Camouflaged Poisoning Attack on Graph Neural Networks

Camouflaged Poisoning Attack on Graph Neural Networks
复制标题

DOI:
10.1145/3512527.3531373
复制
发表时间:
2022-06
期刊:
Proceedings of the 2022 International Conference on Multimedia Retrieval
影响因子:
--
通讯作者:
Chao Jiang;Yingzhe He;Richard Chapman;Hongyi Wu
Chao Jiang;Yingzhe He;Richard Chapman;Hongyi Wu
中科院分区:
其他
文献类型:
--
作者:
Chao Jiang;Yingzhe He;Richard Chapman;Hongyi Wu

文献摘要

相似文献

图神经网络 (GNN) 已经实现了许多需要对图进行节点分类的 Web 应用程序的自动化,例如社交媒体中的诈骗检测和服务网络中的事件预测。然而,最近的研究表明,GNN 很容易受到对抗性攻击,在训练时向 GNN 提供有毒数据可能会导致它们产生灾难性的破坏性测试准确性。这一发现加剧了针对 GNN 的攻击和防御的前沿领域。然而,先前的研究主要假设对手可以免费访问操纵原始图,但在实践中获得这种访问的成本可能太高。为了填补这一空白,我们提出了一种新颖的攻击范式,称为生成对抗性假节点伪装(GAFNC),其关键在于在生成对抗机制中制作一组假节点。这些节点携带伪装的恶意特征,并可以通过学习的拓扑结构将其恶意消息传递到原始图来毒害受害者 GNN,从而使它们 1)最大化分类准确性的破坏(即全局攻击)或 2)强制受害者 GNN 将目标节点集错误分类为规定的类别(即目标攻击)。我们在四个现实世界的图数据集上对我们的实验进行了基准测试,结果证实了我们提出的中毒攻击方法的可行性、有效性和隐蔽性。代码发布于 github.com/chao92/GAFNC。
Graph neural networks (GNNs) have enabled the automation of many web applications that entail node classification on graphs, such as scam detection in social media and event prediction in service networks. Nevertheless, recent studies revealed that the GNNs are vulnerable to adversarial attacks, where feeding GNNs with poisoned data at training time can lead them to yield catastrophically devastative test accuracy. This finding heats up the frontier of attacks and defenses against GNNs. However, the prior studies mainly posit that the adversaries can enjoy free access to manipulate the original graph, while obtaining such access could be too costly in practice. To fill this gap, we propose a novel attacking paradigm, named Generative Adversarial Fake Node Camouflaging (GAFNC), with its crux lying in crafting a set of fake nodes in a generative-adversarial regime. These nodes carry camouflaged malicious features and can poison the victim GNN by passing their malicious messages to the original graph via learned topological structures, such that they 1) maximize the devastation of classification accuracy (i.e., global attack) or 2) enforce the victim GNN to misclassify a targeted node set into prescribed classes (i.e., target attack). We benchmark our experiments on four real-world graph datasets, and the results substantiate the viability, effectiveness, and stealthiness of our proposed poisoning attack approach. Code is released in github.com/chao92/GAFNC.