How does Heterophily Impact the Robustness of Graph Neural Networks?: Theoretical Connections and Practical Implications

How does Heterophily Impact the Robustness of Graph Neural Networks?: Theoretical Connections and Practical Implications
复制标题

DOI:
10.1145/3534678.3539418
复制
发表时间:
2021-06
期刊:
Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining
影响因子:
--
通讯作者:
Jiong Zhu;Junchen Jin;Donald Loveland;Michael T. Schaub;Danai Koutra
Jiong Zhu;Junchen Jin;Donald Loveland;Michael T. Schaub;Danai Koutra
中科院分区:
其他
文献类型:
--
作者:
Jiong Zhu;Junchen Jin;Donald Loveland;Michael T. Schaub;Danai Koutra

文献摘要

相似文献

我们通过形式化节点标签的异质性(即,连接的节点往往具有不同的标签)以及GNN对对抗性攻击的鲁棒性。我们的理论和实证分析表明,对于同质图数据,有影响力的结构攻击总是导致降低同质性,而对于异质图数据的同质性水平的变化取决于节点度。这些见解对于防御对现实世界图的攻击具有实际意义:我们推断,自我嵌入和邻居嵌入的单独聚合器,这是一种已被确定为显着提高对异质图数据的预测的设计原则,也可以为GNN提供更高的鲁棒性。我们的综合实验表明,与性能最好的未接种模型相比,仅采用这种设计的GNN实现了改进的经验和可验证的鲁棒性。此外,将这种设计与对抗性攻击的显式防御机制相结合,可以提高鲁棒性,与性能最好的疫苗接种模型相比,在攻击下性能提高了18.33%。
We bridge two research directions on graph neural networks (GNNs), by formalizing the relation between heterophily of node labels (i.e., connected nodes tend to have dissimilar labels) and the robustness of GNNs to adversarial attacks. Our theoretical and empirical analyses show that for homophilous graph data, impactful structural attacks always lead to reduced homophily, while for heterophilous graph data the change in the homophily level depends on the node degrees. These insights have practical implications for defending against attacks on real-world graphs: we deduce that separate aggregators for ego- and neighbor-embeddings, a design principle which has been identified to significantly improve prediction for heterophilous graph data, can also offer increased robustness to GNNs. Our comprehensive experiments show that GNNs merely adopting this design achieve improved empirical and certifiable robustness compared to the best-performing unvaccinated model. Additionally, combining this design with explicit defense mechanisms against adversarial attacks leads to an improved robustness with up to 18.33% performance increase under attacks compared to the best-performing vaccinated model.