Turning Strengths into Weaknesses: A Certified Robustness Inspired Attack Framework against Graph Neural Networks

Turning Strengths into Weaknesses: A Certified Robustness Inspired Attack Framework against Graph Neural Networks
复制标题

DOI:
10.1109/cvpr52729.2023.01573
复制
发表时间:
2023-03
期刊:
2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
影响因子:
--
通讯作者:
Binghui Wang;Meng Pang;Yun Dong
Binghui Wang;Meng Pang;Yun Dong
中科院分区:
其他
文献类型:
--
作者:
Binghui Wang;Meng Pang;Yun Dong

文献摘要

相似文献

图神经网络(GNN)在许多图学习任务中已经实现了最先进的性能。然而,最近的研究表明,GNN容易受到测试时逃避和训练时中毒攻击,这些攻击会扰乱图结构。虽然现有的攻击方法已经显示出很好的攻击性能,我们想设计一个攻击框架,以进一步提高性能。特别是,我们的攻击框架受到了认证鲁棒性的启发,这最初是防御者用来防御对抗性攻击的。从攻击者的角度来看,我们是第一个利用其属性更好地攻击GNN的人。具体来说,我们首先推导出节点的认证扰动大小,分别对图规避和中毒攻击的基础上随机平滑。节点的较大认证扰动大小表明该节点理论上对图扰动更鲁棒。这样的属性促使我们更多地关注具有较小认证扰动大小的节点,因为它们在图扰动后更容易被攻击。因此,我们设计了一个认证的鲁棒性启发的攻击损失,当纳入(任何)现有的攻击,产生我们的认证的鲁棒性启发的攻击对手。我们将该框架应用于现有的攻击,结果表明它可以显着提高现有的基础攻击的性能。
Graph neural networks (GNNs) have achieved state-of-the-art performance in many graph learning tasks. However, recent studies show that GNNs are vulnerable to both test-time evasion and training-time poisoning attacks that perturb the graph structure. While existing attack methods have shown promising attack performance, we would like to design an attack framework to further enhance the performance. In particular, our attack framework is inspired by certified robustness, which was originally used by defenders to defend against adversarial attacks. We are the first, from the attacker perspective, to leverage its properties to better attack GNNs. Specifically, we first derive nodes' certified perturbation sizes against graph evasion and poisoning attacks based on randomized smoothing, respectively. A larger certified perturbation size of a node indicates this node is theoretically more robust to graph perturbations. Such a property motivates us to focus more on nodes with smaller certified perturbation sizes, as they are easier to be attacked after graph perturbations. Accordingly, we design a certified robustness inspired attack loss, when incorporated into (any) existing attacks, produces our certified robustness inspired attack counterpart. We apply our frame-work to the existing attacks and results show it can significantly enhance the existing base attacks' performance.