Return
Structural complementary hypergraph defense framework against adversarial attacks
DOI:10.1016/j.knosys.2025.114897.png)
Abstract
En 中文
Hypergraph Neural Networks (HGNNs) effectively capture high-order dependencies, which also makes them vulnerable to adversarial structural attacks. Existing defense methods mainly focus on conventional graph neural networks, while the vulnerability of HGNNs remains underexplored. To mitigate the issue, we propose a robust hypergraph framework named Structural COmplementary hyPergraph dEfense (SCOPE). In the training phase, SCOPE jointly trains the complementary structural dependency branches. The deep structural dependency branch captures high-order semantics through multi-round message passing. The shallow structural dependency branch diminishes the reliance on hyperedges to reduce the sensitivity of structural perturbations. Then, the contrastive learning is employed to align the hyperedge embeddings of the two branches, enabling the shallow branch to absorb high-order semantics from the deep branch while maintaining robustness. To further remove unreliable connections, we design a structural purification strategy that combines weighted clique expansion and feature similarity filtering. On the purified graph, we introduce a prediction smoothing regularization to enforce smoothness among nodes that are semantically similar and structurally closely connected. During the inference phase, only the shallow branch is employed for structural robustness and efficiency. We compare SCOPE with 17 baselines under both poisoning and evasion attack scenarios. The results demonstrate that SCOPE consistently outperforms existing HGNNs, achieving both high-order representation ability and robustness.
Journal
K
IF:
7.6
Papers:
1.2W
Citations:
4.5W

