Data Poisoning Attack against Knowledge Graph Embedding

Data Poisoning Attack against Knowledge Graph Embedding
复制标题

DOI:
10.24963/ijcai.2019/674
复制
发表时间:
2019-04
期刊:
--
影响因子:
--
通讯作者:
Hengtong Zhang;T. Zheng;Jing Gao;Chenglin Miao;Lu Su;Yaliang Li;K. Ren
Hengtong Zhang;T. Zheng;Jing Gao;Chenglin Miao;Lu Su;Yaliang Li;K. Ren
中科院分区:
其他
文献类型:
--
作者:
Hengtong Zhang;T. Zheng;Jing Gao;Chenglin Miao;Lu Su;Yaliang Li;K. Ren

文献摘要

相似文献

知识图嵌入(KGE)是一种对知识图中的实体和关系进行连续嵌入学习的技术。由于其在知识图谱补全、问答和推荐等下游任务中的优势,KGE最近受到了极大的关注。尽管它在良性环境中有效,但KGE对对抗性攻击的稳健性尚未得到充分研究。由于知识图的异构性,现有的图数据攻击方法不能直接用于攻击知识图的嵌入。为了填补这一空白,我们提出了一组数据中毒攻击策略,该策略可以通过添加或删除知识图上的事实来有效地操纵知识图中任意目标事实的可信性。通过对两个广泛使用的基准进行广泛的评估,验证了所提出的攻击策略的有效性和效率。
Knowledge graph embedding (KGE) is a technique for learning continuous embeddings for entities and relations in the knowledge graph. Due to its benefit to a variety of downstream tasks such as knowledge graph completion, question answering and recommendation, KGE has gained significant attention recently. Despite its effectiveness in a benign environment, KGE's robustness to adversarial attacks is not well-studied. Existing attack methods on graph data cannot be directly applied to attack the embeddings of knowledge graph due to its heterogeneity. To fill this gap, we propose a collection of data poisoning attack strategies, which can effectively manipulate the plausibility of arbitrary targeted facts in a knowledge graph by adding or deleting facts on the graph. The effectiveness and efficiency of the proposed attack strategies are verified by extensive evaluations on two widely-used benchmarks.