AdverSparse: An Adversarial Attack Framework for Deep Spatial-Temporal Graph Neural Networks
AdverSparse: An Adversarial Attack Framework for Deep Spatial-Temporal Graph Neural Networks
复制标题
DOI:
10.1109/icassp43922.2022.9747850
复制
发表时间:
2022-05
期刊:
影响因子:
--
通讯作者:
Jiayu Li;Tianyun Zhang;Shengmin Jin;M. Fardad;R. Zafarani
中科院分区:
文献类型:
--
作者:
Jiayu Li;Tianyun Zhang;Shengmin Jin;M. Fardad;R. Zafarani
Spatial-temporal graph have been widely observed in various domains such as neuroscience, climate research, and transportation engineering. The state-of-the-art models of spatialtemporal graphs rely on Graph Neural Networks (GNNs) to obtain explicit representations for such networks and to discover hidden spatial dependencies in them. These models have demonstrated superior performance in various tasks. In this paper, we propose a sparse adversarial attack framework AdverSparse to illustrate that when only a few key connections are removed in such graphs, hidden spatial dependencies learned by such spatial-temporal models are significantly impacted, leading to various issues such as increasing prediction errors. We formulate the adversarial attack as an optimization problem and solve it by the Alternating Direction Method of Multipliers (ADMM). Experiments show that AdverSparse can find and remove key connections in these graphs, leading to malfunctioning models, even in models capable of learning hidden spatial dependencies.