Logo image
Detecting Targets of Graph Adversarial Attacks With Edge and Feature Perturbations
期刊文章

Detecting Targets of Graph Adversarial Attacks With Edge and Feature Perturbations

Boyi Lee, Jhao-Yin Jhang, Lo-Yao Yeh, Ming-Yi Chang, Chia-Mei ChenChih-Ya Shen
IEEE Transactions on Computational Social Systems
2024

摘要

Closed box Detection Detectors graph adversarial attacks Image edge detection machine learning Perturbation methods Predictive models reinforcement learning Robustness Training Modeling and Simulation Social Sciences (miscellaneous) Human-Computer Interaction
Graph neural networks (GNNs) enable many novel applications and achieve excellent performance. However, their performance may be significantly degraded by the graph adversarial attacks, which intentionally add small perturbations to the graph. Previous countermeasures usually handle such attacks by enhancing model robustness. However, robust models cannot identify the <italic>target nodes</italic> of the adversarial attacks, and thus we are unable to pinpoint the weak spots and analyze the causes or the targets of the attacks. In this article, we study the important research problem to detect the <italic>target nodes</italic> of graph adversarial attacks under the <italic>black-box detection</italic> scenario, which is particularly challenging because our detection models do not have any knowledge about the attacker, while the attackers usually employ unnoticeability strategies to minimize the chance of being detected. To our best knowledge, this is the first work that aims at detecting the <italic>target nodes</italic> of graph adversarial attacks under the <italic>black-box detector</italic> scenario. We propose two detection models, named <italic>Det-H</italic> and <italic>Det-RL</italic>, which employ different techniques that effectively detect the target nodes under the black-box detection scenario against various graph adversarial attacks. To enhance the generalization of the proposed detectors, we further propose two novel surrogate attackers that are able to generate effective attack examples and camouflage their attack traces for training robust detectors. In addition, we propose three strategies to effectively improve the training efficiency. Experimental results on multiple datasets show that our proposed detectors significantly outperform the other baselines against multiple state-of-the-art graph adversarial attackers with various attack strategies. The proposed <italic>Det-RL</italic> detector achieves an averaged area under curve (AUC) of 0.945 against all the attackers, and our efficiency-improving strategies are able save up to 91&null of the training time.

相關連結

指標

1 檢視次數

詳細資料

Logo image