Defending Graph Neural Networks against Adversarial Attacks