GNNGuard: Defending Graph Neural Networks against Adversarial Attacks

GNNGuard: Defending Graph Neural Networks against Adversarial Attacks
复制标题

DOI:
--
复制
发表时间:
2020-06
期刊:
ArXiv
影响因子:
--
通讯作者:
Xiang Zhang-;M. Zitnik
Xiang Zhang-;M. Zitnik
中科院分区:
其他
文献类型:
--
作者:
Xiang Zhang-;M. Zitnik

文献摘要

相似文献

图的深度学习方法在许多任务上取得了显著的性能。然而,尽管这些方法的扩散和他们的成功,最近的研究表明,图结构的小的,不明显的扰动可以灾难性地降低性能,即使是最强和最流行的图神经网络(gnn)。在这里,我们开发了GNNGuard,这是一种针对各种训练时间攻击的通用防御方法,这些攻击会干扰离散图结构。GNNGuard可以直接合并到任何GNN中。它的核心原理是检测和量化图结构和节点特征之间的关系,如果存在的话,然后利用这种关系来减轻攻击的负面影响。GNNGuard使用网络同态理论来学习如何最好地为连接相似节点的边分配更高的权重,同时修剪不相关节点之间的边。修正后的边允许底层GNN在图中鲁棒地传播神经信息。GNNGuard引入了两个新组件,邻居重要性估计和分层图内存,我们通过经验证明这两个组件对于成功的防御是必要的。在5个gnn、3种防御方法和4个数据集(包括一个具有挑战性的人类疾病图)中,实验表明GNNGuard比现有的防御方法平均高出15.3%。值得注意的是,GNNGuard可以在面对各种对抗性攻击(包括目标攻击和非目标攻击)时有效地恢复gnn的最先进性能。
Deep learning methods for graphs achieve remarkable performance on many tasks. However, despite the proliferation of such methods and their success, recent findings indicate that small, unnoticeable perturbations of graph structure can catastrophically reduce performance of even the strongest and most popular Graph Neural Networks (GNNs). Here, we develop GNNGuard, a general defense approach against a variety of training-time attacks that perturb the discrete graph structure. GNNGuard can be straightforwardly incorporated into any GNN. Its core principle is to detect and quantify the relationship between the graph structure and node features, if one exists, and then exploit that relationship to mitigate negative effects of the attack. GNNGuard uses network theory of homophily to learn how best assign higher weights to edges connecting similar nodes while pruning edges between unrelated nodes. The revised edges then allow the underlying GNN to robustly propagate neural messages in the graph. GNNGuard introduces two novel components, the neighbor importance estimation, and the layer-wise graph memory, and we show empirically that both components are necessary for a successful defense. Across five GNNs, three defense methods, and four datasets, including a challenging human disease graph, experiments show that GNNGuard outperforms existing defense approaches by 15.3% on average. Remarkably, GNNGuard can effectively restore the state-of-the-art performance of GNNs in the face of various adversarial attacks, including targeted and non-targeted attacks.