无需先验知识,用扩散模型净化图结构对抗攻击
Robust Graph Learning Against Adversarial Evasion Attacks via Prior-Free Diffusion-Based Structure Purification
- 用扩散模型学习干净图的内在分布,无须依赖攻击或图结构先验
- 在多种攻击和数据集上显著提升GNN鲁棒性,效果优于现有方法
- 适合研究图神经网络安全与对抗防御的学者和工程师
对抗性逃避攻击对图学习构成重大威胁。现有方法多依赖对干净图或攻击策略的先验知识,常具启发性且不一致。为在不同攻击类型和数据集上实现鲁棒图学习,本文从无先验结构净化视角出发,提出新型扩散结构净化框架DiffSP。该框架通过图扩散模型学习干净图的内在分布,利用捕获的预测模式指导净化被扰动的图结构,无需依赖任何先验。DiffSP包含前向扩散与反向去噪过程,实现结构净化。为避免前向过程中有价值信息丢失,提出基于LID的非各向同性噪声注入机制,选择性地异质加噪;为促进反向生成中干净图与净化图间的语义对齐,设计图转移熵引导的去噪机制以降低生成不确定性。大量实验表明,DiffSP在多种逃避攻击下均表现出优越鲁棒性。
原文摘要 · Abstract (English)
Adversarial evasion attacks pose significant threats to graph learning, with lines of studies that have improved the robustness of Graph Neural Networks (GNNs). However, existing works rely on priors about clean graphs or attacking strategies, which are often heuristic and inconsistent. To achieve robust graph learning over different types of evasion attacks and diverse datasets, we investigate this problem from a prior-free structure purification perspective. Specifically, we propose a novel Diffusion-based Structure Purification framework named DiffSP, which creatively incorporates the graph diffusion model to learn intrinsic distributions of clean graphs and purify the perturbed structures by removing adversaries under the direction of the captured predictive patterns without relying on priors. DiffSP is divided into the forward diffusion process and the reverse denoising process, during which structure purification is achieved. To avoid valuable information loss during the forward process, we propose an LID-driven nonisotropic diffusion mechanism to selectively inject noise anisotropically. To promote semantic alignment between the clean graph and the purified graph generated during the reverse process, we reduce the generation uncertainty by the proposed graph transfer entropy guided denoising mechanism. Extensive experiments demonstrate the superior robustness of DiffSP against evasion attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。