arrow
Return

Adversarial Attack Framework on Graph Embedding Models With Limited Knowledge

delete2022-01-01
delete9
delete
OA
AI
H
Heng Chang
R
Rong, Yu *
T
Tingyang Xu
黄文炳 (Wenbing Huang)
H
Honglei Zhang
P
Peng Cui
X
Xin Wang
W
Wenwu Zhu *
J
Junzhou Huang
DOI:10.1109/TKDE.2022.3153060delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
With the success of the graph embedding model in both academic and industrial areas, the robustness of graph embeddings against adversarial attacks inevitably becomes a crucial problem in graph learning. Existing works usually perform the attack in a white-box fashion: they need to access the predictions/labels to construct their adversarial losses. However, the inaccessibility of predictions/labels makes the white-box attack impractical for a real graph learning system. This paper promotes current frameworks in a more general and flexible sense - we consider the ability of various types of graph embedding models to remain resilient against black-box driven attacks. We investigate the theoretical connection between graph signal processing and graph embedding models, and formulate the graph embedding model as a general graph signal process with a corresponding graph filter. Therefore, we design a generalized adversarial attack framework: GF-Attack. Without accessing any labels and model predictions, GF-Attack can perform the attack directly on the graph filter in a black-box fashion. We further prove that GF-Attack can perform an effective attack without assumption on the number of layers/window-size of graph embedding models. To validate the generalization of GF-Attack, we construct GF-Attack on five popular graph embedding models. Extensive experiments validate the effectiveness of GF-Attack on several benchmark datasets.
Keywords:
Predictive models
Data models
Task analysis
Information filters
Electronic mail
Veins
Deep learning
Adversarial attack
deep graph learning
graph neural networks
graph representation learning

Journal

IEEE Transactions on Knowledge and Data Engineering cover
IEEE Transactions on Knowledge and Data Engineering
IF:
10.4
Papers:
6.7K
Citations:
3.2W

Organization

T
tsinghua university
Scholars:
11.7W
Papers: 10.0W
Citations: 137
T
Tsinghua Shenzhen International Graduate School
Scholars:
6.8K
Papers: 4.9K
Citations: 9
T
Tencent
Scholars:
1.1K
Papers: 893
Citations: 5
researcher View more organizations