arXiv:2504.20869cs.LGcs.AI2025-04被引 1

量化图攻击中节点/边扰动的噪声强度,提升攻击可解释性。

Quantifying the Noise of Structural Perturbations on Graph Adversarial Attacks

  • 引入噪声概念衡量每条对抗边的攻击强度
  • 提出三种基于噪声与分类边界优化的攻击策略
  • 揭示有效扰动节点的分布模式,适合安全研究者参考

图神经网络因其强大的邻域信息利用能力被广泛应用于图相关任务,但近期研究证实其对恶意攻击缺乏鲁棒性。现有工作多聚焦于以攻击效果为目标的扰动优化,却较少关注单个扰动(如特定节点或边的注入)的攻击强度量化,导致扰动选择过程缺乏可解释性。本文提出用‘噪声’来量化每条对抗边的攻击强度,并基于该噪声及分类边界,设计了单步与多步优化的三种攻击策略。在多个基准数据集上,针对三种代表性图神经网络的大量实验验证了所提策略的有效性。此外,通过分析有效扰动节点的属性,揭示了其偏好模式。

原文摘要 · Abstract (English)

Graph neural networks have been widely utilized to solve graph-related tasks because of their strong learning power in utilizing the local information of neighbors. However, recent studies on graph adversarial attacks have proven that current graph neural networks are not robust against malicious attacks. Yet much of the existing work has focused on the optimization objective based on attack performance to obtain (near) optimal perturbations, but paid less attention to the strength quantification of each perturbation such as the injection of a particular node/link, which makes the choice of perturbations a black-box model that lacks interpretability. In this work, we propose the concept of noise to quantify the attack strength of each adversarial link. Furthermore, we propose three attack strategies based on the defined noise and classification margins in terms of single and multiple steps optimization. Extensive experiments conducted on benchmark datasets against three representative graph neural networks demonstrate the effectiveness of the proposed attack strategies. Particularly, we also investigate the preferred patterns of effective adversarial perturbations by analyzing the corresponding properties of the selected perturbation nodes.

图神经网络对抗攻击可解释性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。