{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,14]],"date-time":"2026-03-14T17:59:24Z","timestamp":1773511164891,"version":"3.50.1"},"reference-count":76,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Prime Minister&#x2019;s Research Fellowship","award":["1402107"],"award-info":[{"award-number":["1402107"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Signal Process."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tsp.2024.3514091","type":"journal-article","created":{"date-parts":[[2024,12,11]],"date-time":"2024-12-11T03:26:31Z","timestamp":1733887591000},"page":"83-98","source":"Crossref","is-referenced-by-count":2,"title":["A Unified Optimization-Based Framework for Certifiably Robust and Fair Graph Neural Networks"],"prefix":"10.1109","volume":"73","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6897-6830","authenticated-orcid":false,"given":"Vipul Kumar","family":"Singh","sequence":"first","affiliation":[{"name":"Department of Electrical Engineering, Indian Institute of Technology, Delhi, India"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0415-8625","authenticated-orcid":false,"given":"Sandeep","family":"Kumar","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, Indian Institute of Technology, Delhi, India"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-3422-7114","authenticated-orcid":false,"given":"Avadhesh","family":"Prasad","sequence":"additional","affiliation":[{"name":"Department of Mathematics, Indian Institute of Technology, Delhi, India"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0604-8756","authenticated-orcid":false,"family":"Jayadeva","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, Indian Institute of Technology, Delhi, India"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3357384.3358106"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2022.3164696"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2022.07.030"},{"key":"ref4","article-title":"Semi-supervised classification with graph convolutional networks","author":"Kipf","year":"2016"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2024.3371592"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3183143"},{"key":"ref7","first-page":"1115","article-title":"Adversarial attack on graph structured data","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Dai","year":"2018"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3447556.3447566"},{"key":"ref9","first-page":"7637","article-title":"Robustness of graph neural networks at scale","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Geisler","year":"2021"},{"key":"ref10","first-page":"33146","article-title":"Randomized message-interception smoothing: Gray-box certificates for graph neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"35","author":"Scholten","year":"2022"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/669"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3336191.3371789"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403049"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2019.2957786"},{"key":"ref15","first-page":"9263","article-title":"GNNGuard: Defending graph neural networks against adversarial attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Zhang","year":"2020"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330851"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599335"},{"key":"ref18","first-page":"8954","article-title":"Are defenses for graph neural networks robust","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"35","author":"Mujkanovic","year":"2022"},{"key":"ref19","article-title":"Certifiable robustness to graph perturbations","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Bojchevski","year":"2019"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330905"},{"key":"ref21","first-page":"1003","article-title":"Efficient robustness certificates for discrete data: Sparsity-aware randomized smoothing for graphs, images and more","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bojchevski","year":"2020"},{"key":"ref22","article-title":"Revisiting robustness in graph machine learning","volume-title":"Proc. Eleventh Int. Conf. Learn. Representations (ICLR)","author":"Gosch","year":"2023"},{"key":"ref23","article-title":"Bounding the expected robustness of graph neural networks subject to node feature attacks","author":"Abbahaddou","year":"2024"},{"key":"ref24","article-title":"Certified defenses for data poisoning attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"30","author":"Steinhardt","year":"2017"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2023.3271126"},{"key":"ref26","first-page":"18049","article-title":"Locality sensitive teaching","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Xu","year":"2021"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3551636"},{"key":"ref28","article-title":"Stabilizing GNN for fairness via Lipschitz bounds","volume-title":"Proc. 2nd Workshop New Frontiers Adversarial Mach. Learn.","author":"Jia","year":"2023"},{"issue":"144","key":"ref29","first-page":"1","article-title":"Individual fairness in hindsight","volume":"22","author":"Gupta","year":"2021","journal-title":"J. Mach. Learn. Res."},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2024.102428"},{"key":"ref31","first-page":"2114","article-title":"Towards a unified framework for fair and stable graph representation learning","volume-title":"Proc. Uncertainty Artif. Intell.","author":"Agarwal","year":"2021"},{"key":"ref32","first-page":"4","article-title":"Distributionally robust deep learning as a generalization of adversarial training","volume-title":"Proc. NIPS Workshop Mach. Learn. Comput. Secur.","volume":"3","author":"Staib","year":"2017"},{"key":"ref33","article-title":"Distributionally robust semi-supervised learning over graphs","author":"Sadeghi","year":"2021"},{"key":"ref34","first-page":"2178","article-title":"Generalised Lipschitz regularisation equals distributional robustness","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Cranko","year":"2021"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2020.3026980"},{"key":"ref36","first-page":"1073","article-title":"Robust graph neural networks via probabilistic Lipschitz constraints","volume-title":"Proc. Learn. Dyn. Control Conf.","author":"Arghal","year":"2022"},{"key":"ref37","first-page":"2456","article-title":"Lipschitz normalization for self-attention layers with application to graph neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Dasoulas","year":"2021"},{"key":"ref38","article-title":"Exploiting connections between Lipschitz structures for certifiably robust deep equilibrium models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"36","author":"Havens","year":"2024"},{"key":"ref39","first-page":"22745","article-title":"Training certifiably robust neural networks with efficient local Lipschitz bounds","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Huang","year":"2021"},{"key":"ref40","article-title":"Lipschitz-margin training: Scalable certification of perturbation invariance for deep neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"31","author":"Tsuzuku","year":"2018"},{"key":"ref41","first-page":"854","article-title":"Parseval networks: Improving robustness to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Cisse","year":"2017"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467295"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2023.3311105"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1137\/090774707"},{"key":"ref45","article-title":"Can stable and accurate neural networks be computed?\u2014On the barriers of deep learning and smale\u2019s 18th problem","author":"Colbrook","year":"2021"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3287560.3287589"},{"key":"ref47","first-page":"2879","article-title":"Stable and fair classification","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Huang","year":"2019"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2235192"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2016.2602809"},{"key":"ref50","first-page":"920","article-title":"How to learn a graph from smooth signals","volume-title":"Proc. Artif. Intell. Statist.","author":"Kalofolias","year":"2016"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2021.02.046"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3459637.3482225"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1137\/120891009"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1287\/moor.2019.1010"},{"key":"ref55","article-title":"Successive convex approximation: Analysis and applications","author":"Razaviyayn","year":"2014"},{"issue":"1","key":"ref56","first-page":"785","article-title":"A unified framework for structured graph learning via spectral constraints","volume":"21","author":"Kumar","year":"2020","journal-title":"J. Mach. Learn. Res."},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/s00041-008-9045-x"},{"issue":"3","key":"ref58","first-page":"794","article-title":"Majorization-minimization algorithms in signal processing","volume":"65","author":"Sun","year":"2017","journal-title":"communications and machine learning"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1198\/0003130042836"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611974409"},{"key":"ref61","first-page":"20385","article-title":"A convergence analysis of gradient descent on graph neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Awasthi","year":"2021"},{"key":"ref62","article-title":"UCI machine learning repository","author":"Dua","year":"2017"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467314"},{"key":"ref64","article-title":"Adversarial attacks on graph neural networks via meta learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Z\u00fcgner","year":"2019"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/550"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/SPCOM55316.2022.9840814"},{"key":"ref68","first-page":"3","article-title":"GARNET: Reduced-rank topology learning for robust and scalable graph neural networks","volume-title":"Proc. Learn. Graphs Conf.","author":"Deng","year":"2022"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-020-05929-w"},{"key":"ref70","article-title":"Spectral normalization for generative adversarial networks","author":"Miyato","year":"2018"},{"key":"ref71","first-page":"291","article-title":"Sorting out Lipschitz function approximation","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Anil","year":"2019"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1177\/0049124118782533"},{"key":"ref73","article-title":"Equality of opportunity in supervised learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"29","author":"Hardt","year":"2016"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1145\/2090236.2090255"},{"key":"ref75","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"30","author":"Kusner","year":"2017"},{"key":"ref76","article-title":"FairGNN: Eliminating the discrimination in graph neural networks with limited sensitive attribute information","author":"Dai","year":"2020"}],"container-title":["IEEE Transactions on Signal Processing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/78\/10807692\/10789240.pdf?arnumber=10789240","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,2]],"date-time":"2025-01-02T05:46:57Z","timestamp":1735796817000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10789240\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":76,"URL":"https:\/\/doi.org\/10.1109\/tsp.2024.3514091","relation":{},"ISSN":["1053-587X","1941-0476"],"issn-type":[{"value":"1053-587X","type":"print"},{"value":"1941-0476","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}