Jointly Attacking Graph Neural Network and its Explanations

Jointly Attacking Graph Neural Network and its Explanations
复制标题

DOI:
10.1109/icde55515.2023.00056
复制
发表时间:
2021-08
期刊:
2023 IEEE 39th International Conference on Data Engineering (ICDE)
影响因子:
--
通讯作者:
Wenqi Fan;Wei Jin;Xiaorui Liu;Han Xu;Xianfeng Tang;Suhang Wang;Qing Li;Jiliang Tang;
Wenqi Fan;Wei Jin;Xiaorui Liu;Han Xu;Xianfeng Tang;Suhang Wang;Qing Li;Jiliang Tang;
中科院分区:
其他
文献类型:
--
作者:
Wenqi Fan;Wei Jin;Xiaorui Liu;Han Xu;Xianfeng Tang;Suhang Wang;Qing Li;Jiliang Tang;

文献摘要

相似文献

图神经网络(GNN)提高了许多与图相关的任务的性能。尽管取得了巨大成功,但最近的研究表明,GNN 仍然容易受到对抗性攻击,对手可以通过修改图来误导 GNN 的预测。另一方面,GNN 的解释(简称 GnnExplainer)通过生成一个小子图和对其预测影响最大的特征,可以更好地理解经过训练的 GNN 模型。在本文中,我们首先进行实证研究来验证 GnnExplainer 可以作为检查工具,并且有可能检测图的对抗性扰动。这一发现激励我们进一步研究一个新问题:图神经网络及其解释是否可以通过恶意修改图来受到联合攻击?回答这个问题很有挑战性,因为对抗性攻击和绕过 GnnExplainer 的目标本质上是相互矛盾的。在这项工作中,我们提出了一种新颖的图攻击框架(GEAttack),为这个问题提供了明确的答案,该框架可以同时利用 GNN 模型及其解释的漏洞来攻击它们。据我们所知,这是针对 GNN 和图结构数据解释以保证 GNN 可信度的首次尝试。对各种现实世界数据集的综合实验证明了所提出方法的有效性。
Graph Neural Networks (GNNs) have boosted the performance for many graph-related tasks. Despite the great success, recent studies have shown that GNNs are still vulnerable to adversarial attacks, where adversaries can mislead the GNNs' prediction by modifying graphs. On the other hand, the explanation of GNNs (GnnExplainer for short) provides a better understanding of a trained GNN model by generating a small subgraph and features that are most influential for its prediction. In this paper, we first perform empirical studies to validate that GnnExplainer can act as an inspection tool and have the potential to detect the adversarial perturbations for graphs. This finding motivates us to further investigate a new problem: Whether a graph neural network and its explanations can be jointly attacked by modifying graphs with malicious desires? It is challenging to answer this question since the goals of adversarial attack and bypassing the GnnExplainer essentially contradict with each other. In this work, we give a confirmative answer for this question by proposing a novel attack framework (GEAttack) for graphs, which can attack both a GNN model and its explanations by exploiting their vulnerabilities simultaneously. To the best of our knowledge, this is the very first effort to attack both GNNs and explanations on graph-structured data for the trustworthiness of GNNs. Comprehensive experiments on various real-world datasets demonstrate the effectiveness of the proposed method.