GRD-GNN: Graph Reconstruction Defense for Graph Neural Network
-
摘要: 近年来,图神经网络在图表示学习领域中取得了较好表现广泛应用于日常生活中,例如电子商务、社交媒体和生物学等.但是研究表明,图神经网络容易受到精心设计的对抗攻击迷惑,使其无法正常工作.因此,提高图神经网络的鲁棒性至关重要.已有研究提出了一些提高图神经网络鲁棒性的防御方法,然而如何在确保模型主任务性能的前提下降低对抗攻击的攻击成功率仍存在挑战.通过观察不同攻击产生的对抗样本发现,对抗攻击生成的对抗连边所对应的节点对之间通常存在低结构相似性和低节点特征相似性的特点.基于上述发现,提出了一种面向图神经网络的图重构防御方法GRD-GNN,分别从图结构和节点特征考虑,采用共同邻居数和节点相似度2种相似度指标检测对抗连边并实现图重构,使得重构的图结构删除对抗连边,且添加了增强图结构关键特征的连边,从而实现有效防御.最后,论文在3个真实数据集上展开防御实验,验证了GRD-GNN相比其他防御方法均能取得最佳的防御性能,且不影响正常图数据的分类任务.此外,利用可视化方法对防御结果做解释,解析方法的有效性.Abstract: Recent years, graph neural network (GNN) has been widely applied in our daily life for its satisfying performance in graph representation learning, and such as e-commerce, social media and biology, etc. However, research has suggested that GNNs are vulnerable to adversarial attacks carefully crafted, leading the GNN model to fail. Therefore, it is essential to improve the robustness of graph neural network. Several defense methods have been proposed to improve the robustness of GNNs. However, how to reduce the attack success rate of adversarial attacks while ensuring the performance of the main task of the GNN still remains a challenge. Through the observation of various adversarial samples, it is concluded that the node pairs connected by adversarial edges have characteristics of low structural similarity and low node feature similarity compared with the clean ones. Based on the observation, we propose a graph reconstruction defense for graph neural network named GRD-GNN. Considering both graph structure and node features, both the number of common neighbors and the similarity of nodes are applied to guide the graph reconstruction. GRD-GNN not only removes the adversarial edges, but also adds edges that are beneficial to the performance of the GNN to enhance the graph structure. At last, comprehensive experiments on three real-world datasets verify the art-of-the-state defense performance of proposed GRD-GNN compared with baselines. Additionally, the explanation of the results of experiments and analysis of effectiveness of the method are shown in the paper.
-
-
期刊类型引用(6)
1. 牛惊雷,牛易航. 基于社会网络分析法的洗钱犯罪数据挖掘侦查技术的改进. 贵州警察学院学报. 2024(06): 71-78 . 百度学术
2. 蒋忠珍,何景明. 基于在线评论的高端酱香型白酒消费特征分析——以飞天茅台酒在京东上的在线评论为例. 中国酿造. 2021(10): 235-238 . 百度学术
3. 徐勇,汪倩,武雅利,李晓宇,张心蕊. 用户画像研究的文献计量分析. 榆林学院学报. 2020(02): 4-9 . 百度学术
4. 李贞,吴勇,耿海军. 基于重引力搜索链接预测和评分传播的大数据推荐系统. 计算机应用与软件. 2020(02): 39-47 . 百度学术
5. 张艳红,俞龙. 基于噪声检测修正和神经网络的稀疏数据推荐算法. 计算机应用与软件. 2020(08): 274-281 . 百度学术
6. 汪倩,徐勇,张心蕊,李晓宇. 用户画像研究进展综述. 现代计算机. 2020(24): 60-63 . 百度学术
其他类型引用(6)
计量
- 文章访问数: 827
- HTML全文浏览量: 6
- PDF下载量: 529
- 被引次数: 12