用元学习设计无权图中毒攻击,显著降低GNN链接预测性能
Exploiting Meta-Learning-based Poisoning Attacks for Graph Link Prediction
- 基于元学习设计加权策略的无权图中毒攻击
- 在多个数据集上显著降低链接预测准确率
- 适合研究GNN安全性的研究人员参考
图数据中的链接预测使用多种算法和图神经网络(GNN)模型来预测节点间的潜在关系,已广泛应用于推荐系统、社交网络和生物结构等领域。然而,近期研究揭示了GNN模型易受对抗攻击(如中毒攻击和逃避攻击)的影响。提升GNN模型的鲁棒性对保障其在实际应用中的稳定表现至关重要。尽管已有大量工作关注提升节点分类任务中GNN的鲁棒性,但链接预测任务的鲁棒性研究仍相对不足。为此,本文提出一种基于元学习的无权图中毒攻击方法,结合加权策略以降低GNN在链接预测任务中的性能。我们在多个不同数据集上的多种链接预测应用中进行了全面实验,评估所提方法及其参数,并在相同条件下与现有方法进行对比。结果表明,该方法能显著降低链接预测性能,且持续优于其他先进基线方法。
原文摘要 · Abstract (English)
Link prediction in graph data uses various algorithms and Graph Nerual Network (GNN) models to predict potential relationships between graph nodes. These techniques have found widespread use in numerous real-world applications, including recommendation systems, community/social networks, and biological structures. However, recent research has highlighted the vulnerability of GNN models to adversarial attacks, such as poisoning and evasion attacks. Addressing the vulnerability of GNN models is crucial to ensure stable and robust performance in GNN applications. Although many works have focused on enhancing the robustness of node classification on GNN models, the robustness of link prediction has received less attention. To bridge this gap, this article introduces an unweighted graph poisoning attack that leverages meta-learning with weighted scheme strategies to degrade the link prediction performance of GNNs. We conducted comprehensive experiments on diverse datasets across multiple link prediction applications to evaluate the proposed method and its parameters, comparing it with existing approaches under similar conditions. Our results demonstrate that our approach significantly reduces link prediction performance and consistently outperforms other state-of-the-art baselines.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。