Adversarial Attacks on Deep Graph Matching
Zijie Zhang, Zeru Zhang, Yang Zhou, Yelong Shen, Ruoming Jin, Dejing Dou
摘要
Despite achieving remarkable performance, deep graph learning models, such as node classification and network embedding, suffer from harassment caused by small adversarial perturbations. However, the vulnerability analysis of graph matching under adversarial attacks has not been fully investigated yet. This paper proposes an adversarial attack model with two novel attack techniques to perturb the graph structure and degrade the quality of deep graph matching: (1) a kernel density estimation approach is utilized to estimate and maximize node densities to derive imperceptible perturbations, by pushing attacked nodes to dense regions in two graphs, such that they are indistinguishable from many neighbors; and (2) a meta learning-based projected gradient descent method is developed to well choose attack starting points and to improve the search performance for producing effective perturbations. We evaluate the effectiveness of the attack model on real datasets and validate that the attacks can be transferable to other graph learning models. Recent literature has shown that both traditional and deep graph learning algorithms remain highly sensitive to adversarial attacks, i.e., carefully designed small perturbations in graph structure and attributes can cause the models to produce wrong prediction results [14, 126, 64, 125, 123, 69, 90, 74, 45, 85, 80, 127] . We have witnessed various effective attack models to cause failures of 34th Conference on Neural Information Processing Systems (NeurIPS 2020), Vancouver, Canada.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- Fast Federated Machine Unlearning with Nonlinear Functional TheoryTianshi Che, Yang Zhou, Zijie Zhang, Lingjuan Lyu 等ICML 2023 · 被引用 77 次
- Practical Adversarial Attacks on Spatiotemporal Traffic Forecasting ModelsFan Liu, Hao Liu, Wenzhao JiangNeurIPS 2022 · 被引用 57 次
- Prompt Certified Machine Unlearning with Randomized Gradient Smoothing and QuantizationZijie Zhang, Yang Zhou, Xin Zhao, Tianshi Che 等NeurIPS 2022 · 被引用 56 次
- Expressive 1-Lipschitz Neural Networks for Robust Multiple Graph Learning against Adversarial AttacksXin Zhao, Zeru Zhang, Zijie Zhang, Lingfei Wu 等ICML 2021 · 被引用 33 次
- Input-agnostic Certified Group Fairness via Gaussian Parameter SmoothingJiayin Jin, Zeru Zhang, Yang Zhou, Lingfei WuICML 2022 · 被引用 18 次
它引用的顶会 Paper8
- Rapid Learning or Feature Reuse? Towards Understanding the Effectiveness of MAMLAniruddh Raghu, Maithra Raghu, Samy Bengio, Oriol VinyalsICLR 2020 · 被引用 736 次
- Deep Graph Matching ConsensusMatthias Fey, Jan Eric Lenssen, Christopher Morris, Jonathan Masci 等ICLR 2020 · 被引用 227 次
- Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning ApproachYiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh 等WWW 2020 · 被引用 217 次
- Attacking Graph-based Classification via Manipulating the Graph StructureBinghui Wang, Neil Zhenqiang GongCCS 2019 · 被引用 175 次
- A Restricted Black-Box Adversarial Framework Towards Attacking Graph Embedding ModelsHeng Chang, Yu Rong, Tingyang Xu, Wenbing Huang 等AAAI 2020 · 被引用 171 次
相关 Paper
- Adversarial Attack against Cross-lingual Knowledge Graph AlignmentZeru Zhang, Zijie Zhang, Yang Zhou, Lingfei Wu 等EMNLP 2021 · 被引用 10 次
- Graph Adversarial Attack via RewiringYao Ma, Suhang Wang, Tyler Derr, Lingfei Wu 等KDD 2021 · 被引用 62 次
- Appearance and Structure Aware Robust Deep Visual Graph Matching: Attack, Defense and BeyondQibing Ren, Qingquan Bao, Runzhong Wang, Junchi YanCVPR 2022 · 被引用 10 次
- Uncertainty-Matching Graph Neural Networks to Defend Against Poisoning AttacksUday Shankar Shanthamallu, Jayaraman J. Thiagarajan, Andreas SpaniasAAAI 2021 · 被引用 19 次
- Integrated Defense for Resilient Graph MatchingJiaxiang Ren, Zijie Zhang, Jiayin Jin, Xin Zhao 等ICML 2021 · 被引用 15 次
