Graph Structural Attack by Perturbing Spectral Distance
Lu Lin, Ethan Blaser, Hongning Wang
摘要
Graph Convolutional Networks (GCNs) have fueled a surge of research interest due to their encouraging performance on graph learning tasks, but they are also shown vulnerability to adversarial attacks. In this paper, an effective graph structural attack is investigated to disrupt graph spectral filters in the Fourier domain, which are the theoretical foundation of GCNs. We define the notion of spectral distance based on the eigenvalues of graph Laplacian to measure the disruption of spectral filters. We realize the attack by maximizing the spectral distance and propose an efficient approximation to reduce the time complexity brought by eigen-decomposition. The experiments demonstrate the remarkable effectiveness of the proposed attack in both black-box and white-box settings for both test-time evasion attacks and training-time poisoning attacks. Our qualitative analysis suggests the connection between the imposed spectral changes in the Fourier domain and the attack behavior in the spatial domain, which provides empirical evidence that maximizing spectral distance is an effective way to change the graph structural property and thus disturb the frequency components for graph filters to affect the learning of GCNs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Graph Contrastive Backdoor AttacksHangfan Zhang, Jinghui Chen, Lu Lin, Jinyuan Jia 等ICML 2023 · 被引用 25 次
- Community-Invariant Graph Contrastive LearningShiyin Tan, Dongyuan Li, Renhe Jiang, Ying Zhang 等ICML 2024 · 被引用 16 次
- Globally Interpretable Graph Learning via Distribution MatchingYi Nian, Yurui Chang, Wei Jin, Lu LinWWW 2024 · 被引用 11 次
- Deceptive Fairness Attacks on Graphs via Meta LearningJian Kang, Yinglong Xia, Ross Maciejewski, Jiebo Luo 等ICLR 2024 · 被引用 9 次
- Adversarial Attacks on Fairness of Graph Neural NetworksBinchi Zhang, Yushun Dong, Chen Chen, Yada Zhu 等ICLR 2024 · 被引用 8 次
它引用的顶会 Paper9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- DropEdge: Towards Deep Graph Convolutional Networks on Node ClassificationYu Rong, Wenbing Huang, Tingyang Xu, Junzhou HuangICLR 2020 · 被引用 1,599 次
- Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning ApproachYiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh 等WWW 2020 · 被引用 217 次
- Attacking Graph-based Classification via Manipulating the Graph StructureBinghui Wang, Neil Zhenqiang GongCCS 2019 · 被引用 175 次
- A Restricted Black-Box Adversarial Framework Towards Attacking Graph Embedding ModelsHeng Chang, Yu Rong, Tingyang Xu, Wenbing Huang 等AAAI 2020 · 被引用 171 次
相关 Paper
- Not All Low-Pass Filters are Robust in Graph Convolutional NetworksHeng Chang, Yu Rong, Tingyang Xu, Yatao Bian 等NeurIPS 2021 · 被引用 65 次
- Robust Mid-Pass Filtering Graph Convolutional NetworksJincheng Huang, Lun Du, Xu Chen, Qiang Fu 等WWW 2023 · 被引用 57 次
- Power up! Robust Graph Convolutional Network via Graph PoweringMing Jin, Heng Chang, Wenwu Zhu, Somayeh SojoudiAAAI 2021 · 被引用 31 次
- Blindfolded Attackers Still Threatening: Strict Black-Box Adversarial Attacks on GraphsJiarong Xu, Yizhou Sun, Xin Jiang, Yanhao Wang 等AAAI 2022 · 被引用 16 次
- EvenNet: Ignoring Odd-Hop Neighbors Improves Robustness of Graph Neural NetworksRunlin Lei, Zhen Wang, Yaliang Li, Bolin Ding 等NeurIPS 2022 · 被引用 72 次
