arXiv:2604.15370cs.CRcs.LG2026-04

通过动态系统理论定位图神经网络抗攻击的临界状态

TopFeaRe: Locating Critical State of Adversarial Resilience for Graphs Regarding Topology-Feature Entanglement

论文配图:TopFeaRe: Locating Critical State of Adversarial Resilience for Graphs Regarding Topology-Feature Entanglement
图 1 · 摘自论文原文
  • 将图结构与节点特征融合建模为二维动态扰动函数
  • 在五个真实数据集上显著优于现有最先进方法
  • 适合研究图对抗攻击机制与防御策略的学者

图对抗攻击通常从拓扑结构和节点特征两个角度发起,二者均是当前深度学习模型所依赖的关键表征。尽管已有若干防御方法,但未能揭示这两方面为何必要及其如何协同学习图表示。本文提出一种基于复杂动态系统平衡点理论的防御方法,通过定位图的对抗鲁棒性临界状态来实现。核心创新包括:i)将图状态映射至复杂动态系统(CDS),用系统振荡模拟对抗扰动行为;ii)设计二维拓扑-特征纠缠扰动函数,分别投影拓扑与特征空间并建模动态变化;iii)利用平衡点理论,基于扰动反映的二维函数定位图的抗攻击临界状态。在五个常用真实数据集上的多维度实验验证了方法有效性,结果表明其在四种代表性图对抗攻击下显著优于现有基线。

原文摘要 · Abstract (English)

Graph adversarial attacks are usually produced from the two perspectives of topology/structure and node feature, both of them represent the paramount characteristics learned by today's deep learning models. Although some defense countermeasures are proposed at present, they fails to disclose the intrinsic reasons why these two aspects necessitate and how they are adequately fused to co-learn the graph representation. Towards this question, we in this paper propose an adversarial defense approach through locating the graph's critical state of adversarial resilience, resorting to the equilibrium-point theory in the discipline of complex dynamic system (CDS). In brief, our work has three novelties: i) Adversarial-Attack Modeling, i.e. map a graph regime into CDS, and use the oscillation of dynamic system to model the behavior of adversarial perturbation; ii) 2D Topology-Feature-Entangled Function Design for Perturbed Graph, i.e. project graph topology and node feature as two characteristic spaces, and define two-dimensional entangled perturbation functions to represent the dynamic variance under adversarial attacks; and iii) Location of Critical State of Adversarial Resilience, i.e. utilize the equilibrium-point theory to locate the graph's critical state of attack resilience resorting to the perturbation-reflected 2D function. Finally, multi-facet experiments on five commonly-used realistic datasets validate the effectiveness of our proposed approach, and the results show our approach can significantly outperform the state-of-the-art baselines under four representative graph adversarial attacks.

图神经网络对抗攻击动态系统鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。