提出新型黑盒攻击方法,精准打击动态图神经网络的关键节点与边。
Leveraging Vulnerabilities in Temporal Graph Neural Networks via Strategic High-Impact Assaults
- 构建代理模型识别结构与动态关键节点,指导攻击策略。
- 混合注入与删除边,使链接预测准确率下降最高达35.55%。
- 扰动少且隐蔽,适用于评估动态图模型的安全性。
动态图神经网络(TGNNs)在社交网络、通信系统和金融网络等关键场景中日益重要,但其对对抗攻击的鲁棒性,尤其是利用时间维度的复杂攻击,仍是重大挑战。现有针对时空动态图(STDGs)的攻击方法多依赖简单、易被检测的扰动(如随机增删边),无法有效瞄准最具影响力的节点与边。本文提出高影响攻击(HIA),一种新型受限黑盒攻击框架,通过数据驱动的代理模型识别结构关键节点(维系网络连通性)与动态关键节点(影响图演化)。采用混合扰动策略,结合战略性边注入(制造误导连接)与目标边删除(破坏关键路径),最大化降低TGNN性能。关键优势在于最小化扰动数量以增强隐蔽性。在五个真实数据集和四种代表性TGNN架构(TGN、JODIE、DySAT、TGAT)上的实验表明,HIA显著降低链接预测准确率,使平均倒数排名(MRR)最高下降35.55%,优于当前最先进基线。结果揭示了现有STDG模型的根本漏洞,凸显需同时考虑结构与时间动态的鲁棒防御的紧迫性。
原文摘要 · Abstract (English)
Temporal Graph Neural Networks (TGNNs) have become indispensable for analyzing dynamic graphs in critical applications such as social networks, communication systems, and financial networks. However, the robustness of TGNNs against adversarial attacks, particularly sophisticated attacks that exploit the temporal dimension, remains a significant challenge. Existing attack methods for Spatio-Temporal Dynamic Graphs (STDGs) often rely on simplistic, easily detectable perturbations (e.g., random edge additions/deletions) and fail to strategically target the most influential nodes and edges for maximum impact. We introduce the High Impact Attack (HIA), a novel restricted black-box attack framework specifically designed to overcome these limitations and expose critical vulnerabilities in TGNNs. HIA leverages a data-driven surrogate model to identify structurally important nodes (central to network connectivity) and dynamically important nodes (critical for the graph's temporal evolution). It then employs a hybrid perturbation strategy, combining strategic edge injection (to create misleading connections) and targeted edge deletion (to disrupt essential pathways), maximizing TGNN performance degradation. Importantly, HIA minimizes the number of perturbations to enhance stealth, making it more challenging to detect. Comprehensive experiments on five real-world datasets and four representative TGNN architectures (TGN, JODIE, DySAT, and TGAT) demonstrate that HIA significantly reduces TGNN accuracy on the link prediction task, achieving up to a 35.55% decrease in Mean Reciprocal Rank (MRR) - a substantial improvement over state-of-the-art baselines. These results highlight fundamental vulnerabilities in current STDG models and underscore the urgent need for robust defenses that account for both structural and temporal dynamics.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。