CRII: SaTC: Towards Understanding the Robustness of Graph Neural Networks against Graph Perturbations
CRII: SaTC: Towards Understanding the Robustness of Graph Neural Networks against Graph Perturbations
批准号:
2241713
负责人:
Binghui Wang
金额:
$17.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2023
资助国家:
美国
项目状态:
未结题
起止时间:
2023-06-01 至 2025-05-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Learning with graphs, such as social networks, biological networks, and financial networks, has drawn continuous attention recently, wherein graph neural networks (GNNs) have been emerging as the most prominent methodology. However, recent studies show that GNNs are vulnerable to graph perturbation attacks: slightly perturbing the graph structure can make GNN model's performance severely degraded. The lack of robustness of GNNs makes them risky for their potential applications. However, existing studies on GNN attacks and defenses are very limited in scope: the attacks are assumed under less practical scenarios (i.e., the attacker has a full or partial knowledge about the GNN model), while the defenses are either heuristic-based that can be easily broken or their robustness in defense is lacking. This project aims to understand how to perform the graph perturbation attack to fool any GNNs with least/no knowledge about the GNN model. Accordingly, the project designs both restricted and stringent black-box graph perturbation attacks to any GNNs, which are inspired by the influence function and bandit algorithms, respectively. Next, the project aims to understand how to protect any GNNs from the strongest white-box attack with robustness guarantees. To this end, it designs provable defenses for any GNNs against white-box graph perturbation attacks via novel randomized smoothing techniques and designs principled methods to optimize the defense performance.The project’s novelties are to gain a holistic understanding on the robustness of GNNs against graph perturbation attacks, to look into more practicable attacks and lastly to devise a more provable defenses. The project’s broader significance and impact are 1)advancing not only the field of secure and trustworthy machine learning, but also other fields (e.g., social science and economy) where graph data model and graph learning are widely used; 2) developing a new seminar course “Graph Learning in the Adversarial Settings”, and 3)supporting cross-disciplinary research for both undergraduate and graduate students.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(2)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3616855.3635826
发表时间:
2020-09
期刊:
Proceedings of the 17th ACM International Conference on Web Search and Data Mining
影响因子:
--
作者:
[Binghui Wang;Tianxiang Zhou;Min-Bin Lin;Pan Zhou;Ang Li;Meng Pang;Cai Fu;H. Li;Yiran Chen]
通讯作者:
Binghui Wang;Tianxiang Zhou;Min-Bin Lin;Pan Zhou;Ang Li;Meng Pang;Cai Fu;H. Li;Yiran Chen
DOI:
10.1109/cvpr52729.2023.01573
发表时间:
2023-03
期刊:
2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)
影响因子:
--
作者:
[Binghui Wang;Meng Pang;Yun Dong]
通讯作者:
Binghui Wang;Meng Pang;Yun Dong
Collaborative Research: SHF: Small: LEGAS: Learning Evolving Graphs At Scale
-
批准号:2331302
-
项目类别:Standard Grant
-
资助金额:$29.13万
-
财政年份:2024
-
负责人:Binghui Wang
-
依托单位:
CAREER: Towards Trustworthy Machine Learning via Learning Trustworthy Representations: An Information-Theoretic Framework
-
批准号:2339686
-
项目类别:Continuing Grant
-
资助金额:$54.8万
-
财政年份:2024
-
负责人:Binghui Wang
-
依托单位:
CRII: SaTC: Discerning the Upgradeability of Smart Contracts in Blockchains From a Security Perspective
-
批准号:2245627
-
项目类别:Standard Grant
-
资助金额:$17.48万
-
财政年份:2023
-
负责人:Binghui Wang
-
依托单位:
海外基金