Value at Adversarial Risk: A Graph Defense Strategy against Cost-Aware Attacks
Junlong Liao, Wenda Fu, Cong Wang, Zhongyu Wei, Jiarong Xu
Abstract
Deep learning methods on graph data have achieved remarkable efficacy across a variety of real-world applications, such as social network analysis and transaction risk detection. Nevertheless, recent studies have illuminated a concerning fact: even the most expressive Graph Neural Networks (GNNs) are vulnerable to graph adversarial attacks. While several methods have been proposed to enhance the robustness of GNN models against adversarial attacks, few have focused on a simple yet realistic approach: valuing the adversarial risks and focused safeguards at the node level. This empowers defenders to allocate heightened security level to vulnerable nodes, while lower to robust nodes. With this new perspective, we propose a novel graph defense strategy RisKeeper, such that the adversarial risk can be directly kept in the input graph. We start at valuing the adversarial risk, by introducing a cost-aware gradient-based graph adversarial attack that takes into account not only cost avoidance and compliance with cost budgets but also addresses the challenges posed by discrete graph data. Subsequently, we present a learnable approach to ascertain the ideal security level for each individual node by solving a bi-level optimization problem. Through extensive experiments on four realworld datasets, we demonstrate that our method achieves superior performance surpassing state-of-the-art methods. Our in-depth case studies provide further insights into vulnerable and robust structural patterns, serving as inspiration for practitioners to exercise heightened vigilance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a426427d-a6bf-48c3-b607-a239f6c37f09Cited by top-tier papers2
- Can Graph Neural Networks Expose Training Data Properties? An Efficient Risk Assessment ApproachHanyang Yuan, Jiarong Xu, Renhong Huang, Mingli Song et al.NeurIPS 2024 · 3 citations
- Unveiling Privacy Vulnerabilities: Investigating the Role of Structure in Graph DataHanyang Yuan, Jiarong Xu, Cong Wang, Ziqi Yang et al.KDD 2024 · 2 citations
Builds on8
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang et al.KDD 2020 · 604 citations
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 416 citations
- Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning ApproachYiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh et al.WWW 2020 · 217 citations
- Reliable Graph Neural Networks via Robust AggregationSimon Geisler, Daniel Zügner, Stephan GünnemannNeurIPS 2020 · 95 citations
- Rethinking Graph Convolutional Networks in Knowledge Graph CompletionZhanqiu Zhang, Jie Wang, Jieping Ye, Feng WuWWW 2022 · 83 citations
Related papers
- Fight Fire with Fire: Towards Robust Graph Neural Networks on Dynamic Graphs via Actively DefenseHaoyang Li, Shimin Di, Calvin Hong Yi Li, Lei Chen et al.VLDB 2024 · 6 citations
- HyperDefender: A Robust Framework for Hyperbolic GNNsNikita Malik, Rahul Gupta, Sandeep KumarAAAI 2025 · 6 citations
- Practical Attacks Against Graph-based ClusteringYizheng Chen, Yacin Nadji, Athanasios Kountouras, Fabian Monrose et al.CCS 2017 · 90 citations
- Adversarial Attacks on Graph Classifiers via Bayesian OptimisationXingchen Wan, Henry Kenlay, Robin Ru, Arno Blaas et al.NeurIPS 2021 · 27 citations
- Inference Attacks Against Graph Neural NetworksZhikun Zhang, Min Chen, Michael Backes, Yun Shen et al.USENIX Security 2022
