{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T14:39:50Z","timestamp":1781534390417,"version":"3.54.5"},"reference-count":41,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T00:00:00Z","timestamp":1779753600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Jiangsu Province Science and Technology Department","award":["ZL042501"],"award-info":[{"award-number":["ZL042501"]}]},{"award":["ZL042501"],"award-info":[{"award-number":["ZL042501"]}],"id":[{"id":"https:\/\/ror.org\/02mkqta53","id-type":"ROR","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008081","name":"Southeast University","doi-asserted-by":"publisher","award":["CXJH_SEU_25245"],"award-info":[{"award-number":["CXJH_SEU_25245"]}],"id":[{"id":"10.13039\/501100008081","id-type":"DOI","asserted-by":"publisher"}]},{"award":["CXJH_SEU_25245"],"award-info":[{"award-number":["CXJH_SEU_25245"]}],"id":[{"id":"https:\/\/ror.org\/04ct4d772","id-type":"ROR","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>Graph neural networks (GNNs) are highly effective on relational data, yet their performance degrades sharply when graph topology is poisoned before training. Existing defenses usually assume a fixed attack pattern and a fixed graph structure, which makes them brittle when the poisoned graph changes across attacks, perturbation budgets, or deployment conditions. We propose GADD, a game-inspired adversarial distillation framework for robust graph defense. GADD first constructs multiple positive and negative graph views through a homophily-aware graph sampling scheme, allowing the model to learn from both purified and high-risk subgraphs. It then trains a heterogeneous group of student GNNs online, where each student receives global class-distribution knowledge from its peers and local structural knowledge through an adversarial cyclic distillation objective. Finally, GADD replaces uniform ensembling with an entropy-regularized adaptive aggregation rule that assigns graph-adaptive weights according to confidence and inter-model agreement. On Cora, CiteSeer, and PubMed, GADD consistently improves robustness against both Meta and Nettack attacks while preserving clean accuracy. Under the strongest Meta and Nettack settings in the main benchmark, GADD improves the best competing baseline by up to 2.99 and 3.42 percentage points, respectively. Additional ablations show that graph sampling, adversarial distillation, and adaptive aggregation all contribute materially to the final robustness gains.<\/jats:p>","DOI":"10.3390\/info17060527","type":"journal-article","created":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T13:28:21Z","timestamp":1779802101000},"page":"527","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["GADD: Game-Inspired Adversarial Distillation for Robust Graph Defense"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-5546-6286","authenticated-orcid":false,"given":"Yabin","family":"Peng","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China"},{"name":"Purple Mountain Laboratories, Nanjing 211111, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-7039-3159","authenticated-orcid":false,"given":"Chenyu","family":"Zhou","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China"},{"name":"Purple Mountain Laboratories, Nanjing 211111, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1541-3441","authenticated-orcid":false,"given":"Yuchen","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Technology, Information Engineering University, Zhengzhou 450002, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-3990-5569","authenticated-orcid":false,"given":"Kunlin","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing 211189, China"},{"name":"Purple Mountain Laboratories, Nanjing 211111, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Purple Mountain Laboratories, Nanjing 211111, China"},{"name":"Institute of Big Data, Fudan University, Shanghai 200433, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shaoxun","family":"Liu","sequence":"additional","affiliation":[{"name":"Purple Mountain Laboratories, Nanjing 211111, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2026,5,26]]},"reference":[{"key":"ref_1","unstructured":"Kipf, T.N., and Welling, M. (2017, January 24\u201326). Semi-Supervised Classification with Graph Convolutional Networks. Proceedings of the International Conference on Learning Representations, Toulon, France."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Peng, Y., Zhou, C., Cui, H., Duan, T., Chen, H., Zhang, F., and Liu, S. (2026, January 20\u201327). Resilient UAV Swarm with Fast Connectivity Recovery and Extensive Coverage. Proceedings of the AAAI Conference on Artificial Intelligence, Singapore.","DOI":"10.1609\/aaai.v40i2.37060"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Tang, B., Wu, Z., Wu, X., Huang, Q., Chen, J., Lei, S., and Meng, H. (2024, January 20\u201327). SimCalib: Graph Neural Network Calibration Based on Similarity between Nodes. Proceedings of the AAAI Conference on Artificial Intelligence, Vancouver, BC, Canada.","DOI":"10.1609\/aaai.v38i14.29450"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Wang, M., Yang, H., Huang, J., and Cheng, Q. (2024, January 20\u201327). Moderate Message Passing Improves Calibration: A Universal Way to Mitigate Confidence Bias in Graph Neural Networks. Proceedings of the AAAI Conference on Artificial Intelligence, Vancouver, BC, Canada.","DOI":"10.1609\/aaai.v38i19.30167"},{"key":"ref_5","unstructured":"Trivedi, P., Heimann, M., Anirudh, R., Koutra, D., and Thiagarajan, J.J. (2024, January 7\u201311). Accurate and Scalable Estimation of Epistemic Uncertainty for Graph Neural Networks. Proceedings of the Twelfth International Conference on Learning Representations (ICLR), Vienna, Austria."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Xiao, Z., Zhou, Y., Li, D., and Wang, K. (2025). Towards Fair Graph Neural Networks via Counterfactual and Balance. Information, 16.","DOI":"10.3390\/info16080704"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Z\u00fcgner, D., Akbarnejad, A., and G\u00fcnnemann, S. (2018, January 19\u201323). Adversarial Attacks on Neural Networks for Graph Data. Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, London, UK.","DOI":"10.1145\/3219819.3220078"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Z\u00fcgner, D., and G\u00fcnnemann, S. (2019, January 6\u20139). Adversarial Attacks on Graph Neural Networks via Meta Learning. Proceedings of the International Conference on Learning Representations, New Orleans, LA, USA.","DOI":"10.24963\/ijcai.2019\/872"},{"key":"ref_9","unstructured":"Xia, Z., Yang, H., Wang, B., and Jia, J. (2024, January 7\u201311). GNNCert: Deterministic Certification of Graph Neural Networks against Adversarial Perturbations. Proceedings of the Twelfth International Conference on Learning Representations (ICLR), Vienna, Austria."},{"key":"ref_10","unstructured":"Alom, M.Z., Ngo, T.G.B., Kantarcioglu, M., and Ak\u00e7ora, C.G. (2025, January 24\u201328). GOttack: Universal Adversarial Attacks on Graph Neural Networks via Graph Orbits Learning. Proceedings of the Thirteenth International Conference on Learning Representations (ICLR), Singapore."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Peng, Y., Wu, J., Duan, T., Liu, Y., Zhou, C., and Zhang, Z. (2026). Decentralized Topology Robustness Optimization for IoT via Multi-Agent Graph Reinforcement Learning. IEEE Trans. Mob. Comput., in press.","DOI":"10.1109\/TMC.2026.3680228"},{"key":"ref_12","unstructured":"Li, K., Chen, Y., Liu, Y., Wang, J., He, Q., Cheng, M., and Ao, X. (2024, January 7\u201311). Boosting the Adversarial Robustness of Graph Neural Networks: An OOD Perspective. Proceedings of the Twelfth International Conference on Learning Representations (ICLR), Vienna, Austria."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Ennadir, S., Abbahaddou, Y., Lutzeyer, J.F., Vazirgiannis, M., and Bostr\u00f6m, H. (2024, January 20\u201327). A Simple and Yet Fairly Effective Defense for Graph Neural Networks. Proceedings of the AAAI Conference on Artificial Intelligence, Vancouver, BC, Canada.","DOI":"10.1609\/aaai.v38i19.30098"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"112867","DOI":"10.1016\/j.knosys.2024.112867","article-title":"Fortifying graph neural networks against adversarial attacks via ensemble learning","volume":"309","author":"Zhou","year":"2025","journal-title":"Knowl.-Based Syst."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Guo, Y., Yang, C., Shi, C., Tu, K., Wu, Z., Zhang, Z., and Zhou, J. (2024, January 9\u201313). Adaptively Denoising Graph Neural Networks for Knowledge Distillation. Proceedings of the Machine Learning and Knowledge Discovery in Databases: Research Track, Vilnius, Lithuania.","DOI":"10.1007\/978-3-031-70371-3_15"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Huo, C., Huang, X., He, D., Du, Y., Lu, W., and Jin, D. (2026, January 20\u201327). DuoKD: Dual Knowledge Distillation from Large Language Models for Robust Graph Neural Networks. Proceedings of the AAAI Conference on Artificial Intelligence, Singapore.","DOI":"10.1609\/aaai.v40i17.38513"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1023\/A:1009953814988","article-title":"Automating the Construction of Internet Portals with Machine Learning","volume":"3","author":"McCallum","year":"2000","journal-title":"Inf. Retr."},{"key":"ref_18","first-page":"93","article-title":"Collective Classification in Network Data","volume":"29","author":"Sen","year":"2008","journal-title":"AI Mag."},{"key":"ref_19","unstructured":"Abbahaddou, Y., Ennadir, S., Lutzeyer, J.F., Vazirgiannis, M., and Bostr\u00f6m, H. (2024, January 7\u201311). Bounding the Expected Robustness of Graph Neural Networks Subject to Node Feature Attacks. Proceedings of the Twelfth International Conference on Learning Representations (ICLR), Vienna, Austria."},{"key":"ref_20","unstructured":"Sabanayagam, M., Gosch, L., G\u00fcnnemann, S., and Ghoshdastidar, D. (2025, January 24\u201328). Exact Certification of (Graph) Neural Networks Against Label Poisoning. Proceedings of the Thirteenth International Conference on Learning Representations (ICLR), Singapore."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Zeng, X., Li, H., Qi, Q., Wang, J., Deng, H., Sun, H., Zhuang, Z., and Liao, J. (2025, January 10\u201314). Robustness Verification of Deep Graph Neural Networks Tightened by Linear Approximation. Proceedings of the 18th ACM International Conference on Web Search and Data Mining, Hannover, Germany.","DOI":"10.1145\/3701551.3703506"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Wu, H., Wang, C., Tyshetskiy, Y., Docherty, A., Lu, K., and Zhu, L. (2019, January 10\u201316). Adversarial Examples for Graph Data: Deep Insights into Attack and Defense. Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence (IJCAI-19), Macao, China.","DOI":"10.24963\/ijcai.2019\/669"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Jin, W., Ma, Y., Liu, X., Tang, X., Wang, S., and Tang, J. (2020, January 23\u201327). Graph Structure Learning for Robust Graph Neural Networks. Proceedings of the 26th ACM SIGKDD Conference on Knowledge Discovery & Data Mining, Virtual Conference.","DOI":"10.1145\/3394486.3403049"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Yang, H., Wang, M., Wang, Q., Lao, M., and Zhou, Y. (2024, January 25\u201329). Balanced Confidence Calibration for Graph Neural Networks. Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Barcelona, Spain.","DOI":"10.1145\/3637528.3671741"},{"key":"ref_25","unstructured":"Zhuang, D., Jiang, C., Zheng, Y., Wang, S., and Zhao, J. (2025, January 24\u201328). GETS: Ensemble Temperature Scaling for Calibration in Graph Neural Networks. Proceedings of the Thirteenth International Conference on Learning Representations (ICLR), Singapore."},{"key":"ref_26","unstructured":"Bergna, R., Calvo-Ordo\u00f1ez, S., Opolka, F.L., Li\u00f2, P., and Hern\u00e1ndez-Lobato, J.M. (2025, January 24\u201328). Uncertainty Modeling in Graph Neural Networks via Stochastic Differential Equations. Proceedings of the Thirteenth International Conference on Learning Representations (ICLR), Singapore."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Zhu, Y., Li, J., Chen, L., and Zheng, Z. (2024, January 4\u20138). The Devil is in the Data: Learning Fair Graph Neural Networks via Partial Knowledge Distillation. Proceedings of the 17th ACM International Conference on Web Search and Data Mining, M\u00e9rida, Mexico.","DOI":"10.1145\/3616855.3635768"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"108184","DOI":"10.1016\/j.neunet.2025.108184","article-title":"Toward Fair Graph Neural Networks via Dual-Teacher Knowledge Distillation","volume":"194","author":"Li","year":"2026","journal-title":"Neural Netw."},{"key":"ref_29","unstructured":"Hou, Z., Feng, R., Derr, T., and Liu, X. (2024, January 10\u201315). Robust Graph Neural Networks via Unbiased Aggregation. Proceedings of the Advances in Neural Information Processing Systems, Vancouver, BC, Canada."},{"key":"ref_30","unstructured":"Veli\u010dkovi\u0107, P., Cucurull, G., Casanova, A., Romero, A., Li\u00f2, P., and Bengio, Y. (May, January 30). Graph Attention Networks. Proceedings of the International Conference on Learning Representations, Vancouver, BC, Canada."},{"key":"ref_31","unstructured":"Hamilton, W.L., Ying, R., and Leskovec, J. (2017, January 4\u20139). Inductive Representation Learning on Large Graphs. Proceedings of the Advances in Neural Information Processing Systems, Long Beach, CA, USA."},{"key":"ref_32","unstructured":"Zhang, C., Liu, J., Dang, K., and Zhang, W. (March, January 22). Multi-Scale Distillation from Multiple Graph Neural Networks. Proceedings of the AAAI Conference on Artificial Intelligence, Virtual Event."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Guo, Z., Zhang, C., Fan, Y., Tian, Y., Zhang, C., and Chawla, N.V. (2023, January 7\u201314). Boosting Graph Neural Networks via Adaptive Knowledge Distillation. Proceedings of the AAAI Conference on Artificial Intelligence, Washington, DC, USA.","DOI":"10.1609\/aaai.v37i6.25944"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"4375","DOI":"10.1109\/TKDE.2024.3374773","article-title":"A Teacher-Free Graph Knowledge Distillation Framework with Dual Self-Distillation","volume":"36","author":"Wu","year":"2024","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"107810","DOI":"10.1016\/j.neunet.2025.107810","article-title":"A Dynamic Ensemble Learning Model for Robust Graph Neural Networks","volume":"191","author":"Zhou","year":"2025","journal-title":"Neural Netw."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Jin, W., Derr, T., Wang, Y., Ma, Y., Liu, Z., and Tang, J. (2021, January 8\u201312). Node Similarity Preserving Graph Convolutional Networks. Proceedings of the 14th ACM International Conference on Web Search and Data Mining, Virtual Event, Israel.","DOI":"10.1145\/3437963.3441735"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Jia, Y., Zou, D., Wang, H., and Jin, H. (2023, January 6\u201310). Enhancing Node-Level Adversarial Defenses by Lipschitz Regularization of Graph Neural Networks. Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Long Beach, CA, USA.","DOI":"10.1145\/3580305.3599335"},{"key":"ref_38","unstructured":"Hu, W., Fey, M., Zitnik, M., Dong, Y., Ren, H., Liu, B., Catasta, M., and Leskovec, J. (2020, January 6\u201312). Open Graph Benchmark: Datasets for Machine Learning on Graphs. Proceedings of the Advances in Neural Information Processing Systems, Virtual Event."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Xu, K., Chen, H., Liu, S., Chen, P.Y., Weng, T.W., Hong, M., and Lin, X. (2019, January 10\u201316). Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective. Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence, Macao, China.","DOI":"10.24963\/ijcai.2019\/550"},{"key":"ref_40","unstructured":"Deng, C., Li, X., Feng, Z., and Zhang, Z. (2022, January 9\u201312). GARNET: Reduced-Rank Topology Learning for Robust and Scalable Graph Neural Networks. Proceedings of the First Learning on Graphs Conference, Virtual Event. PMLR, Proceedings of Machine Learning Research."},{"key":"ref_41","unstructured":"Yang, Z., Cohen, W., and Salakhudinov, R. (2016, January 19\u201324). Revisiting Semi-Supervised Learning with Graph Embeddings. Proceedings of the 33rd International Conference on Machine Learning, New York City, NY, USA. PMLR, Proceedings of Machine Learning Research."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/17\/6\/527\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T04:16:06Z","timestamp":1780460166000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/17\/6\/527"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,26]]},"references-count":41,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2026,6]]}},"alternative-id":["info17060527"],"URL":"https:\/\/doi.org\/10.3390\/info17060527","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,26]]}}}