Adversarial Attacks on Graph Classifiers via Bayesian Optimisation
Xingchen Wan, Henry Kenlay, Robin Ru, Arno Blaas, Michael A. Osborne, Xiaowen Dong
摘要
Graph neural networks, a popular class of models effective in a wide range of graph-based learning tasks, have been shown to be vulnerable to adversarial attacks. While the majority of the literature focuses on such vulnerability in node-level classification tasks, little effort has been dedicated to analysing adversarial attacks on graph-level classification, an important problem with numerous real-life applications such as biochemistry and social network analysis. The few existing methods often require unrealistic setups, such as access to internal information of the victim models, or an impractically-large number of queries. We present a novel Bayesian optimisation-based attack method for graph classification models. Our method is black-box, query-efficient and parsimonious with respect to the perturbation applied. We empirically validate the effectiveness and flexibility of the proposed method on a wide range of graph classification tasks involving varying graph properties, constraints and modes of attack. Finally, we analyse common interpretable patterns behind the adversarial samples produced, which may shed further light on the adversarial robustness of graph classification models. An open-source implementation is available at https://github.com/xingchenwan/grabnel .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Query-Efficient and Scalable Black-Box Adversarial Attacks on Discrete Sequential Data via Bayesian OptimizationDeokjae Lee, Seungyong Moon, Junhyeok Lee, Hyun Oh SongICML 2022 · 被引用 52 次
- Static and Sequential Malicious Attacks in the Context of Selective ForgettingChenxu Zhao, Wei Qian, Rex Ying, Mengdi HuaiNeurIPS 2023 · 被引用 30 次
- GNNX-BENCH: Unravelling the Utility of Perturbation-based GNN Explainers through In-depth BenchmarkingMert Kosan, Samidha Verma, Burouj Armgaan, Khushbu Pahwa 等ICLR 2024 · 被引用 21 次
- Neural Latent Geometry Search: Product Manifold Inference via Gromov-Hausdorff-Informed Bayesian OptimizationHaitz Sáez de Ocáriz Borde, Alvaro Arroyo, Ismael Morales, Ingmar Posner 等NeurIPS 2023 · 被引用 21 次
- Efficient Black-box Adversarial Attacks via Bayesian Optimization Guided by a Function PriorShuyu Cheng, Yibo Miao, Yinpeng Dong, Xiao Yang 等ICML 2024 · 被引用 15 次
它引用的顶会 Paper11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Graph Contrastive Learning with AugmentationsYuning You, Tianlong Chen, Yongduo Sui, Ting Chen 等NeurIPS 2020 · 被引用 3,042 次
- A Restricted Black-Box Adversarial Framework Towards Attacking Graph Embedding ModelsHeng Chang, Yu Rong, Tingyang Xu, Wenbing Huang 等AAAI 2020 · 被引用 171 次
- Towards More Practical Adversarial Attacks on Graph Neural NetworksJiaqi Ma, Shuangrui Ding, Qiaozhu MeiNeurIPS 2020 · 被引用 160 次
- Bridging the Gap between Sample-based and One-shot Neural Architecture Search with BONASHan Shi, Renjie Pi, Hang Xu, Zhenguo Li 等NeurIPS 2020 · 被引用 148 次
相关 Paper
- A Hard Label Black-box Adversarial Attack Against Graph Neural NetworksJiaming Mu, Binghui Wang, Qi Li, Kun Sun 等CCS 2021 · 被引用 30 次
- Blindfolded Attackers Still Threatening: Strict Black-Box Adversarial Attacks on GraphsJiarong Xu, Yizhou Sun, Xin Jiang, Yanhao Wang 等AAAI 2022 · 被引用 16 次
- GOttack: Universal Adversarial Attacks on Graph Neural Networks via Graph Orbits LearningMd. Zulfikar Alom, Tran Gia Bao Ngo, Murat Kantarcioglu, Cuneyt Gurcan AkcoraICLR 2025
- Bandits for Structure Perturbation-based Black-box Attacks to Graph Neural Networks with Theoretical GuaranteesBinghui Wang, Youqi Li, Pan ZhouCVPR 2022 · 被引用 16 次
- Value at Adversarial Risk: A Graph Defense Strategy against Cost-Aware AttacksJunlong Liao, Wenda Fu, Cong Wang, Zhongyu Wei 等AAAI 2024 · 被引用 5 次
