arXiv:2509.17987cs.LG2025-09

限定节点扰动下,用图解释+中心性剪枝实现高效图神经网络异常检测欺骗

Budgeted Indirect Adversarial Attack on Graph-Based Anomaly Detection in Sensor Networks

  • 通过图解释与中心性剪枝定位关键干扰节点
  • 在真实数据集上使顶尖检测器F1分数平均下降36.07%~50.45%
  • 适用于资源受限场景下的隐蔽对抗攻击研究

图神经网络(GNN)在分析多变量时间序列的传感器网络异常检测中表现出强大能力。本文提出BETA,一种新型间接逃避攻击方法,攻击者仅能对有限节点的传感器读数进行扰动,且不包括目标节点,目标是抑制真实异常或在目标节点制造误报。BETA结合图解释模型与基于中心性的剪枝策略,识别最具影响力的节点,并向其特征注入精心设计的对抗扰动。在三个真实传感器网络数据集上的大量实验表明,BETA在符合实际约束条件下持续优于基线攻击策略,使最先进的GNN检测器的F1分数平均降低36.07%至50.45%。

原文摘要 · Abstract (English)

Graph Neural Networks (GNNs) have emerged as powerful models for anomaly detection in sensor networks, particularly when analyzing multivariate time series. In this work, we introduce BETA, a novel indirect evasion attack targeting such GNN-based detectors, where the attacker is constrained to perturb sensor readings from a limited set of nodes, excluding the target sensor, with the goal of either suppressing a true anomaly or triggering a false alarm at the target node. BETA uses a graph explanatory model combined with a centrality-based pruning strategy to identify the most influential nodes, subsequently injecting carefully crafted adversarial perturbations into their features. Extensive experiments on three real-world sensor network datasets show that BETA consistently outperforms baseline attack strategies while operating under realistic constraints, reducing the F1-score of state-of-the-art GNN-based detectors by 36.07 to 50.45\% on average.

图神经网络对抗攻击异常检测传感器网络

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。