Adversarial Attack on Graph Structured Data

Adversarial Attack on Graph Structured Data
复制标题

DOI:
--
复制
发表时间:
2018-06
期刊:
--
影响因子:
--
通讯作者:
H. Dai;Hui Li-;Tian Tian-Tian;Xin Huang;L. Wang;Jun Zhu;Le Song
H. Dai;Hui Li-;Tian Tian-Tian;Xin Huang;L. Wang;Jun Zhu;Le Song
中科院分区:
其他
文献类型:
--
作者:
H. Dai;Hui Li-;Tian Tian-Tian;Xin Huang;L. Wang;Jun Zhu;Le Song

文献摘要

被引文献

相似文献

对图结构的深度学习在各种应用中都显示出令人兴奋的结果。但是,与众多用于图像或文本对抗性攻击和防御的研究工作相反,很少有人注意这种模型的鲁棒性。在本文中,我们专注于通过修改数据组合结构来欺骗模型的对抗性攻击。我们首先提出了一种基于增强学习的攻击方法,该方法了解可推广的攻击策略,而仅需要目标分类器的预测标签。此外,在可用的预测置信度或梯度的情况下,介绍了遗传算法和梯度方法的变体。我们同时使用合成和现实世界数据来表明,在图形级别和节点级分类任务中,图形神经网络模型一家都容易受到这些攻击的影响。我们还显示这种攻击可用于诊断学习的分类器。
Deep learning on graph structures has shown exciting results in various applications. However, few attentions have been paid to the robustness of such models, in contrast to numerous research work for image or text adversarial attack and defense. In this paper, we focus on the adversarial attacks that fool the model by modifying the combinatorial structure of data. We first propose a reinforcement learning based attack method that learns the generalizable attack policy, while only requiring prediction labels from the target classifier. Also, variants of genetic algorithms and gradient methods are presented in the scenario where prediction confidence or gradients are available. We use both synthetic and real-world data to show that, a family of Graph Neural Network models are vulnerable to these attacks, in both graph-level and node-level classification tasks. We also show such attacks can be used to diagnose the learned classifiers.