Bounding the Expected Robustness of Graph Neural Networks Subject to Node Feature Attacks