JANUS通过双约束生成隐秘节点注入攻击,更难被发现。
JANUS: A Dual-Constraint Generative Framework for Stealthy Node Injection Attacks
- 局部对齐特征流形,全局建模语义结构,提升隐蔽性
- 在多个数据集上攻击成功率更高,且更难被检测
- 适合研究图神经网络安全或对抗攻击的学者
图神经网络在诸多应用中表现优异,但易受复杂对抗攻击影响,尤其是节点注入攻击。攻击的成功依赖于隐蔽性——即融入原图并逃避检测。然而现有方法多依赖间接代理指标,忽视注入内容的本质特征,或仅模仿局部结构,导致局部短视问题。为此,我们提出双约束隐秘节点注入框架JANUS(联合节点与全局结构对齐)。在局部层面,采用特征流形对齐策略实现特征空间的几何一致性;在全局层面,引入结构化潜在变量并最大化与生成结构的互信息,确保注入结构符合原图的语义模式。将注入攻击建模为序列决策过程,由强化学习智能体优化。在多个标准数据集上的实验表明,JANUS在攻击有效性和隐蔽性方面均显著优于现有方法。
原文摘要 · Abstract (English)
Graph Neural Networks (GNNs) have demonstrated remarkable performance across various applications, yet they are vulnerable to sophisticated adversarial attacks, particularly node injection attacks. The success of such attacks heavily relies on their stealthiness, the ability to blend in with the original graph and evade detection. However, existing methods often achieve stealthiness by relying on indirect proxy metrics, lacking consideration for the fundamental characteristics of the injected content, or focusing only on imitating local structures, which leads to the problem of local myopia. To overcome these limitations, we propose a dual-constraint stealthy node injection framework, called Joint Alignment of Nodal and Universal Structures (JANUS). At the local level, we introduce a local feature manifold alignment strategy to achieve geometric consistency in the feature space. At the global level, we incorporate structured latent variables and maximize the mutual information with the generated structures, ensuring the injected structures are consistent with the semantic patterns of the original graph. We model the injection attack as a sequential decision process, which is optimized by a reinforcement learning agent. Experiments on multiple standard datasets demonstrate that the JANUS framework significantly outperforms existing methods in terms of both attack effectiveness and stealthiness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。