GNNGuard: Defending Graph Neural Networks against Adversarial Attacks
Xiang Zhang, Marinka Zitnik
摘要
Deep learning methods for graphs achieve remarkable performance across a variety of domains. However, recent findings indicate that small, unnoticeable perturbations of graph structure can catastrophically reduce performance of even the strongest and most popular Graph Neural Networks (GNNs). Here, we develop GNNGUARD, a general algorithm to defend against a variety of training-time attacks that perturb the discrete graph structure. GNNGUARD can be straightforwardly incorporated into any GNN. Its core principle is to detect and quantify the relationship between the graph structure and node features, if one exists, and then exploit that relationship to mitigate negative effects of the attack. GNN-GUARD learns how to best assign higher weights to edges connecting similar nodes while pruning edges between unrelated nodes. The revised edges allow for robust propagation of neural messages in the underlying GNN. GNNGUARD introduces two novel components, the neighbor importance estimation, and the layer-wise graph memory, and we show empirically that both components are necessary for a successful defense. Across five GNNs, three defense methods, and four datasets, including a challenging human disease graph, experiments show that GNNGUARD outperforms existing defense approaches by 15.3% on average. Remarkably, GN-NGUARD can effectively restore state-of-the-art performance of GNNs in the face of various adversarial attacks, including targeted and non-targeted attacks, and can defend against attacks on heterophily graphs. 34th Conference on Neural Information Processing Systems (NeurIPS 2020),
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper84
- NodeFormer: A Scalable Graph Structure Learning Transformer for Node ClassificationQitian Wu, Wentao Zhao, Zenan Li, David P. Wipf 等NeurIPS 2022 · 被引用 472 次
- Sequential Recommendation with Graph Neural NetworksJianxin Chang, Chen Gao, Yu Zheng, Yiqun Hui 等SIGIR 2021 · 被引用 435 次
- Robustness of Graph Neural Networks at ScaleSimon Geisler, Tobias Schmidt, Hakan Sirin, Daniel Zügner 等NeurIPS 2021 · 被引用 189 次
- Kairos: Practical Intrusion Detection and Investigation using Whole-system ProvenanceZijun Cheng, Qiujian Lv, Jinyuan Liang, Yan Wang 等S&P 2024 · 被引用 125 次
- Understanding and Improving Graph Injection Attack by Promoting UnnoticeabilityYongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma 等ICLR 2022 · 被引用 106 次
它引用的顶会 Paper4
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong 等NeurIPS 2020 · 被引用 3,935 次
- GraphSAINT: Graph Sampling Based Inductive Learning MethodHanqing Zeng, Hongkuan Zhou, Ajitesh Srivastava, Rajgopal Kannan 等ICLR 2020 · 被引用 1,155 次
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang 等KDD 2020 · 被引用 604 次
- Policy Teaching via Environment Poisoning: Training-time Adversarial Attacks against Reinforcement LearningAmin Rakhsha, Goran Radanovic, Rati Devidze, Xiaojin Zhu 等ICML 2020 · 被引用 145 次
相关 Paper
- Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary PerturbationsJiate Li, Meng Pang, Yun Dong, Binghui WangCVPR 2025
- Fight Fire with Fire: Towards Robust Graph Neural Networks on Dynamic Graphs via Actively DefenseHaoyang Li, Shimin Di, Calvin Hong Yi Li, Lei Chen 等VLDB 2024 · 被引用 6 次
- How does Heterophily Impact the Robustness of Graph Neural Networks?: Theoretical Connections and Practical ImplicationsJiong Zhu, Junchen Jin, Donald Loveland, Michael T. Schaub 等KDD 2022 · 被引用 26 次
- Value at Adversarial Risk: A Graph Defense Strategy against Cost-Aware AttacksJunlong Liao, Wenda Fu, Cong Wang, Zhongyu Wei 等AAAI 2024 · 被引用 5 次
- Adversarial Training for Graph Neural Networks: Pitfalls, Solutions, and New DirectionsLukas Gosch, Simon Geisler, Daniel Sturm, Bertrand Charpentier 等NeurIPS 2023 · 被引用 19 次
