arXiv:2505.14463cs.LG2025-05被引 1

发现图数据对抗攻击下的临界稳定态,可提升防御能力

Adverseness vs. Equilibrium: Exploring Graph Adversarial Resilience through Dynamic Equilibrium

论文配图:Adverseness vs. Equilibrium: Exploring Graph Adversarial Resilience through Dynamic Equilibrium
图 1 · 摘自论文原文
  • 将图对抗学习建模为动态系统,分析攻击行为演化
  • 理论证明存在临界防御状态,且在五大数据集上验证
  • 通过一维函数求解平衡点,适合安全敏感场景研究

图数据分析面临的对抗攻击日益受到关注。现有防御方法主要从图结构或图神经网络角度出发,但尚未回答图自身是否存在内在的对抗鲁棒性状态,以及如何识别该关键状态。本文从三个视角切入:首先将图上的对抗学习过程视为复杂多目标动态系统,建模攻击行为;其次提出广义理论框架,证明临界对抗鲁棒性状态的存在性;最后构建压缩的一维函数,捕捉图在扰动下的动态变化,通过求解系统平衡点定位临界状态。在五个常用真实世界数据集和三种代表性攻击下进行多维度实验,结果表明所提方法显著优于当前最先进防御方法。

原文摘要 · Abstract (English)

Adversarial attacks to graph analytics are gaining increased attention. To date, two lines of countermeasures have been proposed to resist various graph adversarial attacks from the perspectives of either graph per se or graph neural networks. Nevertheless, a fundamental question lies in whether there exists an intrinsic adversarial resilience state within a graph regime and how to find out such a critical state if exists. This paper contributes to tackle the above research questions from three unique perspectives: i) we regard the process of adversarial learning on graph as a complex multi-object dynamic system, and model the behavior of adversarial attack; ii) we propose a generalized theoretical framework to show the existence of critical adversarial resilience state; and iii) we develop a condensed one-dimensional function to capture the dynamic variation of graph regime under perturbations, and pinpoint the critical state through solving the equilibrium point of dynamic system. Multi-facet experiments are conducted to show our proposed approach can significantly outperform the state-of-the-art defense methods under five commonly-used real-world datasets and three representative attacks.

图神经网络对抗攻击动态系统鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。