GARNET: Reduced-Rank Topology Learning for Robust and Scalable Graph Neural Networks

GARNET: Reduced-Rank Topology Learning for Robust and Scalable Graph Neural Networks
复制标题

DOI:
--
复制
发表时间:
2022-01
期刊:
ArXiv
影响因子:
--
通讯作者:
Chenhui Deng;Xiuyu Li;Zhuobo Feng;Zhiru Zhang
Chenhui Deng;Xiuyu Li;Zhuobo Feng;Zhiru Zhang
中科院分区:
其他
文献类型:
--
作者:
Chenhui Deng;Xiuyu Li;Zhuobo Feng;Zhiru Zhang

文献摘要

相似文献

图形神经网络(GNN)已被越来越多地应用于涉及非欧几里德数据学习的各种应用中。然而,最近的研究表明,GNN容易受到图的对抗性攻击。虽然有几种防御方法可以通过消除敌对组件来提高GNN的健壮性,但它们也可能损害有助于GNN训练的底层干净的图形结构。此外,这些防御模型中很少有能够扩展到大型图形的,因为它们的计算复杂性和内存使用量很高。在本文中,我们提出了Garnet,一种可伸缩的谱方法来提高GNN模型的对抗健壮性。Garnet First利用加权谱嵌入来构造基图,该基图不仅能抵抗敌方攻击,而且还包含GNN训练所需的关键(干净)图结构。接下来,Garnet基于概率图模型,通过剪枝额外的非关键边来进一步精化基图。石榴石已经在各种数据集上进行了评估,包括一个包含数百万个节点的大型图表。我们的大量实验结果表明,与现有的GNN(防御)模型相比,Garnet的对抗准确率提高了13.27%,运行时加速比提高了14.7倍。
Graph neural networks (GNNs) have been increasingly deployed in various applications that involve learning on non-Euclidean data. However, recent studies show that GNNs are vulnerable to graph adversarial attacks. Although there are several defense methods to improve GNN robustness by eliminating adversarial components, they may also impair the underlying clean graph structure that contributes to GNN training. In addition, few of those defense models can scale to large graphs due to their high computational complexity and memory usage. In this paper, we propose GARNET, a scalable spectral method to boost the adversarial robustness of GNN models. GARNET first leverages weighted spectral embedding to construct a base graph, which is not only resistant to adversarial attacks but also contains critical (clean) graph structure for GNN training. Next, GARNET further refines the base graph by pruning additional uncritical edges based on probabilistic graphical model. GARNET has been evaluated on various datasets, including a large graph with millions of nodes. Our extensive experiment results show that GARNET achieves adversarial accuracy improvement and runtime speedup over state-of-the-art GNN (defense) models by up to 13.27% and 14.7x, respectively.