (2020) Variational inference for graph convolutional networks in the absence of graph data and adversarial settings. In: Advances in neural information processing systems 33: annual conference on neural information processing systems 2020, NeurIPS"},{"key":"10656_CR29","doi-asserted-by":"crossref","unstructured":"Entezari N, Al-Sayouri SA, Darvishzadeh A, Papalexakis EE (2020) All you need is low (rank): defending against adversarial attacks on graphs. In: WSDM \u201920: the thirteenth ACM international conference on web search and data mining, pp 169\u2013177","DOI":"10.1145\/3336191.3371789"},{"key":"10656_CR30","unstructured":"Errica F, Podda M, Bacciu D, Micheli A (2020) A fair comparison of graph neural networks for graph classification. In: 8th international conference on learning representations, ICLR"},{"key":"10656_CR31","doi-asserted-by":"crossref","unstructured":"Fan W, Ma Y, Li Q, He Y, Zhao YE, Tang J, Yin D (2019) Graph neural networks for social recommendation. In: The world wide web conference, WWW, pp 417\u2013426","DOI":"10.1145\/3308558.3313488"},{"issue":"6","key":"10656_CR32","doi-asserted-by":"publisher","first-page":"2493","DOI":"10.1109\/TKDE.2019.2957786","volume":"33","author":"F Feng","year":"2021","unstructured":"Feng F, He X, Tang J, Chua T (2021) Graph adversarial training: dynamically regularizing based on graph structure. IEEE Trans Knowl Data Eng 33(6):2493\u20132504","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"10656_CR33","doi-asserted-by":"crossref","unstructured":"Feng B, Wang Y, Ding Y (2021) UAG: uncertainty-aware attention graph neural network for defending adversarial attacks. In: Thirty-fifth AAAI conference on artificial intelligence, AAAI, pp 7404\u20137412","DOI":"10.1609\/aaai.v35i8.16908"},{"key":"10656_CR34","doi-asserted-by":"crossref","unstructured":"Fredrikson M, Jha S, Ristenpart T (2015) Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security, pp 1322\u20131333","DOI":"10.1145\/2810103.2813677"},{"key":"10656_CR35","unstructured":"Fredrikson M, Lantz E, Jha S, Lin SM, Page D, Ristenpart T (2014) Privacy in pharmacogenetics: an end-to-end case study of personalized warfarin dosing. In: Proceedings of the 23rd USENIX security symposium, pp 17\u201332"},{"key":"10656_CR36","doi-asserted-by":"crossref","unstructured":"Fu X, Zhang J, Meng Z, King I (2020) MAGNN: metapath aggregated graph neural network for heterogeneous graph embedding. In: WWW \u201920: the web conference 2020, pp 2331\u20132341","DOI":"10.1145\/3366423.3380297"},{"key":"10656_CR37","unstructured":"Geisler S, Schmidt T, \u015eirin H, Z\u00fcgner D, Bojchevski A, G\u00fcnnemann S (2021) Robustness of graph neural networks at scale. Adv Neural Inf Process Syst 34"},{"key":"10656_CR38","unstructured":"Geisler S, Z\u00fcgner D, G\u00fcnnemann S (2020) Reliable graph neural networks via robust aggregation. In: Advances in neural information processing systems 33: annual conference on neural information processing systems 2020, NeurIPS"},{"issue":"4","key":"10656_CR39","doi-asserted-by":"publisher","first-page":"1141","DOI":"10.1214\/aoms\/1177706098","volume":"30","author":"EN Gilbert","year":"1959","unstructured":"Gilbert EN (1959) Random graphs. Ann Math Stat 30(4):1141\u20131144","journal-title":"Ann Math Stat"},{"key":"10656_CR40","unstructured":"Gilmer J, Schoenholz SS, Riley PF, Vinyals O, Dahl GE (2017) Neural message passing for quantum chemistry. In: Proceedings of the 34th international conference on machine learning, ICML. Proceedings of machine learning research, vol 70, pp 1263\u20131272"},{"key":"10656_CR41","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. In: 3rd international conference on learning representations, ICLR"},{"key":"10656_CR42","doi-asserted-by":"crossref","unstructured":"G\u00fcnnemann S (2022) Graph neural networks: adversarial robustness. In: Graph neural networks: foundations, frontiers, and applications, pp 149\u2013176","DOI":"10.1007\/978-981-16-6054-2_8"},{"key":"10656_CR43","unstructured":"Hamilton WL, Ying Z, Leskovec J (2017) Inductive representation learning on large graphs. In: Advances in neural information processing systems 30: annual conference on neural information processing systems 2017, NeurIPS, pp 1024\u20131034"},{"issue":"3","key":"10656_CR44","first-page":"52","volume":"40","author":"WL Hamilton","year":"2017","unstructured":"Hamilton WL, Ying R, Leskovec J (2017) Representation learning on graphs: methods and applications. IEEE Data Eng Bull 40(3):52\u201374","journal-title":"IEEE Data Eng Bull"},{"key":"10656_CR45","unstructured":"He X, Jia J, Backes M, Gong N.Z, Zhang Y (2021) Stealing links from graph neural networks. In: 30th USENIX security symposium, USENIX, pp 2669\u20132686"},{"key":"10656_CR46","unstructured":"He X, Wen R, Wu Y, Backes M, Shen Y, Zhang Y (2021) Node-level membership inference attacks against graph neural networks. CoRR arXiv:2102.05429"},{"key":"10656_CR47","unstructured":"Hidano S, Murakami T (2022) Degree-preserving randomized response for graph neural networks under local differential privacy. CoRR arXiv:2202.10209"},{"key":"10656_CR48","unstructured":"Hinton GE, Vinyals O, Dean J (2015) Distilling the knowledge in a neural network. CoRR arXiv:1503.02531"},{"key":"10656_CR49","doi-asserted-by":"crossref","unstructured":"Hu H, Cheng L, Vap J.P, Borowczak M (2022) Learning privacy-preserving graph convolutional network with partially observed sensitive attributes. In: WWW \u201922: the ACM web conference 2022, virtual event, pp 3552\u20133561","DOI":"10.1145\/3485447.3511975"},{"issue":"2","key":"10656_CR50","doi-asserted-by":"publisher","first-page":"1305","DOI":"10.1109\/COMST.2016.2633620","volume":"19","author":"S Ji","year":"2017","unstructured":"Ji S, Mittal P, Beyah RA (2017) Graph data anonymization, de-anonymization attacks, and de-anonymizability quantification: a survey. IEEE Commun Surv Tutor 19(2):1305\u20131326","journal-title":"IEEE Commun Surv Tutor"},{"key":"10656_CR51","doi-asserted-by":"crossref","unstructured":"Jia J, Cao X, Wang B, Gong NZ (2020) Certified robustness for top-k predictions against adversarial perturbations via randomized smoothing. In: 8th international conference on learning representations, ICLR","DOI":"10.1145\/3366423.3380029"},{"key":"10656_CR52","doi-asserted-by":"crossref","unstructured":"Jia J, Salem A, Backes M, Zhang Y, Gong NZ (2019) Memguard: defending against black-box membership inference attacks via adversarial examples. In: Proceedings of the 2019 ACM SIGSAC conference on computer and communications security, CCS, pp 259\u2013274 (2019)","DOI":"10.1145\/3319535.3363201"},{"key":"10656_CR53","unstructured":"Jin H, Shi Z, Peruri VJSA, Zhang X (2020) Certified robustness of graph convolution networks for graph classification under topological attacks. In: Advances in neural information processing systems 33: annual conference on neural information processing systems 2020, NeurIPS"},{"issue":"6245","key":"10656_CR54","doi-asserted-by":"publisher","first-page":"255","DOI":"10.1126\/science.aaa8415","volume":"349","author":"MI Jordan","year":"2015","unstructured":"Jordan MI, Mitchell TM (2015) Machine learning: trends, perspectives, and prospects. Science 349(6245):255\u2013260","journal-title":"Science"},{"issue":"3","key":"10656_CR55","doi-asserted-by":"publisher","first-page":"793","DOI":"10.1137\/090756090","volume":"40","author":"SP Kasiviswanathan","year":"2011","unstructured":"Kasiviswanathan SP, Lee HK, Nissim K, Raskhodnikova S, Smith AD (2011) What can we learn privately? SIAM J Comput 40(3):793\u2013826","journal-title":"SIAM J Comput"},{"key":"10656_CR56","first-page":"1","volume":"3\u20134","author":"MI Kayes","year":"2017","unstructured":"Kayes MI, Iamnitchi A (2017) Privacy and security in online social networks: a survey. Online Soc Netw Media 3\u20134:1\u201321","journal-title":"Online Soc Netw Media"},{"key":"10656_CR57","unstructured":"Kipf TN, Welling M (2016) Semi-supervised classification with graph convolutional networks. CoRR arXiv:1609.02907"},{"key":"10656_CR58","doi-asserted-by":"crossref","unstructured":"L\u00e9cuyer M, Atlidakis V, Geambasu R, Hsu D, Jana S (2019) Certified robustness to adversarial examples with differential privacy. In: 2019 IEEE symposium on security and privacy, SP, pp 656\u2013672","DOI":"10.1109\/SP.2019.00044"},{"key":"10656_CR59","unstructured":"Leino K, Fredrikson M (2020) Stolen memories: Leveraging model memorization for calibrated white-box membership inference. In: 29th USENIX security symposium, USENIX, pp 1605\u20131622"},{"issue":"8","key":"10656_CR60","doi-asserted-by":"publisher","first-page":"6904","DOI":"10.1109\/JIOT.2020.3036583","volume":"8","author":"K Li","year":"2021","unstructured":"Li K, Luo G, Ye Y, Li W, Ji S, Cai Z (2021) Adversarial privacy-preserving graph embedding against inference attack. IEEE Internet Things J 8(8):6904\u20136915","journal-title":"IEEE Internet Things J"},{"key":"10656_CR61","unstructured":"Li B, Chen C, Wang W, Carin L (2019) Certified adversarial robustness with additive noise. In: Advances in neural information processing systems 32: annual conference on neural information processing systems 2019, NeurIPS, pp 9459\u20139469"},{"key":"10656_CR62","unstructured":"Li K, Liu Y, Ao X, He Q (2023) Revisiting graph adversarial attack and defense from a data distribution perspective. In: The eleventh international conference on learning representations, ICLR 2023, Kigali, Rwanda, May 1\u20135, 2023"},{"key":"10656_CR63","doi-asserted-by":"crossref","unstructured":"Li K, Lu G, Luo G, Cai Z (2020) Seed-free graph de-anonymiztiation with adversarial learning. In: d\u2019Aquin M, Dietze S, Hauff C, Curry E, Cudr\u00e9-Mauroux P (eds) CIKM \u201920: the 29th ACM international conference on information and knowledge management, virtual event, Ireland, October 19\u201323, 2020, pp 745\u2013754","DOI":"10.1145\/3340531.3411970"},{"key":"10656_CR64","doi-asserted-by":"crossref","unstructured":"Liu X, Cheng M, Zhang H, Hsieh C (2018) Towards robust neural networks via random self-ensemble. In: Computer Vision\u2014ECCV 2018\u201415th European Conference, Munich. Lecture Notes in computer science, vol 11211, pp 381\u2013397","DOI":"10.1007\/978-3-030-01234-2_23"},{"key":"10656_CR65","unstructured":"Liu X, Ding J, Jin W, Xu H, Ma Y, Liu Z, Tang J (2021) Graph neural networks with adaptive residual. Adv Neural Inf Process Syst 34"},{"key":"10656_CR66","doi-asserted-by":"crossref","unstructured":"Liu Z, Zhang X, Chen C, Lin S, Li J (2022) Membership inference attacks against robust graph neural network. In: Chen X, Shen J, Susilo W (eds) Cyberspace safety and security\u201414th international symposium, CSS 2022, Xi\u2019an, China, October 16\u201318, 2022, Proceedings. Lecture notes in computer science, vol 13547, pp 259\u2013273","DOI":"10.1007\/978-3-031-18067-5_19"},{"key":"10656_CR67","unstructured":"Ma J, Ding S, Mei Q (2020) Towards more practical adversarial attacks on graph neural networks. In: Advances in neural information processing systems 33: annual conference on neural information processing systems 2020, NeurIPS"},{"key":"10656_CR68","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2018) Towards deep learning models resistant to adversarial attacks. In: 6th international conference on learning representations, ICLR"},{"key":"10656_CR69","doi-asserted-by":"crossref","unstructured":"Marchant NG, Rubinstein BIP, Alfeld S (2022) Hard to forget: poisoning attacks on certified machine unlearning. In: Thirty-sixth AAAI conference on artificial intelligence, AAAI 2022, thirty-fourth conference on innovative applications of artificial intelligence, IAAI 2022, the twelveth symposium on educational advances in artificial intelligence, EAAI 2022 virtual event, February 22\u2013March 1, 2022, pp 7691\u20137700","DOI":"10.1609\/aaai.v36i7.20736"},{"key":"10656_CR70","unstructured":"Ma Y, Wang S, Wu L, Tang J (2019) Attacking graph convolutional networks via rewiring. CoRR arXiv:1906.03750"},{"key":"10656_CR71","doi-asserted-by":"crossref","unstructured":"Mironov I (2017) R\u00e9nyi differential privacy. In: 30th IEEE computer security foundations symposium, CSF, pp 263\u2013275","DOI":"10.1109\/CSF.2017.11"},{"key":"10656_CR72","doi-asserted-by":"publisher","first-page":"619","DOI":"10.1016\/j.future.2020.10.007","volume":"115","author":"V Mothukuri","year":"2021","unstructured":"Mothukuri V, Parizi RM, Pouriyeh S, Huang Y, Dehghantanha A, Srivastava G (2021) A survey on security and privacy of federated learning. Future Gener Comput Syst 115:619\u2013640","journal-title":"Future Gener Comput Syst"},{"key":"10656_CR73","unstructured":"Mueller TT, Paetzold JC, Prabhakar C, Usynin D, Rueckert D, Kaissis G (2022) Differentially private graph classification with GNNs. CoRR arXiv:2202.02575"},{"key":"10656_CR74","unstructured":"Mueller TT, Usynin D, Paetzold JC, Rueckert D, Kaissis G (2022) SoK: differential privacy on graph-structured data. CoRR arXiv:2203.09205 (2022)"},{"key":"10656_CR75","doi-asserted-by":"crossref","unstructured":"Mu J, Wang B, Li Q, Sun K, Xu M, Liu Z (2021) A hard label black-box adversarial attack against graph neural networks. In: CCS \u201921: 2021 ACM SIGSAC conference on computer and communications security, virtual event, pp 108\u2013125","DOI":"10.1145\/3460120.3484796"},{"key":"10656_CR76","unstructured":"Olatunji IE, Funke T, Khosla M (2021) Releasing graph neural networks with differential privacy guarantees. CoRR arXiv:2109.08907"},{"key":"10656_CR77","doi-asserted-by":"crossref","unstructured":"Olatunji IE, Nejdl W, Khosla M (2021) Membership inference attack on graph neural networks. In: 3rd IEEE international conference on trust, privacy and security in intelligent systems and applications, TPS-ISA, pp 11\u201320","DOI":"10.1109\/TPSISA52974.2021.00002"},{"key":"10656_CR78","unstructured":"Papernot N, McDaniel PD (2017) Extending defensive distillation. CoRR arXiv:1705.05264"},{"key":"10656_CR79","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel PD, Goodfellow I.J, Jha S, Celik ZB, Swami A (2016) Practical black-box attacks against deep learning systems using adversarial examples. CoRR arXiv:1602.02697","DOI":"10.1145\/3052973.3053009"},{"key":"10656_CR80","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P.D, Wu X, Jha S, Swami A (2016) Distillation as a defense to adversarial perturbations against deep neural networks. In: IEEE symposium on security and privacy, SP, pp 582\u2013597","DOI":"10.1109\/SP.2016.41"},{"key":"10656_CR81","doi-asserted-by":"crossref","unstructured":"Park S, Park J, Shin S, Moon I (2018) Adversarial dropout for supervised and semi-supervised learning. In: Proceedings of the thirty-second AAAI conference on artificial intelligence, AAAI, pp 3917\u20133924","DOI":"10.1609\/aaai.v32i1.11634"},{"issue":"6","key":"10656_CR82","doi-asserted-by":"publisher","first-page":"386","DOI":"10.1037\/h0042519","volume":"65","author":"F Rosenblatt","year":"1958","unstructured":"Rosenblatt F (1958) The perceptron: a probabilistic model for information storage and organization in the brain. Psychol Rev 65(6):386","journal-title":"Psychol Rev"},{"key":"10656_CR83","doi-asserted-by":"crossref","unstructured":"Sajadmanesh S, Gatica-Perez D (2021) Locally private graph neural networks. In: CCS \u201921: 2021 ACM SIGSAC conference on computer and communications security, virtual event, pp 2130\u20132145","DOI":"10.1145\/3460120.3484565"},{"key":"10656_CR84","unstructured":"Sajadmanesh S, Shamsabadi AS, Bellet A, Gatica-Perez D (2023) GAP: differentially private graph neural networks with aggregation perturbation"},{"key":"10656_CR85","doi-asserted-by":"crossref","unstructured":"Salem A, Zhang Y, Humbert M, Berrang P, Fritz M, Backes M (2019) Ml-leaks: model and data independent membership inference attacks and defenses on machine learning models. In: 26th annual network and distributed system security symposium, NDSS","DOI":"10.14722\/ndss.2019.23119"},{"issue":"1","key":"10656_CR86","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1109\/TNN.2008.2005605","volume":"20","author":"F Scarselli","year":"2009","unstructured":"Scarselli F, Gori M, Tsoi AC, Hagenbuchner M, Monfardini G (2009) The graph neural network model. IEEE Trans Neural Netw 20(1):61\u201380","journal-title":"IEEE Trans Neural Netw"},{"key":"10656_CR87","unstructured":"Schlichtkrull MS, Cao ND, Titov I (2021) Interpreting graph neural networks for NLP with differentiable edge masking. In: 9th international conference on learning representations, ICLR 2021, Virtual Event, Austria, May 3\u20137, 2021"},{"key":"10656_CR88","unstructured":"Schuchardt J, Bojchevski A, Klicpera J, G\u00fcnnemann S (2021) Collective robustness certificates: exploiting interdependence in graph neural networks. In: 9th international conference on learning representations, ICLR"},{"key":"10656_CR89","doi-asserted-by":"crossref","unstructured":"Shanthamallu US, Thiagarajan JJ, Spanias A (2021) Uncertainty-matching graph neural networks to defend against poisoning attacks. In: Thirty-fifth AAAI conference on artificial intelligence, AAAI, pp 9524\u20139532","DOI":"10.1609\/aaai.v35i11.17147"},{"key":"10656_CR90","unstructured":"Shen Y, He X, Han Y, Zhang Y: Model stealing attacks against inductive graph neural networks. CoRR arXiv:2112.08331"},{"key":"10656_CR91","doi-asserted-by":"crossref","unstructured":"Shi W, Rajkumar R (2020) Point-GNN: graph neural network for 3D object detection in a point cloud. In: 2020 IEEE\/CVF conference on computer vision and pattern recognition, CVPR 2020, Seattle, WA, USA, June 13\u201319, 2020, pp 1708\u20131716","DOI":"10.1109\/CVPR42600.2020.00178"},{"key":"10656_CR92","doi-asserted-by":"crossref","unstructured":"Shi L, Zhang Y, Cheng J, Lu H (2019) Skeleton-based action recognition with directed graph neural networks. In: IEEE conference on computer vision and pattern recognition, CVPR, pp 7912\u20137921","DOI":"10.1109\/CVPR.2019.00810"},{"key":"10656_CR93","doi-asserted-by":"crossref","unstructured":"Shokri R, Stronati M, Song C, Shmatikov V (2017) Membership inference attacks against machine learning models. In: 2017 IEEE symposium on security and privacy, SP, pp 3\u201318","DOI":"10.1109\/SP.2017.41"},{"key":"10656_CR94","doi-asserted-by":"crossref","unstructured":"Song C, Shmatikov V (2019) Auditing data provenance in text-generation models. In: Proceedings of the 25th ACM SIGKDD international conference on knowledge discovery & data mining, KDD, pp 196\u2013206","DOI":"10.1145\/3292500.3330885"},{"key":"10656_CR95","doi-asserted-by":"crossref","unstructured":"Song L, Shokri R, Mittal P (2019) Privacy risks of securing machine learning models against adversarial examples. In: Cavallaro L, Kinder J, Wang X, Katz J (eds) Proceedings of the 2019 ACM SIGSAC conference on computer and communications security, CCS 2019, London, UK, November 11\u201315, 2019, pp 241\u2013257","DOI":"10.1145\/3319535.3354211"},{"key":"10656_CR96","doi-asserted-by":"crossref","unstructured":"Stewart GW (1990) Matrix perturbation theory","DOI":"10.1137\/1032121"},{"key":"10656_CR97","doi-asserted-by":"crossref","unstructured":"Sun Y, Wang S, Tang X, Hsieh T, Honavar VG (2020) Adversarial attacks on graph neural networks via node injections: A hierarchical reinforcement learning approach. In: WWW \u201920: the web conference 2020, pp 673\u2013683","DOI":"10.1145\/3366423.3380149"},{"key":"10656_CR98","unstructured":"Sun L, Wang J, Yu PS, Li B (2018) Adversarial attack and defense on graph data: a survey. CoRR arXiv:1812.10528"},{"key":"10656_CR99","unstructured":"Tian Y, Zhang C, Guo Z, Zhang X, Chawla NV (2023) Learning MLPs on graphs: a unified view of effectiveness, robustness, and efficiency. In: The eleventh international conference on learning representations, ICLR 2023, Kigali, Rwanda, May 1\u20135, 2023"},{"key":"10656_CR100","unstructured":"Tram\u00e8r F, Zhang F, Juels A, Reiter MK, Ristenpart T (2016) Stealing machine learning models via prediction apis. In 25th USENIX security symposium, USENIX, pp 601\u2013618"},{"key":"10656_CR101","unstructured":"Vaswani A, Shazeer N, Parmar N, Uszkoreit J, Jones L, Gomez A.N, Kaiser L, Polosukhin I (2017) Attention is all you need"},{"key":"10656_CR102","unstructured":"Velickovic P, Cucurull G, Casanova A, Romero A, Li\u00f2 P, Bengio Y (2018) Graph attention networks. In: 6th international conference on learning representations, ICLR"},{"key":"10656_CR103","unstructured":"Waikhom L, Patgiri R (2021) Graph neural networks: methods, applications, and opportunities. CoRR arXiv:2108.10733"},{"issue":"4","key":"10656_CR104","doi-asserted-by":"publisher","first-page":"600","DOI":"10.1109\/TIP.2003.819861","volume":"13","author":"Z Wang","year":"2004","unstructured":"Wang Z, Bovik AC, Sheikh HR, Simoncelli EP (2004) Image quality assessment: from error visibility to structural similarity. IEEE Trans Image Process 13(4):600\u2013612","journal-title":"IEEE Trans Image Process"},{"key":"10656_CR105","doi-asserted-by":"crossref","unstructured":"Wang B, Gong NZ (2019) Attacking graph-based classification via manipulating the graph structure. In: Proceedings of the 2019 ACM SIGSAC conference on computer and communications security, CCS, pp 2023\u20132040","DOI":"10.1145\/3319535.3354206"},{"key":"10656_CR106","unstructured":"Wang C, Huai M, Wang D: Inductive graph unlearning. In: Calandrino JA, Troncoso C (eds) 32nd USENIX security symposium, USENIX security 2023, Anaheim, CA, USA, August 9\u201311, 2023"},{"key":"10656_CR107","doi-asserted-by":"crossref","unstructured":"Wang B, Jia J, Cao X, Gong NZ (2021) Certified robustness of graph neural networks against adversarial structural perturbation. In: KDD \u201921: the 27th ACM SIGKDD conference on knowledge discovery and data mining, virtual event, pp 1645\u20131653","DOI":"10.1145\/3447548.3467295"},{"key":"10656_CR108","doi-asserted-by":"crossref","unstructured":"Wang X, Ji H, Shi C, Wang B, Ye Y, Cui P, Yu PS (2019) Heterogeneous graph attention network. In: The world wide web conference, WWW, pp 2022\u20132032","DOI":"10.1145\/3308558.3313562"},{"key":"10656_CR109","doi-asserted-by":"crossref","unstructured":"Wang X, Wang WH (2022) Group property inference attacks against graph neural networks. In: Yin H, Stavrou A, Cremers C, Shi E (eds) Proceedings of the 2022 ACM SIGSAC conference on computer and communications security, CCS 2022, Los Angeles, CA, USA, November 7\u201311, 2022, pp 2871\u20132884","DOI":"10.1145\/3548606.3560662"},{"key":"10656_CR110","doi-asserted-by":"crossref","unstructured":"Wang Y, Wang Y, Zhang Z, Yang S, Zhao K, Liu J (2023) USER: unsupervised structural entropy-based robust graph neural network. In: Williams B, Chen Y, Neville J (eds) Thirty-seventh AAAI conference on artificial intelligence, AAAI 2023, thirty-fifth conference on innovative applications of artificial intelligence, IAAI 2023, thirteenth symposium on educational advances in artificial intelligence, EAAI 2023, Washington, DC, USA, February 7\u201314, 2023, pp 10235\u201310243","DOI":"10.1609\/aaai.v37i8.26219"},{"key":"10656_CR111","doi-asserted-by":"crossref","unstructured":"Wang B, Yao Y, Shan S, Li H, Viswanath B, Zheng H, Zhao BY (2019) Neural cleanse: identifying and mitigating backdoor attacks in neural networks. In: 2019 IEEE symposium on security and privacy, SP, pp 707\u2013723","DOI":"10.1109\/SP.2019.00031"},{"key":"10656_CR112","unstructured":"Wan X, Kenlay H, Ru B, Blaas A, Osborne MA, Dong X (2021) Adversarial attacks on graph classification via Bayesian optimisation. CoRR arXiv:2111.02842"},{"issue":"309","key":"10656_CR113","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1080\/01621459.1965.10480775","volume":"60","author":"SL Warner","year":"1965","unstructured":"Warner SL (1965) Randomized response: a survey technique for eliminating evasive answer bias. J Am Stat Assoc 60(309):63\u201369","journal-title":"J Am Stat Assoc"},{"issue":"6684","key":"10656_CR114","doi-asserted-by":"publisher","first-page":"440","DOI":"10.1038\/30918","volume":"393","author":"DJ Watts","year":"1998","unstructured":"Watts DJ, Strogatz SH (1998) Collective dynamics of \u2018small-world\u2019 networks. Nature 393(6684):440\u2013442","journal-title":"Nature"},{"issue":"9","key":"10656_CR115","first-page":"12","volume":"2","author":"B Weisfeiler","year":"1968","unstructured":"Weisfeiler B, Leman A (1968) The reduction of a graph to canonical form and the algebra which appears therein. NTI Ser 2(9):12\u201316","journal-title":"NTI Ser"},{"key":"10656_CR116","doi-asserted-by":"crossref","unstructured":"Wei Z, Xu J, Lan Y, Guo J, Cheng X (2017) Reinforcement learning to rank with Markov decision process. In: Proceedings of the 40th international ACM SIGIR conference on research and development in information retrieval, pp 945\u2013948","DOI":"10.1145\/3077136.3080685"},{"issue":"12","key":"10656_CR117","doi-asserted-by":"publisher","first-page":"12854","DOI":"10.1109\/TCYB.2021.3090769","volume":"52","author":"K Wu","year":"2022","unstructured":"Wu K, Wang C, Liu J (2022) Evolutionary multitasking multilayer network reconstruction. IEEE Trans Cybern 52(12):12854\u201312868","journal-title":"IEEE Trans Cybern"},{"issue":"6","key":"10656_CR118","doi-asserted-by":"publisher","first-page":"5136","DOI":"10.1109\/TCYB.2020.3027642","volume":"52","author":"K Wu","year":"2022","unstructured":"Wu K, Hao X, Liu J, Liu P, Shen F (2022) Online reconstruction of complex networks from streaming data. IEEE Trans Cybern 52(6):5136\u20135147","journal-title":"IEEE Trans Cybern"},{"key":"10656_CR119","unstructured":"Wu L, Chen Y, Shen K, Guo X, Gao H, Li S, Pei J, Long B (2021) Graph neural networks for natural language processing: a survey. CoRR arXiv:2106.06090"},{"key":"10656_CR120","unstructured":"Wu F, Jr. A.H.S, Zhang T, Fifty C, Yu T, Weinberger KQ (2019) Simplifying graph convolutional networks. In: Proceedings of the 36th international conference on machine learning, ICML. Proceedings of machine learning research, vol 97, pp 6861\u20136871"},{"key":"10656_CR121","doi-asserted-by":"crossref","unstructured":"Wu Y, Lian D, Xu Y, Wu L, Chen E (2020) Graph convolutional networks with Markov random field reasoning for social spammer detection. In: The thirty-fourth AAAI conference on artificial intelligence, AAAI, pp 1054\u20131061","DOI":"10.1609\/aaai.v34i01.5455"},{"key":"10656_CR122","doi-asserted-by":"crossref","unstructured":"Wu L, Lin H, Huang Y, Fan T, Li SZ (2023) Extracting low-\/high- frequency knowledge from graph neural networks and injecting it into MLPS: an effective GNN-to-MLP distillation framework. In: Williams B, Chen Y, Neville J (eds) Thirty-seventh AAAI conference on artificial intelligence, AAAI 2023, thirty-fifth conference on innovative applications of artificial intelligence, IAAI 2023, thirteenth symposium on educational advances in artificial intelligence, EAAI 2023, Washington, DC, USA, February 7\u201314, 2023, pp 10351\u201310360","DOI":"10.1609\/aaai.v37i9.26232"},{"key":"10656_CR123","doi-asserted-by":"crossref","unstructured":"Wu H, Wang C, Tyshetskiy Y, Docherty A, Lu K, Zhu L (2019) Adversarial examples for graph data: deep insights into attack and defense. In: Proceedings of the twenty-eighth international joint conference on artificial intelligence, IJCAI, pp 4816\u20134823","DOI":"10.24963\/ijcai.2019\/669"},{"key":"10656_CR124","doi-asserted-by":"crossref","unstructured":"Wu Z, Wang Z, Wang Z, Jin H (2018) Towards privacy-preserving visual recognition via adversarial training: a pilot study. In: Computer vision\u2014ECCV. Lecture notes in computer science, vol 11220, pp 627\u2013645","DOI":"10.1007\/978-3-030-01270-0_37"},{"key":"10656_CR125","unstructured":"Wu C, Wu F, Cao Y, Huang Y, Xie X: FEDGNN: federated graph neural network for privacy-preserving recommendation. CoRR arXiv:2102.04925"},{"key":"10656_CR126","doi-asserted-by":"crossref","unstructured":"Wu B, Yang X, Pan S, Yuan X (2021) Adapting membership inference attacks to GNN for graph classification: approaches and implications. In: IEEE international conference on data mining, ICDM, pp 1421\u20131426","DOI":"10.1109\/ICDM51629.2021.00182"},{"key":"10656_CR127","doi-asserted-by":"crossref","unstructured":"Wu B, Yang X, Pan S, Yuan X (2022) Model extraction attacks on graph neural networks: Taxonomy and realisation. In: ASIA CCS \u201922: ACM Asia conference on computer and communications security, pp 337\u2013350","DOI":"10.1145\/3488932.3497753"},{"key":"10656_CR128","unstructured":"Wu S, Zhang W, Sun F, Cui B (2020) Graph neural networks in recommender systems: a survey. CoRR arXiv:2011.02260"},{"key":"10656_CR129","unstructured":"Xi Z, Pang R, Ji S, Wang T (2021) Graph backdoor. In: 30th USENIX security symposium, USENIX, pp 1523\u20131540"},{"key":"10656_CR130","doi-asserted-by":"crossref","unstructured":"Xu K, Chen H, Liu S, Chen P, Weng T, Hong M, Lin X (2019) Topology attack and defense for graph neural networks: an optimization perspective. In: Proceedings of the twenty-eighth international joint conference on artificial intelligence, IJCAI, pp 3961\u20133967","DOI":"10.24963\/ijcai.2019\/550"},{"key":"10656_CR131","unstructured":"Xu K, Hu W, Leskovec J, Jegelka S (2019) How powerful are graph neural networks? In: 7th international conference on learning representations, ICLR"},{"key":"10656_CR132","unstructured":"Xu J, Picek S (2021) Watermarking graph neural networks based on backdoor attacks. CoRR arXiv:2110.11024"},{"key":"10656_CR133","doi-asserted-by":"crossref","unstructured":"Xu J, Picek S (2022) Poster: clean-label backdoor attack on graph neural networks. In: Yin H, Stavrou A, Cremers C, Shi E (eds) Proceedings of the 2022 ACM SIGSAC conference on computer and communications security, CCS 2022, Los Angeles, CA, USA, November 7\u201311, 2022, pp 3491\u20133493","DOI":"10.1145\/3548606.3563531"},{"key":"10656_CR134","doi-asserted-by":"crossref","unstructured":"Yang C, Wang H, Zhang K, Chen L, Sun L (2021) Secure deep graph generation with link differential privacy. In: Proceedings of the thirtieth international joint conference on artificial intelligence, IJCAI, pp 3271\u20133278","DOI":"10.24963\/ijcai.2021\/450"},{"key":"10656_CR135","doi-asserted-by":"crossref","unstructured":"Ying R, He R, Chen K, Eksombatchai P, Hamilton WL, Leskovec J (2018) Graph convolutional neural networks for web-scale recommender systems. In: Proceedings of the 24th ACM SIGKDD international conference on knowledge discovery & data mining, KDD, pp 974\u2013983","DOI":"10.1145\/3219819.3219890"},{"key":"10656_CR136","unstructured":"Yosinski J, Clune J, Bengio Y, Lipson H (2014) How transferable are features in deep neural networks? In: Advances in neural information processing systems 27: annual conference on neural information processing systems 2014, NeurIPS, pp 3320\u20133328"},{"key":"10656_CR137","unstructured":"Yun S, Jeong M, Kim R, Kang J, Kim HJ (2019) Graph transformer networks. In: Advances in neural information processing systems 32: annual conference on neural information processing systems 2019, NeurIPS, pp 11960\u201311970"},{"key":"10656_CR138","doi-asserted-by":"crossref","unstructured":"Zang X, Xie Y, Chen J, Yuan B: Graph universal adversarial attacks: a few bad actors ruin graph learning models. In: Proceedings of the thirtieth international joint conference on artificial intelligence, IJCAI, pp 3328\u20133334","DOI":"10.24963\/ijcai.2021\/458"},{"key":"10656_CR139","unstructured":"Zhang C, Bengio S, Hardt M, Recht B, Vinyals O (2017) Understanding deep learning requires rethinking generalization. In: 5th international conference on learning representations, ICLR"},{"key":"10656_CR140","unstructured":"Zhang Z, Chen M, Backes M, Shen Y, Zhang Y (2022) Inference attacks against graph neural networks. In: Proceedings of the USENIX security"},{"key":"10656_CR141","doi-asserted-by":"crossref","unstructured":"Zhang S, Chen H, Sun X, Li Y, Xu G (2022) Unsupervised graph poisoning attack via contrastive loss back-propagation. In: WWW \u201922: the ACM web conference 2022, virtual event, pp 1322\u20131330","DOI":"10.1145\/3485447.3512179"},{"key":"10656_CR142","doi-asserted-by":"crossref","unstructured":"Zhang Y, Gao H, Pei J, Huang H (2022) Robust self-supervised structural graph neural network for social network prediction. In: WWW \u201922: the ACM web conference 2022, virtual event, pp 1352\u20131361","DOI":"10.1145\/3485447.3512182"},{"key":"10656_CR143","doi-asserted-by":"crossref","unstructured":"Zhang Z, Jia J, Wang B, Gong NZ (2021b) Backdoor attacks to graph neural networks. In: SACMAT \u201921: The 26th ACM symposium on access control models and technologies, virtual event, pp 15\u201326","DOI":"10.1145\/3450569.3463560"},{"key":"10656_CR144","doi-asserted-by":"crossref","unstructured":"Zhang Z, Liu Q, Huang Z, Wang H, Lu C, Liu C, Chen E (2021) Graphmi: extracting private graph data from graph neural networks. In: Proceedings of the thirtieth international joint conference on artificial intelligence, IJCAI, pp 3749\u20133755 (2021)","DOI":"10.24963\/ijcai.2021\/516"},{"key":"10656_CR145","unstructured":"Zhang Y, Regol F, Pal S, Khan S, Ma L, Coates M (2021) Detection and defense of topological adversarial attacks on graphs. In: Proceedings of The 24th international conference on artificial intelligence and statistics, pp 2989\u20132997"},{"key":"10656_CR146","doi-asserted-by":"crossref","unstructured":"Zhang M, Wang X, Zhu M, Shi C, Zhang Z, Zhou J (2022) Robust heterogeneous graph neural networks against adversarial attacks","DOI":"10.1609\/aaai.v36i4.20357"},{"key":"10656_CR147","unstructured":"Zhang X, Zitnik M (2020) GNNGuard: defending graph neural networks against adversarial attacks. In: Advances in neural information processing systems 33: annual conference on neural information processing systems 2020, NeurIPS"},{"key":"10656_CR148","doi-asserted-by":"crossref","unstructured":"Zhao X, Wu H, Zhang X (2021) Watermarking graph neural networks by random graphs. In: 9th international symposium on digital forensics and security, ISDFS, pp 1\u20136","DOI":"10.1109\/ISDFS52919.2021.9486352"},{"key":"10656_CR149","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1016\/j.aiopen.2021.01.001","volume":"1","author":"J Zhou","year":"2020","unstructured":"Zhou J, Cui G, Hu S, Zhang Z, Yang C, Liu Z, Wang L, Li C, Sun M (2020) Graph neural networks: a review of methods and applications. AI Open 1:57\u201381","journal-title":"AI Open"},{"key":"10656_CR150","unstructured":"Zhou J, Chen C, Zheng L, Wu H, Wu J, Zheng X, Wu B, Liu Z, Wang L (2020) Vertically federated graph neural network for privacy-preserving node classification. arXiv preprint arXiv:2005.11903"},{"key":"10656_CR151","unstructured":"Zhou Y, Kutyniok G, Ribeiro B (2022) OOD link prediction generalization capabilities of message-passing GNNs in larger test graphs. In: NeurIPS"},{"key":"10656_CR152","unstructured":"Zhou Z, Zhou C, Li X, Yao J, Yao Q, Han B (2023) On strengthening and defending graph reconstruction attack with Markov chain approximation. In: Krause A, Brunskill E, Cho K, Engelhardt B, Sabato S, Scarlett J (eds) International conference on machine learning, ICML 2023, 23\u201329 July 2023, Honolulu, Hawaii, USA. Proceedings of machine learning research, vol 202, pp 42843\u201342877"},{"key":"10656_CR153","doi-asserted-by":"crossref","unstructured":"Zhuang J, Hasan MA (2022) Defending graph convolutional networks against dynamic graph perturbations via Bayesian self-supervision. CoRR arXiv:2203.03762","DOI":"10.1609\/aaai.v36i4.20362"},{"key":"10656_CR154","doi-asserted-by":"crossref","unstructured":"Zhu D, Zhang Z, Cui P, Zhu W (2019) Robust graph convolutional networks against adversarial attacks. In: Proceedings of the 25th ACM SIGKDD international conference on knowledge discovery & data mining, KDD, pp 1399\u20131407","DOI":"10.1145\/3292500.3330851"},{"key":"10656_CR155","doi-asserted-by":"crossref","unstructured":"Zou X, Zheng Q, Dong Y, Guan X, Kharlamov E, Lu J, Tang J (2021) TDGIA: effective injection attacks on graph neural networks. In: KDD \u201921: The 27th ACM SIGKDD conference on knowledge discovery and data mining, virtual event, pp 2461\u20132471","DOI":"10.1145\/3447548.3467314"},{"key":"10656_CR156","doi-asserted-by":"crossref","unstructured":"Z\u00fcgner D, Akbarnejad A, G\u00fcnnemann S (2018) Adversarial attacks on neural networks for graph data. In: Proceedings of the 24th ACM SIGKDD international conference on knowledge discovery & data mining, KDD, pp 2847\u20132856","DOI":"10.1145\/3219819.3220078"},{"key":"10656_CR157","doi-asserted-by":"crossref","unstructured":"Z\u00fcgner D, G\u00fcnnemann S (2019) Adversarial attacks on graph neural networks via meta learning. In: 7th international conference on learning representations, ICLR","DOI":"10.24963\/ijcai.2019\/872"},{"key":"10656_CR158","doi-asserted-by":"crossref","unstructured":"Z\u00fcgner D, G\u00fcnnemann S (2020) Certifiable robustness of graph convolutional networks under structure perturbations. In: KDD \u201920: the 26th ACM SIGKDD conference on knowledge discovery and data mining, virtual event, pp 1656\u20131665","DOI":"10.1145\/3394486.3403217"},{"key":"10656_CR159","doi-asserted-by":"crossref","unstructured":"Z\u00fcgner D, G\u00fcnnemann S: Certifiable robustness and robust training for graph convolutional networks. In: Proceedings of the 25th ACM SIGKDD international conference on knowledge discovery & data mining, KDD, pp 246\u2013256","DOI":"10.1145\/3292500.3330905"}],"container-title":["Artificial Intelligence Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-023-10656-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10462-023-10656-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-023-10656-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,10]],"date-time":"2024-11-10T21:20:15Z","timestamp":1731273615000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10462-023-10656-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,2,8]]},"references-count":159,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2024,2]]}},"alternative-id":["10656"],"URL":"https:\/\/doi.org\/10.1007\/s10462-023-10656-4","relation":{},"ISSN":["1573-7462"],"issn-type":[{"value":"1573-7462","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,2,8]]},"assertion":[{"value":"19 December 2023","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 February 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"40"}}