arXiv:2503.20630cs.LGcs.AI2025-03中稿 · EuroMLSys 2025被引 3

用动态权重提升GNN抗扰能力,不牺牲正常数据表现。

$β$-GNN: A Robust Ensemble Approach Against Graph Structure Perturbation

  • 通过可学习的动态权重β融合GNN与MLP,自适应调节模型输出。
  • 在多个数据集上实现更高对抗准确率,且能量化攻击严重程度。
  • 无需预设扰动假设,适合实际部署中兼顾安全与性能的场景。

图神经网络(GNN)在计算系统的高效运行与安全保障中扮演关键角色,广泛应用于工作负载调度、异常检测和资源管理。然而,其对图结构扰动的脆弱性构成重大挑战。本文提出β-GNN,一种在不牺牲干净数据性能的前提下增强GNN鲁棒性的集成方法。该方法采用加权集成,将任意GNN与多层感知机(MLP)结合,通过一个可学习的动态权重β调节GNN的贡献。该β不仅控制GNN的影响程度,还能反映数据扰动水平,从而实现主动防御。在多种数据集上的实验表明,β-GNN在对抗准确性方面优于现有方法,并具备攻击严重程度量化能力。尤为重要的是,该方法无需依赖扰动假设,有效保留了原始数据结构与性能。

原文摘要 · Abstract (English)

Graph Neural Networks (GNNs) are playing an increasingly important role in the efficient operation and security of computing systems, with applications in workload scheduling, anomaly detection, and resource management. However, their vulnerability to network perturbations poses a significant challenge. We propose $β$-GNN, a model enhancing GNN robustness without sacrificing clean data performance. $β$-GNN uses a weighted ensemble, combining any GNN with a multi-layer perceptron. A learned dynamic weight, $β$, modulates the GNN's contribution. This $β$ not only weights GNN influence but also indicates data perturbation levels, enabling proactive mitigation. Experimental results on diverse datasets show $β$-GNN's superior adversarial accuracy and attack severity quantification. Crucially, $β$-GNN avoids perturbation assumptions, preserving clean data structure and performance.

图神经网络鲁棒性动态权重

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。