Revisiting Graph Adversarial Attack and Defense From a Data Distribution Perspective
Kuan Li, Yang Liu, Xiang Ao, Qing He
摘要
Recent studies have shown that structural perturbations are significantly effective in degrading the accuracy of Graph Neural Networks (GNNs) in the semi-supervised node classification (SSNC) task. However, the reasons for the destructive nature of gradient-based methods have not been explored in-depth. In this work, we discover an interesting phenomenon: the adversarial edges are not uniformly distributed on the graph, and a majority of perturbations are generated around the training nodes in poisoning attacks. Combined with this phenomenon, we provide an explanation for the effectiveness of the gradient-based attack method from a data distribution perspective and revisit both poisoning attack and evasion attack in SSNC. From this new perspective, we empirically and theoretically discuss some other attack tendencies. Based on the analysis, we provide nine practical tips on both attack and defense and meanwhile leverage them to improve existing attack and defense methods. Moreover, we design a fast attack method and a self-training defense method, which outperform the state-of-the-art methods and can effectively scale to large graphs like ogbn-arxiv. We validate our claims through extensive experiments on four benchmark datasets. * Corresponding to Xiang Ao implementation details and the statistics of the datasets are provided in A.1. RELATED WORK Many efforts have been made to study various properties of the gradient-based attack algorithms. GCN-SVD Entezari et al. (2020) discovers that attacks exhibit a specific behavior in the spectrum 1 Our focus is to revisit both attack and defense sides from a new view. These two algorithms are natural byproducts of this work, so we put them in the appendix.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper17
- Demystifying Structural Disparity in Graph Neural Networks: Can One Size Fit All?Haitao Mao, Zhikai Chen, Wei Jin, Haoyu Han 等NeurIPS 2023 · 被引用 58 次
- FLOOD: A Flexible Invariant Learning Framework for Out-of-Distribution Generalization on GraphsYang Liu, Xiang Ao, Fuli Feng, Yunshan Ma 等KDD 2023 · 被引用 40 次
- Boosting the Adversarial Robustness of Graph Neural Networks: An OOD PerspectiveKuan Li, Yiwen Chen, Yang Liu, Jin Wang 等ICLR 2024 · 被引用 13 次
- SPEAR: A Structure-Preserving Manipulation Method for Graph Backdoor AttacksYuanhao Ding, Yang Liu, Yugang Ji, Weigao Wen 等WWW 2025 · 被引用 12 次
- Can Large Language Models Improve the Adversarial Robustness of Graph Neural Networks?Zhongjian Zhang, Xiao Wang, Huichi Zhou, Yue Yu 等KDD 2025 · 被引用 11 次
它引用的顶会 Paper17
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong 等NeurIPS 2020 · 被引用 3,935 次
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang 等KDD 2020 · 被引用 604 次
- Pick and Choose: A GNN-based Imbalanced Learning Approach for Fraud DetectionYang Liu, Xiang Ao, Zidi Qin, Jianfeng Chi 等WWW 2021 · 被引用 527 次
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 被引用 416 次
- A Fine-Grained Analysis on Distribution ShiftOlivia Wiles, Sven Gowal, Florian Stimberg, Sylvestre-Alvise Rebuffi 等ICLR 2022 · 被引用 258 次
相关 Paper
- Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary PerturbationsJiate Li, Meng Pang, Yun Dong, Binghui WangCVPR 2025
- Turning Strengths into Weaknesses: A Certified Robustness Inspired Attack Framework against Graph Neural NetworksBinghui Wang, Meng Pang, Yun DongCVPR 2023
- Graph BackdoorZhaohan Xi, Ren Pang, Shouling Ji, Ting WangUSENIX Security 2021 · 被引用 12 次
- Graph Structural Attack by Perturbing Spectral DistanceLu Lin, Ethan Blaser, Hongning WangKDD 2022 · 被引用 28 次
- Rethinking Label Poisoning for GNNs: Pitfalls and AttacksVijay Lingam, Mohammad Sadegh Akhondzadeh, Aleksandar BojchevskiICLR 2024 · 被引用 8 次
