{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/provably-robust-explainable-graph-neural","title":"Provably Robust Explainable Graph Neural Networks against Graph Perturbation Attacks","arxiv_id":"2502.04224","date":"2025-02-06","proceeding":null,"authors":["Jiate Li","Meng Pang","Yun Dong","Jinyuan Jia","Binghui Wang"],"abstract":"Explaining Graph Neural Network (XGNN) has gained growing attention to facilitate the trust of using GNNs, which is the mainstream method to learn graph data. Despite their growing attention, Existing XGNNs focus on improving the explanation performance, and its robustness under attacks is largely unexplored. We noticed that an adversary can slightly perturb the graph structure such that the explanation result of XGNNs is largely changed. Such vulnerability of XGNNs could cause serious issues particularly in safety/security-critical applications. In this paper, we take the first step to study the robustness of XGNN against graph perturbation attacks, and propose XGNNCert, the first provably robust XGNN. Particularly, our XGNNCert can provably ensure the explanation result for a graph under the worst-case graph perturbation attack is close to that without the attack, while not affecting the GNN prediction, when the number of perturbed edges is bounded. Evaluation results on multiple graph datasets and GNN explainers show the effectiveness of XGNNCert.","url_abs":"https://arxiv.org/abs/2502.04224v1","url_pdf":"https://arxiv.org/pdf/2502.04224v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"links_only","authors_date_abstract":"arXiv metadata, CC0 1.0 (https://info.arxiv.org/help/license), from the Kaggle arXiv metadata snapshot of 2026-09-12"},"code_links":[{"paper_slug":"provably-robust-explainable-graph-neural","repo_url":"https://github.com/JetRichardLee/XGNNCert","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2502.04224","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2502.04224"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/JetRichardLee/XGNNCert","reach":null}],"summary":{"ran_draft_wrong":2,"ran":1},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":3,"samples":[{"code_sha256_prefix":"1c3bb95ccdd24037","entry":"PGM_perturb_node_features","repo":"jetrichardlee/xgnncert","repo_kind":"official","path":"graphxai/utils/perturb/perturb.py","file_url":"https://github.com/jetrichardlee/xgnncert/blob/HEAD/graphxai/utils/perturb/perturb.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"1c3bb95ccdd24037"}},{"code_sha256_prefix":"49008e989200ac97","entry":"RobustClassifier","repo":"JetRichardLee/XGNNCert","repo_kind":"official","path":"robust_p.py","file_url":"https://github.com/JetRichardLee/XGNNCert/blob/HEAD/robust_p.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"49008e989200ac97"}},{"code_sha256_prefix":"f9598672152517d3","entry":"perturb_node_features","repo":"jetrichardlee/xgnncert","repo_kind":"official","path":"graphxai/utils/perturb/perturb.py","file_url":"https://github.com/jetrichardlee/xgnncert/blob/HEAD/graphxai/utils/perturb/perturb.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"f9598672152517d3"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}