Efficient, Direct, and Restricted Black-Box Graph Evasion Attacks to Any-Layer Graph Neural Networks via Influence Function

Efficient, Direct, and Restricted Black-Box Graph Evasion Attacks to Any-Layer Graph Neural Networks via Influence Function
复制标题

DOI:
10.1145/3616855.3635826
复制
发表时间:
2020-09
期刊:
Proceedings of the 17th ACM International Conference on Web Search and Data Mining
影响因子:
--
通讯作者:
Binghui Wang;Tianxiang Zhou;Min-Bin Lin;Pan Zhou;Ang Li;Meng Pang;Cai Fu;H. Li;Yiran Chen
Binghui Wang;Tianxiang Zhou;Min-Bin Lin;Pan Zhou;Ang Li;Meng Pang;Cai Fu;H. Li;Yiran Chen
中科院分区:
其他
文献类型:
--
作者:
Binghui Wang;Tianxiang Zhou;Min-Bin Lin;Pan Zhou;Ang Li;Meng Pang;Cai Fu;H. Li;Yiran Chen

文献摘要

相似文献

图神经网络(GNN)是图数据学习的主流方法,很容易受到图规避攻击,攻击者稍微扰动图结构就可以欺骗经过训练的 GNN 模型。现有工作至少存在以下缺点之一:1)仅限于直接攻击两层GNN; 2)效率低下; 3)不切实际,因为他们需要知道全部或部分 GNN 模型参数。我们针对上述缺点,提出了一种针对任意层 GNN 的基于影响力的高效、直接且受限的黑盒规避攻击。具体来说,我们首先引入两个影响函数,即特征标签影响力和标签影响力,它们分别在 GNN 和标签传播(LP)上定义。然后我们观察到 GNN 和 LP 在我们定义的影响方面紧密相关。基于此,我们可以将针对 GNN 的规避攻击重新表述为计算标签对 LP 的影响,这本质上适用于任何层的 GNN,而无需了解内部 GNN 模型的信息。最后,我们提出了一种有效的算法来计算标签影响力。在各种图数据集上的实验结果表明,与最先进的白盒攻击相比,我们的攻击可以实现相当的攻击性能,但在攻击两层 GNN 时具有 5-50 倍的加速。此外,我们的攻击对于攻击多层 GNN 是有效的。
Graph neural network (GNN), the mainstream method to learn on graph data, is vulnerable to graph evasion attacks, where an attacker slightly perturbing the graph structure can fool trained GNN models. Existing work has at least one of the following drawbacks: 1) limited to directly attack two-layer GNNs; 2) inefficient; and 3) impractical, as they need to know full or part of GNN model parameters. We address the above drawbacks and propose an influence-based efficient, direct, and restricted black-box evasion attack to any-layer GNNs. Specifically, we first introduce two influence functions, i.e., feature-label influence and label influence, that are defined on GNNs and label propagation (LP), respectively. Then we observe that GNNs and LP are strongly connected in terms of our defined influences. Based on this, we can then reformulate the evasion attack to GNNs as calculating label influence on LP, which is inherently applicable to any-layer GNNs, while no need to know information about the internal GNN model. Finally, we propose an efficient algorithm to calculate label influence. Experimental results on various graph datasets show that, compared to state-of-the-art white-box attacks, our attack can achieve comparable attack performance, but has a 5-50x speedup when attacking two-layer GNNs. Moreover, our attack is effective to attack multi-layer GNNs.