arXiv:2412.18365cs.LGcs.AI2024-12被引 8

通过向核心超边注入同质节点,提升对超图神经网络的攻击效果与隐蔽性。

Hypergraph Attacks via Injecting Homogeneous Nodes into Elite Hyperedges

  • 基于节点跨度识别关键超边,选择高价值注入目标。
  • 用核密度估计生成符合超边群体特征的同质节点。
  • 在五个真实数据集上验证,攻击更隐蔽且效果优于现有方法。

近期研究表明,超图神经网络(HGNNs)易受对抗攻击。现有方法多依赖梯度引导的超图修改,忽视了超图中节点的跨度特性及超边的群体身份,导致攻击性能有限且易被检测。本文提出新框架IE-Attack,即通过向核心超边注入同质节点实现攻击。首先,利用节点跨度特性,设计精英超边采样器识别待注入超边;其次,采用核密度估计(KDE)构建符合超边群体特征的同质节点;最后,将生成节点注入精英超边,显著提升攻击效果并增强隐蔽性。在五个真实数据集上进行的大量实验验证了该方法的有效性及其相对于先进方法的优势。

原文摘要 · Abstract (English)

Recent studies have shown that Hypergraph Neural Networks (HGNNs) are vulnerable to adversarial attacks. Existing approaches focus on hypergraph modification attacks guided by gradients, overlooking node spanning in the hypergraph and the group identity of hyperedges, thereby resulting in limited attack performance and detectable attacks. In this manuscript, we present a novel framework, i.e., Hypergraph Attacks via Injecting Homogeneous Nodes into Elite Hyperedges (IE-Attack), to tackle these challenges. Initially, utilizing the node spanning in the hypergraph, we propose the elite hyperedges sampler to identify hyperedges to be injected. Subsequently, a node generator utilizing Kernel Density Estimation (KDE) is proposed to generate the homogeneous node with the group identity of hyperedges. Finally, by injecting the homogeneous node into elite hyperedges, IE-Attack improves the attack performance and enhances the imperceptibility of attacks. Extensive experiments are conducted on five authentic datasets to validate the effectiveness of IE-Attack and the corresponding superiority to state-of-the-art methods.

超图神经网络对抗攻击生成模型隐匿攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。