AdverSparse: An Adversarial Attack Framework for Deep Spatial-Temporal Graph Neural Networks

AdverSparse: An Adversarial Attack Framework for Deep Spatial-Temporal Graph Neural Networks
复制标题

DOI:
10.1109/icassp43922.2022.9747850
复制
发表时间:
2022-05
期刊:
ICASSP 2022 - 2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)
影响因子:
--
通讯作者:
Jiayu Li;Tianyun Zhang;Shengmin Jin;M. Fardad;R. Zafarani
Jiayu Li;Tianyun Zhang;Shengmin Jin;M. Fardad;R. Zafarani
中科院分区:
其他
文献类型:
--
作者:
Jiayu Li;Tianyun Zhang;Shengmin Jin;M. Fardad;R. Zafarani

文献摘要

相似文献

在神经科学,气候研究和运输工程等各个领域中,空间图图已被广泛观察到。时空图的最新模型依赖于图形神经网络(GNN)来获得此类网络的明确表示,并发现其中隐藏的空间依赖性。这些模型在各种任务中都表现出卓越的性能。在本文中,我们提出了一个稀疏的对抗攻击框架对手,以说明当在此类图中仅删除了几个关键连接时,这种空间 - 周期模型学到的隐藏的空间依赖性受到了重大影响,从而导致了各种问题,例如增加的预测错误等问题。 。我们将对抗性攻击作为优化问题,并通过乘数的交替方向方法(ADMM)解决。实验表明,即使在能够学习隐藏的空间依赖性的模型中,Aversparse可以在这些图中找到并删除这些图中的密钥连接,从而导致故障模型。
Spatial-temporal graph have been widely observed in various domains such as neuroscience, climate research, and transportation engineering. The state-of-the-art models of spatialtemporal graphs rely on Graph Neural Networks (GNNs) to obtain explicit representations for such networks and to discover hidden spatial dependencies in them. These models have demonstrated superior performance in various tasks. In this paper, we propose a sparse adversarial attack framework AdverSparse to illustrate that when only a few key connections are removed in such graphs, hidden spatial dependencies learned by such spatial-temporal models are significantly impacted, leading to various issues such as increasing prediction errors. We formulate the adversarial attack as an optimization problem and solve it by the Alternating Direction Method of Multipliers (ADMM). Experiments show that AdverSparse can find and remove key connections in these graphs, leading to malfunctioning models, even in models capable of learning hidden spatial dependencies.