跳到主要导航 跳到搜索 跳到主要内容

Adversarial label-flipping attack and defense for graph neural networks

  • Mengmei Zhang
  • , Linmei Hu
  • , Chuan Shi
  • , Xiao Wang
  • Beijing University of Posts and Telecommunications

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

With the great popularity of Graph Neural Networks (GNNs), the robustness of GNNs to adversarial attacks has received increasing attention. However, existing works neglect adversarial label-flipping attacks, where the attacker can manipulate an unnoticeable fraction of training labels. Exploring the robustness of GNNs to label-flipping attacks is highly critical, especially when labels are collected from external sources and false labels are easy to inject (e.g., recommendation systems). In this work, we introduce the first study of adversarial label-flipping attacks on GNNs. We propose an effective attack model LafAK based on approximated closed form of GNNs and continuous surrogate of non-differentiable objective, efficiently generating attacks via gradient-based optimizers. Furthermore, we show that one key reason for the vulnerability of GNNs to label-flipping attack is overfitting to flipped nodes. Based on this observation, we propose a defense framework which introduces a community-preserving self-supervised task as regularization to avoid overfitting. We demonstrate the effectiveness of our proposed attack model to GNNs on four real-world datasets. The effectiveness of our defense framework is also well validated by the substantial improvements of defense based GNN and its variants under label-flipping attacks.

源语言英语
主期刊名Proceedings - 20th IEEE International Conference on Data Mining, ICDM 2020
编辑Claudia Plant, Haixun Wang, Alfredo Cuzzocrea, Carlo Zaniolo, Xindong Wu
出版商Institute of Electrical and Electronics Engineers Inc.
791-800
页数10
ISBN(电子版)9781728183169
DOI
出版状态已出版 - 11月 2020
已对外发布
活动20th IEEE International Conference on Data Mining, ICDM 2020 - Virtual, Sorrento, 意大利
期限: 17 11月 202020 11月 2020

出版系列

姓名Proceedings - IEEE International Conference on Data Mining, ICDM
2020-November
ISSN(印刷版)1550-4786

会议

会议20th IEEE International Conference on Data Mining, ICDM 2020
国家/地区意大利
Virtual, Sorrento
时期17/11/2020/11/20

学术指纹

探究 'Adversarial label-flipping attack and defense for graph neural networks' 的科研主题。它们共同构成独一无二的学术指纹。

引用此