用控制理论让图神经网络更抗攻击,理论可证明稳定
Lyapunov Stable Graph Neural Flow
- 引入可学习的李雅普诺夫函数和投影机制,约束特征更新过程
- 在多个基准上显著优于基线模型,在各种攻击下保持鲁棒性
- 方法与现有防御兼容,适合需要理论保障的图学习场景
图神经网络(GNN)在拓扑和特征层面均易受对抗扰动影响,学习鲁棒表示成为关键挑战。本文将GNN与控制理论结合,提出基于整数阶与分数阶李雅普诺夫稳定性的新型防御框架。不同于依赖资源密集型对抗训练或数据净化的传统策略,本方法从根本上约束GNN的特征更新动态。我们设计了自适应、可学习的李雅普诺夫函数,并引入一种新颖的投影机制,将网络状态映射至稳定空间,从而提供理论上可证明的稳定性保证。该机制与现有防御正交,可无缝集成对抗训练等技术以实现累积鲁棒性。大量实验表明,所提出的李雅普诺夫稳定图神经流在标准基准和多种对抗攻击场景中,显著优于基础神经流及当前最优基线。
原文摘要 · Abstract (English)
Graph Neural Networks (GNNs) are highly vulnerable to adversarial perturbations in both topology and features, making the learning of robust representations a critical challenge. In this work, we bridge GNNs with control theory to introduce a novel defense framework grounded in integer- and fractional-order Lyapunov stability. Unlike conventional strategies that rely on resource-heavy adversarial training or data purification, our approach fundamentally constrains the underlying feature-update dynamics of the GNN. We propose an adaptive, learnable Lyapunov function paired with a novel projection mechanism that maps the network's state into a stable space, thereby offering theoretically provable stability guarantees. Notably, this mechanism is orthogonal to existing defenses, allowing for seamless integration with techniques like adversarial training to achieve cumulative robustness. Extensive experiments demonstrate that our Lyapunov-stable graph neural flows substantially outperform base neural flows and state-of-the-art baselines across standard benchmarks and various adversarial attack scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。