arXiv:2505.02566cs.LGcs.AI2025-05被引 4

GNN模型在对抗攻击下,可解释性与鲁棒性存在严重权衡。

Robustness questions the interpretability of graph neural networks: what to do?

  • 构建基准测试框架,评估六种GNN架构在五数据集上的可解释性表现
  • 发现防御策略会显著降低解释性,且不同模型差异大
  • 适合关注GNN安全与可信部署的研究者和工程师

图神经网络(GNN)已成为图数据分析的核心工具,广泛应用于生物信息学、社交网络和推荐系统等领域。然而,模型可解释性与鲁棒性之间的关系在对抗场景(如投毒和逃避攻击)下仍不明确。本文构建了综合性基准,系统分析多种因素对GNN可解释性的影响,包括增强鲁棒性的防御机制。我们在五个来自两个不同领域的数据集上,评估了基于GCN、SAGE、GIN和GAT的六种GNN架构,采用四种可解释性度量:保真度、稳定性、一致性与稀疏性。研究考察了在训练前和训练中应用的防投毒与防逃避攻击策略对可解释性的影响,揭示了鲁棒性与可解释性之间的关键权衡。框架将开源发布。结果表明,可解释性随防御方法和模型架构特征有显著变化。本工作建立了标准化基准,为开发既鲁棒又可解释的GNN提供了基础,有助于提升其在敏感场景中的可信度。

原文摘要 · Abstract (English)

Graph Neural Networks (GNNs) have become a cornerstone in graph-based data analysis, with applications in diverse domains such as bioinformatics, social networks, and recommendation systems. However, the interplay between model interpretability and robustness remains poorly understood, especially under adversarial scenarios like poisoning and evasion attacks. This paper presents a comprehensive benchmark to systematically analyze the impact of various factors on the interpretability of GNNs, including the influence of robustness-enhancing defense mechanisms. We evaluate six GNN architectures based on GCN, SAGE, GIN, and GAT across five datasets from two distinct domains, employing four interpretability metrics: Fidelity, Stability, Consistency, and Sparsity. Our study examines how defenses against poisoning and evasion attacks, applied before and during model training, affect interpretability and highlights critical trade-offs between robustness and interpretability. The framework will be published as open source. The results reveal significant variations in interpretability depending on the chosen defense methods and model architecture characteristics. By establishing a standardized benchmark, this work provides a foundation for developing GNNs that are both robust to adversarial threats and interpretable, facilitating trust in their deployment in sensitive applications.

GNN可解释性鲁棒性对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。