arXiv:2409.19096cs.LGstat.ML2024-09

用加权p-拉普拉斯提升图神经网络抗攻击能力

Enhancing Robustness of Graph Neural Networks through p-Laplacian

  • 基于加权p-拉普拉斯构建高效鲁棒框架
  • 在真实数据集上验证了方法的有效性与效率
  • 适合需要快速部署的图学习场景

随着日常生活中数据量的增长,企业和各利益相关方需要分析数据以实现更精准的预测。传统关系型数据虽已提供诸多洞察,但随着计算能力提升及对实体间深层关系理解的需求增加,新型分析技术应运而生。图数据建模成为理解复杂关系的有力工具,能够实现更真实、灵活的表示。近年来,图神经网络(GNN)在社交网络分析、推荐系统、药物发现等众多领域展现出巨大潜力。然而,数据在训练(投毒攻击)或测试阶段(逃避攻击)可能遭受多种对抗性攻击,导致GNN模型输出被恶意操纵。因此,提升GNN的鲁棒性至关重要。现有鲁棒方法计算开销大,且在攻击强度增强时性能显著下降。本文提出一种基于加权p-拉普拉斯的计算高效框架pLapGNN,用于增强GNN鲁棒性。在多个真实数据集上的实证评估证明了该方法的有效性与高效性。

原文摘要 · Abstract (English)

With the increase of data in day-to-day life, businesses and different stakeholders need to analyze the data for better predictions. Traditionally, relational data has been a source of various insights, but with the increase in computational power and the need to understand deeper relationships between entities, the need to design new techniques has arisen. For this graph data analysis has become an extraordinary tool for understanding the data, which reveals more realistic and flexible modelling of complex relationships. Recently, Graph Neural Networks (GNNs) have shown great promise in various applications, such as social network analysis, recommendation systems, drug discovery, and more. However, many adversarial attacks can happen over the data, whether during training (poisoning attack) or during testing (evasion attack), which can adversely manipulate the desired outcome from the GNN model. Therefore, it is crucial to make the GNNs robust to such attacks. The existing robustness methods are computationally demanding and perform poorly when the intensity of attack increases. This paper presents a computationally efficient framework, namely, pLapGNN, based on weighted p-Laplacian for making GNNs robust. Empirical evaluation on real datasets establishes the efficacy and efficiency of the proposed method.

图神经网络对抗攻击鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。