NeurIPS 2020

GNNGuard: Defending Graph Neural Networks against Adversarial Attacks

Meta Review

Three reviewers participated in the discussion. The main concern was that the proposed method works only on graphs with homophily. Although the rebuttal gives an example where structural similarity of nodes can also be used to design defense strategies, it is still some sort of assumption on the graph. That said, some reviewers pointed out that this is not a deal-breaking limitation, since the assumptions are clearly stated in the paper. The reviewers also agreed that the proposed method is simple yet effective. However the lack of theoretical guarantees is another limitation that may be interesting to explore in future work.