Adversarial Attack on Graph Neural Networks as An Influence Maximization Problem

Adversarial Attack on Graph Neural Networks as An Influence Maximization Problem
复制标题

DOI:
10.1145/3488560.3498497
复制
发表时间:
2021-06
期刊:
Proceedings of the Fifteenth ACM International Conference on Web Search and Data Mining
影响因子:
--
通讯作者:
Jiaqi Ma;Junwei Deng;Qiaozhu Mei
Jiaqi Ma;Junwei Deng;Qiaozhu Mei
中科院分区:
其他
文献类型:
--
作者:
Jiaqi Ma;Junwei Deng;Qiaozhu Mei

文献摘要

相似文献

图神经网络(GNNs)引起了越来越多的关注。随着GNN在现实应用中的广泛部署,迫切需要了解GNN在对抗性攻击下的鲁棒性,特别是在现实设置中。在这项工作中,我们研究了在限制和现实的设置中攻击GNN的问题,通过扰动一小部分节点的特征,无法访问模型参数和模型预测。我们的正式分析在这种类型的攻击和图上的影响最大化问题之间建立了联系。这种联系不仅增强了我们对GNN对抗性攻击问题的理解,而且使我们能够提出一组有效和实用的攻击策略。我们的实验验证了所提出的攻击策略显着降低了三种流行的GNN模型的性能,并优于基线对抗攻击策略。
Graph neural networks (GNNs) have attracted increasing interests. With broad deployments of GNNs in real-world applications, there is an urgent need for understanding the robustness of GNNs under adversarial attacks, especially in realistic setups. In this work, we study the problem of attacking GNNs in a restricted and realistic setup, by perturbing the features of a small set of nodes, with no access to model parameters and model predictions. Our formal analysis draws a connection between this type of attacks and an influence maximization problem on the graph. This connection not only enhances our understanding on the problem of adversarial attack on GNNs, but also allows us to propose a group of effective and practical attack strategies. Our experiments verify that the proposed attack strategies significantly degrade the performance of three popular GNN models and outperform baseline adversarial attack strategies.