首个实用的动态图链接预测黑盒逃逸攻击方法
Practicable Black-box Evasion Attacks on Link Prediction in Dynamic Graphs -- A Graph Sequential Embedding Method
- 基于深度强化学习构建图序列嵌入模型,实现有限扰动下的有效攻击
- 在三次真实数据集上验证,攻击成功率显著优于现有方法
- 适合研究模型安全与对抗攻击的学者及工业界安全评估人员
动态图中的链接预测(LPDG)广泛应用于网站推荐、交通流量预测、组织研究等场景。由于模型通常本地部署且仅开放有限接口,如何在交互和扰动受限条件下实施黑盒逃逸攻击具有实际意义。本文提出首个可行的黑盒逃逸攻击方法,在有限交互和扰动下有效攻击目标LPDG模型。为在少扰动下实现高效攻击,我们设计了图序列嵌入模型,并在深度强化学习框架下优化动态图序列的期望状态嵌入。为缓解交互稀疏问题,引入多环境训练管道,通过共享全局交互缓冲区训练多个实例。我们在三个不同规模的真实图数据集上对三种先进LPDG模型进行评估,实验表明该攻击在交互与扰动约束下兼具有效性与可行性。
原文摘要 · Abstract (English)
Link prediction in dynamic graphs (LPDG) has been widely applied to real-world applications such as website recommendation, traffic flow prediction, organizational studies, etc. These models are usually kept local and secure, with only the interactive interface restrictively available to the public. Thus, the problem of the black-box evasion attack on the LPDG model, where model interactions and data perturbations are restricted, seems to be essential and meaningful in practice. In this paper, we propose the first practicable black-box evasion attack method that achieves effective attacks against the target LPDG model, within a limited amount of interactions and perturbations. To perform effective attacks under limited perturbations, we develop a graph sequential embedding model to find the desired state embedding of the dynamic graph sequences, under a deep reinforcement learning framework. To overcome the scarcity of interactions, we design a multi-environment training pipeline and train our agent for multiple instances, by sharing an aggregate interaction buffer. Finally, we evaluate our attack against three advanced LPDG models on three real-world graph datasets of different scales and compare its performance with related methods under the interaction and perturbation constraints. Experimental results show that our attack is both effective and practicable.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。