Black-box Adversarial Attack and Defense on Graph Neural Networks
Haoyang Li, Shimin Di, Zijian Li, Lei Chen, Jiannong Cao
摘要
Graph neural networks (GNNs) have achieved great success on various graph tasks. However, recent studies have re-vealed that GNNs are vulnerable to adversarial attacks, including topology modifications and feature perturbations. Regardless of the fruitful progress, existing attackers require node labels and GNN parameters to optimize a bi-level problem, or cannot cover both topology modifications and feature perturbations, which are not practical, efficient, or effective. In this paper, we propose a black-box attacker PEEGA, which is restricted to access node features and graph topology for practicability. Specifically, we propose to measure the negative impact of various adversarial attacks from the perspective of node representations, thereby we formulate a single-level problem that can be efficiently solved. Furthermore, we observe that existing attackers tend to blur the context of nodes through adding edges between nodes with different labels. As a result, GNNs are unable to recognize nodes. Based on this observation, we propose a GNN defender GNAT, which incorporates three augmented graphs, i.e., a topology graph, a feature graph, and an ego graph, to make the context of nodes more distinguishable. Extensive experiments on three real-world datasets demonstrate the effectiveness and efficiency of our proposed attacker, despite the fact that we do not access node labels and GNN parameters. Moreover, the effectiveness and efficiency of our proposed defender are also validated by substantial experiments.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- Revisiting Injective Attacks on Recommender SystemsHaoyang Li, Shimin Di, Lei ChenNeurIPS 2022 · 被引用 26 次
- Uplift Modeling for Target User Attacks on Recommender SystemsWenjie Wang, Changsheng Wang, Fuli Feng, Wentao Shi 等WWW 2024 · 被引用 11 次
- Message Function Search for Knowledge Graph EmbeddingShimin Di, Lei ChenWWW 2023 · 被引用 10 次
- A Message Passing Neural Network Space for Better Capturing Data-dependent Receptive FieldsZhili Wang, Shimin Di, Lei ChenKDD 2023 · 被引用 8 次
- Adversarial Attacks on Fairness of Graph Neural NetworksBinchi Zhang, Yushun Dong, Chen Chen, Yada Zhu 等ICLR 2024 · 被引用 8 次
它引用的顶会 Paper24
- Graph Contrastive Learning with AugmentationsYuning You, Tianlong Chen, Yongduo Sui, Ting Chen 等NeurIPS 2020 · 被引用 3,042 次
- DropEdge: Towards Deep Graph Convolutional Networks on Node ClassificationYu Rong, Wenbing Huang, Tingyang Xu, Junzhou HuangICLR 2020 · 被引用 1,599 次
- Graph Contrastive Learning with Adaptive AugmentationYanqiao Zhu, Yichen Xu, Feng Yu, Qiang Liu 等WWW 2021 · 被引用 1,415 次
- Measuring and Relieving the Over-Smoothing Problem for Graph Neural Networks from the Topological ViewDeli Chen, Yankai Lin, Wei Li, Peng Li 等AAAI 2020 · 被引用 1,353 次
- Parameterized Explainer for Graph Neural NetworkDongsheng Luo, Wei Cheng, Dongkuan Xu, Wenchao Yu 等NeurIPS 2020 · 被引用 888 次
相关 Paper
- A Hard Label Black-box Adversarial Attack Against Graph Neural NetworksJiaming Mu, Binghui Wang, Qi Li, Kun Sun 等CCS 2021 · 被引用 30 次
- Fight Fire with Fire: Towards Robust Graph Neural Networks on Dynamic Graphs via Actively DefenseHaoyang Li, Shimin Di, Calvin Hong Yi Li, Lei Chen 等VLDB 2024 · 被引用 6 次
- Devil in Disguise: Breaching Graph Neural Networks Privacy through InfiltrationLingshuo Meng, Yijie Bai, Yanjiao Chen, Yutong Hu 等CCS 2023 · 被引用 9 次
- Bandits for Structure Perturbation-based Black-box Attacks to Graph Neural Networks with Theoretical GuaranteesBinghui Wang, Youqi Li, Pan ZhouCVPR 2022 · 被引用 16 次
- TDGIA: Effective Injection Attacks on Graph Neural NetworksXu Zou, Qinkai Zheng, Yuxiao Dong, Xinyu Guan 等KDD 2021 · 被引用 83 次
