On Measuring Unnoticeability of Graph Adversarial Attacks: Observations, New Measure, and Applications
Hyeonsoo Jo, Hyunjin Hwang, Fanchen Bu, Soo Yong Lee, Chanyoung Park, Kijung Shin
Abstract
Adversarial attacks are allegedly unnoticeable. Prior studies have designed attack noticeability measures on graphs, primarily using statistical tests to compare the topology of original and (possibly) attacked graphs. However, we observe two critical limitations in the existing measures. First, because the measures rely on simple rules, attackers can readily enhance their attacks to bypass them, reducing their attack "noticeability" and, yet, maintaining their attack performance. Second, because the measures naively leverage global statistics, such as degree distributions, they may entirely overlook attacks until severe perturbations occur, letting the attacks be almost "totally unnoticeable. " To address the limitations, we introduce HideNSeek, a learnable measure for graph attack noticeability. First, to mitigate the bypass problem, HideNSeek learns to distinguish the original and (potential) attack edges using a learnable edge scorer (LEO), which scores each edge on its likelihood of being an attack. Second, to mitigate the overlooking problem, HideNSeek conducts imbalance-aware aggregation of all the edge scores to obtain the final noticeability score. Using six real-world graphs, we empirically demonstrate that HideNSeek effectively alleviates the observed limitations, and LEO (i.e., our learnable edge scorer) outperforms eleven competitors in distinguishing attack edges under five different attack methods. For an additional application, we show that LEO can boost the performance of robust GNNs by removing attack-like edges.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 79a696ae-da55-4e04-a940-17fab5c54870Builds on9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 416 citations
- SLAPS: Self-Supervision Improves Structure Learning for Graph Neural NetworksBahare Fatemi, Layla El Asri, Seyed Mehran KazemiNeurIPS 2021 · 220 citations
- Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning ApproachYiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh et al.WWW 2020 · 217 citations
- Towards More Practical Adversarial Attacks on Graph Neural NetworksJiaqi Ma, Shuangrui Ding, Qiaozhu MeiNeurIPS 2020 · 160 citations
Related papers
- Understanding and Improving Graph Injection Attack by Promoting UnnoticeabilityYongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma et al.ICLR 2022 · 106 citations
- Robust Heterogeneous Graph Neural Networks against Adversarial AttacksMengmei Zhang, Xiao Wang, Meiqi Zhu, Chuan Shi et al.AAAI 2022 · 55 citations
- Local-Global Defense against Unsupervised Adversarial Attacks on GraphsDi Jin, Bingdao Feng, Siqi Guo, Xiaobao Wang et al.AAAI 2023 · 19 citations
- Graph BackdoorZhaohan Xi, Ren Pang, Shouling Ji, Ting WangUSENIX Security 2021 · 12 citations
- Transferable Hypergraph Attack via Injecting Nodes into Pivotal HyperedgesMeixia He, Peican Zhu, Le Cheng, Yangming Guo et al.AAAI 2026 · 1 citation
