攻击图神经网络高阶语义,隐蔽性强且不破坏原始结构特征
AHSG: Adversarial Attack on High-level Semantics in Graph Neural Networks
- 基于潜在表示与共享主语义,保留原始图属性和关系模式
- 在防御模型上攻击成功率超越现有方法,验证有效性
- 适合研究图神经网络安全与对抗检测的学者参考
图神经网络的对抗攻击通过精心修改图结构和节点属性来降低学习器性能。现有方法虽通过限制修改预算和图属性差异实现隐蔽性,但通常直接破坏任务相关的主语义,导致攻击易被防御或检测。本文提出针对图神经网络高阶语义的对抗攻击方法AHSG,该方法在保持原始图主语义不变的前提下实施攻击。通过结合潜在表示与共享主语义,保留原始图中可检测的属性和关系模式,同时利用更细微的变化完成攻击。采用投影梯度下降算法将带有攻击效果的潜在表示映射至对抗图。在配备防御策略的鲁棒图深度学习模型上的实验表明,AHSG在攻击有效性上优于其他先进方法。此外,使用上下文随机块模型检测攻击图进一步验证了本方法对图主语义的良好保留。
原文摘要 · Abstract (English)
Adversarial attacks on Graph Neural Networks aim to perturb the performance of the learner by carefully modifying the graph topology and node attributes. Existing methods achieve attack stealthiness by constraining the modification budget and differences in graph properties. However, these methods typically disrupt task-relevant primary semantics directly, which results in low defensibility and detectability of the attack. In this paper, we propose an Adversarial Attack on High-level Semantics for Graph Neural Networks (AHSG), which is a graph structure attack model that ensures the retention of primary semantics. By combining latent representations with shared primary semantics, our model retains detectable attributes and relational patterns of the original graph while leveraging more subtle changes to carry out the attack. Then we use the Projected Gradient Descent algorithm to map the latent representations with attack effects to the adversarial graph. Through experiments on robust graph deep learning models equipped with defense strategies, we demonstrate that AHSG outperforms other state-of-the-art methods in attack effectiveness. Additionally, using Contextual Stochastic Block Models to detect the attacked graph further validates that our method preserves the primary semantics of the graph.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。