arXiv:2412.05883cs.LGcs.CR2024-12被引 1

研究图神经网络在图压缩下的抗攻击能力,发现降维会加剧攻击影响。

On the Adversarial Robustness of Graph Neural Networks with Graph Reduction

  • 对比六种图粗化和四种图稀疏化对模型鲁棒性的影响
  • 稀疏化可缓解部分攻击,但对PGD攻击无效;粗化显著降低准确率
  • 揭示攻击增强机制,指导构建更鲁棒的加速图神经网络系统

随着图神经网络(GNNs)在大规模图数据上的广泛应用,其在使用图缩减技术提升可扩展性时对对抗攻击的脆弱性尚未得到充分研究。本文通过大量实验,系统考察了图粗化与稀疏化两类缩减方法对GNN对抗攻击鲁棒性的影响。在多个数据集和GNN架构上,评估了四种稀疏化与六种粗化方法在中毒攻击下的表现。结果表明,尽管稀疏化能削弱部分攻击(如Mettack),但对其他攻击(如PGD)效果有限;而粗化则普遍放大攻击影响,随缩减比例下降,分类准确率显著下降。此外,我们分析了此类现象的成因,并评估了防御型GNN模型在图缩减下的表现,为设计高效且鲁棒的图加速系统提供了实践参考。

原文摘要 · Abstract (English)

As Graph Neural Networks (GNNs) become increasingly popular for learning from large-scale graph data across various domains, their susceptibility to adversarial attacks when using graph reduction techniques for scalability remains underexplored. In this paper, we present an extensive empirical study to investigate the impact of graph reduction techniques, specifically graph coarsening and sparsification, on the robustness of GNNs against adversarial attacks. Through extensive experiments involving multiple datasets and GNN architectures, we examine the effects of four sparsification and six coarsening methods on the poisoning attacks. Our results indicate that, while graph sparsification can mitigate the effectiveness of certain poisoning attacks, such as Mettack, it has limited impact on others, like PGD. Conversely, graph coarsening tends to amplify the adversarial impact, significantly reducing classification accuracy as the reduction ratio decreases. Additionally, we provide a novel analysis of the causes driving these effects and examine how defensive GNN models perform under graph reduction, offering practical insights for designing robust GNNs within graph acceleration systems.

图神经网络对抗鲁棒性图缩减攻击防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。