arXiv:2510.15333cs.LG2025-10

用专家混合模型统一防御图数据的多种恶意攻击。

Backdoor or Manipulation? Graph Mixture of Experts Can Defend Against Various Graph Adversarial Attacks

  • 引入逻辑多样性损失,让不同专家关注不同邻域结构。
  • 设计自适应路由机制,识别攻击模式并引导节点到稳健专家。
  • 在多种攻击下均表现更优,适合高安全要求的图神经网络应用。

大量研究揭示了图神经网络(GNN)对对抗攻击的脆弱性,包括操纵、节点注入以及新兴的后门攻击。然而,现有防御方法通常只针对单一攻击类型,缺乏统一应对多种威胁的能力。本文利用专家混合(MoE)架构的灵活性,提出一种可扩展且统一的防御框架,以同时抵御后门攻击、边操纵和节点注入攻击。具体而言,我们设计基于互信息(MI)的逻辑多样性损失,促使各专家在决策过程中专注于不同的局部邻域结构,从而确保在局部结构被扰动时仍有一部分专家保持不变。此外,我们引入一个鲁棒性感知的路由器,能够识别扰动模式,并将受干扰节点动态路由至对应的稳健专家。在多种对抗设置下的大量实验表明,该方法在应对多种图对抗攻击时始终表现出更强的鲁棒性。

原文摘要 · Abstract (English)

Extensive research has highlighted the vulnerability of graph neural networks (GNNs) to adversarial attacks, including manipulation, node injection, and the recently emerging threat of backdoor attacks. However, existing defenses typically focus on a single type of attack, lacking a unified approach to simultaneously defend against multiple threats. In this work, we leverage the flexibility of the Mixture of Experts (MoE) architecture to design a scalable and unified framework for defending against backdoor, edge manipulation, and node injection attacks. Specifically, we propose an MI-based logic diversity loss to encourage individual experts to focus on distinct neighborhood structures in their decision processes, thus ensuring a sufficient subset of experts remains unaffected under perturbations in local structures. Moreover, we introduce a robustness-aware router that identifies perturbation patterns and adaptively routes perturbed nodes to corresponding robust experts. Extensive experiments conducted under various adversarial settings demonstrate that our method consistently achieves superior robustness against multiple graph adversarial attacks.

图神经网络对抗攻击专家混合

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。