arXiv:2409.14161cs.LG2024-09AAAI被引 8

用拓扑方法增强图神经网络抗攻击能力,仅依赖关键节点提取稳定结构特征。

When Witnesses Defend: A Witness Graph Topological Layer for Adversarial Graph Learning

  • 基于关键节点构建威见证复形,保留图的核心拓扑结构。
  • 在六大数据集上显著提升图神经网络对多种攻击的鲁棒性。
  • 可集成于五种GNN和三种防御方法,适合图对抗防御研究者。

基于形状特征对扰动更鲁棒的直观假设,我们将计算拓扑中的持续同调表示引入对抗图学习。提出图威见证复形概念,仅通过最核心节点(地标)捕获图的显著形状特征,其余节点作为见证者决定高阶子结构是否参与学习,实现拓扑信息最小损失。据此设计了威见证图拓扑层(WGTL),系统融合局部与全局拓扑特征,并由鲁棒正则化拓扑损失自动调控影响。针对攻击预算,推导出局部与全局拓扑编码的稳定性保证及相应鲁棒损失。通过集成五种GNN和三种非拓扑防御机制,验证了WGTL的通用性与高效性。在六个数据集上的大量实验表明,该方法显著增强图神经网络在多种扰动和攻击下的鲁棒性。数据集与源码已公开于 https://github.com/toggled/WGTL。

原文摘要 · Abstract (English)

Capitalizing on the intuitive premise that shape characteristics are more robust to perturbations, we bridge adversarial graph learning with the emerging tools from computational topology, namely, persistent homology representations of graphs. We introduce the concept of witness complex to adversarial analysis on graphs, which allows us to focus only on the salient shape characteristics of graphs, yielded by the subset of the most essential nodes (i.e., landmarks), with minimal loss of topological information on the whole graph. The remaining nodes are then used as witnesses, governing which higher-order graph substructures are incorporated into the learning process. Armed with the witness mechanism, we design Witness Graph Topological Layer (WGTL), which systematically integrates both local and global topological graph feature representations, the impact of which is, in turn, automatically controlled by the robust regularized topological loss. Given the attacker's budget, we derive the important stability guarantees of both local and global topology encodings and the associated robust topological loss. We illustrate the versatility and efficiency of WGTL by its integration with five GNNs and three existing non-topological defense mechanisms. Our extensive experiments across six datasets demonstrate that WGTL boosts the robustness of GNNs across a range of perturbations and against a range of adversarial attacks. Our datasets and source codes are available at https://github.com/toggled/WGTL.

图神经网络对抗攻击拓扑学习鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。