arXiv:2506.07428cs.AIcs.LG2025-06IJCAI被引 2

提出可跨模型通用的异构图攻击框架,快速适配新图并生成有效扰动。

HeTa: Relation-wise Heterogeneous Graph Foundation Attack Model

  • 基于关系感知机制挖掘共性攻击单元,构建通用攻击代理模型
  • 在多个HGNN上实现90%以上攻击成功率,且对新图仅需少量微调
  • 适合研究图神经网络安全性的研究人员,尤其关注可迁移攻击

异构图神经网络(HGNNs)存在安全隐患,亟需针对性攻击来评估其鲁棒性。然而现有攻击方法通常需为新场景重新训练参数,难以泛化。受基础模型在图神经网络中共享语义能力的启发,我们探索能否设计一个面向HGNN的基础攻击模型,实现跨不同HGNN的通用扰动生成,并快速适应新异构图(HGs)。实验发现,尽管模型设计和参数空间差异显著,不同HGNN在关系层面却表现出相似的脆弱模式。为此,本文提出新型关系感知异构图基础攻击模型HeTa:通过构建基础代理模型对齐异质性,识别共享的关系级攻击单元;在此基础上,按关系序列化实施攻击。该方法使扰动可迁移至多种目标HGNN,且在新图上仅需少量微调即可生效。大量实验表明,该方法具备强大攻击性能与广泛泛化能力。

原文摘要 · Abstract (English)

Heterogeneous Graph Neural Networks (HGNNs) are vulnerable, highlighting the need for tailored attacks to assess their robustness and ensure security. However, existing HGNN attacks often require complex retraining of parameters to generate specific perturbations for new scenarios. Recently, foundation models have opened new horizons for the generalization of graph neural networks by capturing shared semantics across various graph distributions. This leads us to ask:Can we design a foundation attack model for HGNNs that enables generalizable perturbations across different HGNNs, and quickly adapts to new heterogeneous graphs (HGs)? Empirical findings reveal that, despite significant differences in model design and parameter space, different HGNNs surprisingly share common vulnerability patterns from a relation-aware perspective. Therefore, we explore how to design foundation HGNN attack criteria by mining shared attack units. In this paper, we propose a novel relation-wise heterogeneous graph foundation attack model, HeTa. We introduce a foundation surrogate model to align heterogeneity and identify the importance of shared relation-aware attack units. Building on this, we implement a serialized relation-by-relation attack based on the identified relational weights. In this way, the perturbation can be transferred to various target HGNNs and easily fine-tuned for new HGs. Extensive experiments exhibit powerful attack performances and generalizability of our method.

图神经网络攻击模型可迁移性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。