{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T17:13:47Z","timestamp":1780766027884,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":52,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,8,14]],"date-time":"2022-08-14T00:00:00Z","timestamp":1660435200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100006785","name":"NVIDIA","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100006785","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1845491"],"award-info":[{"award-number":["1845491"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Amazon"},{"name":"Google"},{"name":"Army Research Office"},{"DOI":"10.13039\/100000183","name":"Adobe Systems","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100004344","name":"Ministerium f\u00fcr Kultur und Wissenschaft des Landes Nordrhein-Westfalen","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100004344","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,8,14]]},"DOI":"10.1145\/3534678.3539418","type":"proceedings-article","created":{"date-parts":[[2022,8,12]],"date-time":"2022-08-12T19:06:12Z","timestamp":1660331172000},"page":"2637-2647","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":27,"title":["How does Heterophily Impact the Robustness of Graph Neural Networks?"],"prefix":"10.1145","author":[{"given":"Jiong","family":"Zhu","sequence":"first","affiliation":[{"name":"University of Michigan, Ann Arbor, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Junchen","family":"Jin","sequence":"additional","affiliation":[{"name":"Northwestern University, Evanston, IL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Donald","family":"Loveland","sequence":"additional","affiliation":[{"name":"University of Michigan, Ann Arbor, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael T.","family":"Schaub","sequence":"additional","affiliation":[{"name":"RWTH Aachen University, Aachen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Danai","family":"Koutra","sequence":"additional","affiliation":[{"name":"University of Michigan, Ann Arbor, MI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,8,14]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"ICML","author":"Abu-El-Haija Sami","year":"2019","unstructured":"Sami Abu-El-Haija, Bryan Perozzi, Amol Kapoor, Hrayr Harutyunyan, Nazanin Alipourfard, Kristina Lerman, Greg Ver Steeg, and Aram Galstyan. Mixhop: Higher-order graph convolution architectures via sparsified neighborhood mixing. In ICML, 2019."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i5.16514"},{"key":"e_1_3_2_1_3_1","volume-title":"ICML","author":"Bojchevski Aleksandar","year":"2019","unstructured":"Aleksandar Bojchevski and Stephan G\u00fc nnemann. Adversarial attacks on node embeddings via graph poisoning. In ICML, 2019 a."},{"key":"e_1_3_2_1_4_1","volume-title":"NeurIPS","author":"Bojchevski Aleksandar","year":"2019","unstructured":"Aleksandar Bojchevski and Stephan G\u00fc nnemann. Certifiable robustness to graph perturbations. In NeurIPS, 2019 b."},{"key":"e_1_3_2_1_5_1","volume-title":"ICML","author":"Bojchevski Aleksandar","year":"2020","unstructured":"Aleksandar Bojchevski, Johannes Klicpera, and Stephan G\u00fcnnemann. Efficient robustness certificates for discrete data: Sparsity-aware randomized smoothing for graphs, images and more. In ICML, 2020."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2017.2693418"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5741"},{"key":"e_1_3_2_1_8_1","volume-title":"ICLR","author":"Chien Eli","year":"2021","unstructured":"Eli Chien, Jianhao Peng, Pan Li, and Olgica Milenkovic. Adaptive universal generalized pagerank graph neural network. In ICLR, 2021."},{"key":"e_1_3_2_1_9_1","first-page":"1310","volume-title":"ICML","author":"Cohen Jeremy","year":"2019","unstructured":"Jeremy Cohen, Elan Rosenfeld, and Zico Kolter. Certified adversarial robustness via randomized smoothing. In ICML, pp. 1310--1320. PMLR, 2019."},{"key":"e_1_3_2_1_10_1","volume-title":"ICML","author":"Dai Hanjun","year":"2018","unstructured":"Hanjun Dai, Hui Li, Tian Tian, Xin Huang, Lin Wang, Jun Zhu, and Le Song. Adversarial attack on graph structured data. In ICML, 2018."},{"key":"e_1_3_2_1_11_1","volume-title":"CIKM","author":"Dong Yushun","year":"2021","unstructured":"Yushun Dong, Kaize Ding, Brian Jalaian, Shuiwang Ji, and Jundong Li. Adagnn: Graph neural networks with adaptive frequency response filter. In CIKM, 2021."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3336191.3371789"},{"key":"e_1_3_2_1_13_1","volume-title":"NeurIPS","author":"Geisler Simon","year":"2020","unstructured":"Simon Geisler, Daniel Z\u00fcgner, and Stephan G\u00fcnnemann. Reliable graph neural networks via robust aggregation. In NeurIPS, 2020."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177705148"},{"key":"e_1_3_2_1_15_1","volume-title":"NeurIPS","author":"Hamilton Will","year":"2017","unstructured":"Will Hamilton, Zhitao Ying, and Jure Leskovec. Inductive representation learning on large graphs. In NeurIPS, 2017."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403049"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447556.3447566"},{"key":"e_1_3_2_1_18_1","volume-title":"ICLR","author":"Thomas","year":"2017","unstructured":"Thomas N. Kipf and Max Welling. Semi-supervised classification with graph convolutional networks. In ICLR, 2017."},{"key":"e_1_3_2_1_19_1","volume-title":"ICLR","author":"Klicpera Johannes","year":"2018","unstructured":"Johannes Klicpera, Aleksandar Bojchevski, and Stephan G\u00fcnnemann. Predict then propagate: Graph neural networks meet personalized pagerank. In ICLR, 2018."},{"key":"e_1_3_2_1_20_1","volume-title":"NeurIPS","author":"Klicpera Johannes","year":"2019","unstructured":"Johannes Klicpera, Stefan Wei\u00dfenberger, and Stephan G\u00fcnnemann. Diffusion improves graph learning. In NeurIPS, 2019."},{"key":"e_1_3_2_1_21_1","volume-title":"NeurIPS","author":"Lee Guang-He","year":"2019","unstructured":"Guang-He Lee, Yang Yuan, Shiyu Chang, and Tommi Jaakkola. Tight certificates of adversarial robustness for randomly smoothed classifiers. In NeurIPS, 2019."},{"key":"e_1_3_2_1_22_1","unstructured":"Jure Leskovec and Andrej Krevl. SNAP Datasets: Stanford large network dataset collection. http:\/\/snap.stanford.edu\/data June 2014."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/1081870.1081893"},{"key":"e_1_3_2_1_24_1","volume-title":"WebConf","author":"Zhang Honglei","year":"2020","unstructured":"Li, Honglei Zhang, Zhichao Han, Yu Rong, Hong Cheng, and Junzhou Huang. Adversarial attack on community detection by hiding individuals. In WebConf, 2020 a."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-86520-7_28"},{"key":"e_1_3_2_1_26_1","volume-title":"Deeprobust: A pytorch library for adversarial attacks and defenses. arXiv preprint arXiv:2005.06149","author":"Li Yaxin","year":"2020","unstructured":"Yaxin Li, Wei Jin, Han Xu, and Jiliang Tang. Deeprobust: A pytorch library for adversarial attacks and defenses. arXiv preprint arXiv:2005.06149, 2020 b."},{"key":"e_1_3_2_1_27_1","volume-title":"NeurIPS","author":"Lim Derek","year":"2021","unstructured":"Derek Lim, Felix Hohne, Xiuyu Li, Sijia Linda Huang, Vaishnavi Gupta, Omkar Bhalerao, and Ser Nam Lim. Large scale learning on non-homophilous graphs: New benchmarks and strong simple methods. In NeurIPS, 2021."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3134200"},{"key":"e_1_3_2_1_29_1","volume-title":"DLG-KDD","author":"Loveland Donald","year":"2022","unstructured":"Donald Loveland, Jiong Zhu, Mark Heimann, Ben Fish, Michael Schaub, and Danai Koutra. On graph neural network fairness in the presence of heterophilous neighborhoods. In DLG-KDD, 2022."},{"key":"e_1_3_2_1_30_1","volume-title":"NeurIPS","author":"Ma Jiaqi","year":"2020","unstructured":"Jiaqi Ma, Shuangrui Ding, and Qiaozhu Mei. Towards more practical adversarial attacks on graph neural networks. In NeurIPS, 2020."},{"key":"e_1_3_2_1_31_1","volume-title":"ICLR","author":"Ma Yao","year":"2022","unstructured":"Yao Ma, Xiaorui Liu, Neil Shah, and Jiliang Tang. Is homophily a necessity for graph neural networks? In ICLR, 2022."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1009953814988"},{"key":"e_1_3_2_1_33_1","volume-title":"MLG","author":"Namata Galileo","year":"2012","unstructured":"Galileo Namata, Ben London, Lise Getoor, and Bert Huang. Query-driven active surveying for collective classification. In MLG, 2012."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611974973.49"},{"key":"e_1_3_2_1_35_1","volume-title":"ICLR","author":"Pei Hongbin","year":"2020","unstructured":"Hongbin Pei, Bingzhe Wei, Kevin Chen-Chuan Chang, Yu Lei, and Bo Yang. Geom-gcn: Geometric graph convolutional networks. In ICLR, 2020."},{"key":"e_1_3_2_1_36_1","volume-title":"Collective classification in network data. AI magazine","author":"Sen Prithviraj","year":"2008","unstructured":"Prithviraj Sen, Galileo Namata, Mustafa Bilgic, Lise Getoor, Brian Galligher, and Tina Eliassi-Rad. Collective classification in network data. AI magazine, 2008."},{"key":"e_1_3_2_1_37_1","volume-title":"Adversarial attack and defense on graph data: A survey. arXiv preprint arXiv:1812.10528","author":"Sun Lichao","year":"2020","unstructured":"Lichao Sun, Yingtong Dou, Carl Yang, Ji Wang, Philip S Yu, Lifang He, and Bo Li. Adversarial attack and defense on graph data: A survey. arXiv preprint arXiv:1812.10528, 2020."},{"key":"e_1_3_2_1_38_1","volume-title":"Big Data","author":"Takahashi Tsubasa","year":"2019","unstructured":"Tsubasa Takahashi. Indirect adversarial attacks via poisoning neighbors for graph convolutional networks. In Big Data. IEEE, 2019."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.physa.2011.12.021"},{"key":"e_1_3_2_1_40_1","volume-title":"ICLR","author":"Veli\u010dkovi\u0107 Petar","year":"2018","unstructured":"Petar Veli\u010dkovi\u0107, Guillem Cucurull, Arantxa Casanova, Adriana Romero, Pietro Li\u00f2, and Yoshua Bengio. Graph Attention Networks. ICLR, 2018."},{"key":"e_1_3_2_1_41_1","first-page":"10","article-title":"Adversarial examples for graph data: Deep insights into attack and defense","author":"Wu Huijun","year":"2019","unstructured":"Huijun Wu, Chen Wang, Yuriy Tyshetskiy, Andrew Docherty, Kai Lu, and Liming Zhu. Adversarial examples for graph data: Deep insights into attack and defense. In IJCAI, 2019. 10.24963\/ijcai.2019\/669.","journal-title":"IJCAI"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/550"},{"key":"e_1_3_2_1_43_1","first-page":"5449","volume-title":"ICML","volume":"80","author":"Xu Keyulu","year":"2018","unstructured":"Keyulu Xu, Chengtao Li, Yonglong Tian, Tomohiro Sonobe, Ken-ichi Kawarabayashi, and Stefanie Jegelka. Representation learning on graphs with jumping knowledge networks. In ICML, volume 80, pp. 5449--5458. PMLR, 2018."},{"key":"e_1_3_2_1_44_1","volume-title":"Two sides of the same coin: Heterophily and oversmoothing in graph convolutional neural networks. arXiv preprint arXiv:2102.06462","author":"Yan Yujun","year":"2021","unstructured":"Yujun Yan, Milad Hashemi, Kevin Swersky, Yaoqing Yang, and Danai Koutra. Two sides of the same coin: Heterophily and oversmoothing in graph convolutional neural networks. arXiv preprint arXiv:2102.06462, 2021."},{"key":"e_1_3_2_1_45_1","volume-title":"NeurIPS","author":"Zhang Xiang","year":"2020","unstructured":"Xiang Zhang and Marinka Zitnik. Gnnguard: Defending graph neural networks against adversarial attacks. In NeurIPS, 2020."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330851"},{"key":"e_1_3_2_1_47_1","volume-title":"NeurIPS","author":"Zhu Jiong","year":"2020","unstructured":"Jiong Zhu, Yujun Yan, Lingxiao Zhao, Mark Heimann, Leman Akoglu, and Danai Koutra. Beyond homophily in graph neural networks: Current limitations and effective designs. In NeurIPS, 2020."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i12.17332"},{"key":"e_1_3_2_1_49_1","volume-title":"ICLR","author":"Z\u00fcgner Daniel","year":"2019","unstructured":"Daniel Z\u00fcgner and Stephan G\u00fcnnemann. Adversarial attacks on graph neural networks via meta learning. In ICLR, 2019 a."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330905"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403217"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"}],"event":{"name":"KDD '22: The 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Washington DC USA","acronym":"KDD '22","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3534678.3539418","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3534678.3539418","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3534678.3539418","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:02:48Z","timestamp":1750186968000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3534678.3539418"}},"subtitle":["Theoretical Connections and Practical Implications"],"short-title":[],"issued":{"date-parts":[[2022,8,14]]},"references-count":52,"alternative-id":["10.1145\/3534678.3539418","10.1145\/3534678"],"URL":"https:\/\/doi.org\/10.1145\/3534678.3539418","relation":{},"subject":[],"published":{"date-parts":[[2022,8,14]]},"assertion":[{"value":"2022-08-14","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}