[1]HAN Jihui,SHI Yupeng,HUANG Ziqi,et al.A Graph Neural Network for Structure-Feature Collaborative Defense[J].Journal of Zhengzhou University (Engineering Science),2026,47(4):134-142.[doi:10.13705/j.issn.1671-6833.2026.04.010]
Copy
Journal of Zhengzhou University (Engineering Science)[ISSN
1671-6833/CN
41-1339/T] Volume:
47
Number of periods:
2026 Issue 4
Page number:
134-142
Column:
Public date:
2026-07-10
- Title:
-
A Graph Neural Network for Structure-Feature Collaborative Defense
- Author(s):
-
HAN Jihui1, SHI Yupeng1, HUANG Ziqi2, ZHANG Anlin3, HUANG Daoying1
-
1. School of Computer Science and Artificial Intelligence, Zhengzhou University of Light Industry, Zhengzhou 450001, China; 2. North Information Control Research Academy Group Co. , Ltd. , Nanjing 211153, China; 3. Engineering Training Center, Zhengzhou University of Light Industry, Zhengzhou 450001, China
-
- Keywords:
-
graph neural networks; robustness; structure perturbation; feature perturbation; sparse attention
- CLC:
-
TP18TN929. 5
- DOI:
-
10.13705/j.issn.1671-6833.2026.04.010
- Abstract:
-
To address the degradation of node representations in graph neural networks with complex perturbation environments, a structure‑feature collaborative defense graph neural network named SFCoRobustGNN was proposed. Structurally, a sparse attention mechanism that integrated structure priors to dynamically suppress anomalous edges was introduced. Feature‑wise, a channel gating mechanism was combined with a nonlinear feature mixing module (FeatureMixPro) to enhance the model’s adaptability to feature perturbations. A collaborative dual‑pathway defense was achieved through adversarial training and a multi‑objective optimization strategy. Experiments on multiple benchmark datasets, including Cora and Citeseer, demonstrated that the proposed method outperformed most mainstream baseline methods with various intensities of structure perturbations (5%‑40%) and feature attacks (\varepsilon = 0.01‑0.10), showing significant improvement in node classification accuracy. On the large‑scale ogbn‑products dataset, it maintained an accuracy of 71.82% even with a 20% MetaAttack structure perturbation, demonstrating its strong scalability. Ablation studies validated the effectiveness and synergistic effects of each module. The proposed method effectively mitigated performance degradation with complex perturbations and exhibited excellent generalization.