Adversarial Attacks on Neural Networks for Graph Data
arXiv:1805.07984 · doi:10.1145/3219819.3220078
Abstract
Deep learning models for graphs have achieved strong performance for the task of node classification. Despite their proliferation, currently there is no study of their robustness to adversarial attacks. Yet, in domains where they are likely to be used, e.g. the web, adversaries are common. Can deep learning models for graphs be easily fooled? In this work, we introduce the first study of adversarial attacks on attributed graphs, specifically focusing on models exploiting ideas of graph convolutions. In addition to attacks at test time, we tackle the more challenging class of poisoning/causative attacks, which focus on the training phase of a machine learning model. We generate adversarial perturbations targeting the node's features and the graph structure, thus, taking the dependencies between instances in account. Moreover, we ensure that the perturbations remain unnoticeable by preserving important data characteristics. To cope with the underlying discrete domain we propose an efficient algorithm Nettack exploiting incremental computations. Our experimental study shows that accuracy of node classification significantly drops even when performing only few perturbations. Even more, our attacks are transferable: the learned attacks generalize to other state-of-the-art node classification models and unsupervised approaches, and likewise are successful even when only limited knowledge about the graph is given.
Accepted as a full paper at KDD 2018 on May 6, 2018
References in corpus (9)
- Power-law distributions in empirical data
- The Space of Transferable Adversarial Examples
- Security Evaluation of Pattern Classifiers under Attack
- Adversarial Attack on Graph Structured Data
- Data Poisoning Attacks on Factorization-Based Collaborative Filtering
- Adversarial Network Embedding
- Practical Attacks Against Graph-based Clustering
- Geometric deep learning on graphs and manifolds using mixture model CNNs
- Two samples test for discrete power-law distributions
Cited by in corpus (191)
- Graph Neural Networks: A Review of Methods and Applications
- Graph Contrastive Learning with Augmentations
- Pitfalls of Graph Neural Network Evaluation
- A Gentle Introduction to Deep Learning for Graphs
- Adversarial Attack and Defense on Graph Data: A Survey
- Graph-based Deep Learning for Communication Networks: A Survey
- threaTrace: Detecting and Tracing Host-based Threats in Node Level Through Provenance Graph Learning
- Stability Properties of Graph Neural Networks
- Failing Loudly: An Empirical Study of Methods for Detecting Dataset Shift
- Deep Learning on Graphs: A Survey
- Adversarial Attack on Graph Structured Data
- Graph Neural Networks: Taxonomy, Advances and Trends
- Fast Gradient Attack on Network Embedding
- Using Attribution to Decode Dataset Bias in Neural Network Models for Chemistry
- GNNGuard: Defending Graph Neural Networks against Adversarial Attacks
- Graph Convolutional Networks for Graphs Containing Missing Features
- Certifiable Robustness and Robust Training for Graph Convolutional Networks
- IoT-based Android Malware Detection Using Graph Neural Network With Adversarial Defense
- Graph Information Bottleneck
- Streaming Graph Neural Networks via Continual Learning
- Quantifying Privacy Leakage in Graph Embedding
- On the Generalizability of Neural Program Models with respect to Semantic-Preserving Program Transformations
- A Comprehensive Survey on Trustworthy Graph Neural Networks: Privacy, Robustness, Fairness, and Explainability
- TDGIA:Effective Injection Attacks on Graph Neural Networks
- Multilevel Graph Matching Networks for Deep Graph Similarity Learning
- Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective
- Differentiable sampling of molecular geometries with uncertainty-based adversarial attacks
- DeepRobust: A PyTorch Library for Adversarial Attacks and Defenses
- Adversarial Attack on Community Detection by Hiding Individuals
- Subgraph Federated Learning with Missing Neighbor Generation
- Revisiting Adversarially Learned Injection Attacks Against Recommender Systems
- Beta Embeddings for Multi-Hop Logical Reasoning in Knowledge Graphs
- You Only Propagate Once: Accelerating Adversarial Training via Maximal Principle
- Unnoticeable Backdoor Attacks on Graph Neural Networks
- Single Node Injection Attack against Graph Neural Networks
- Reliable Representations Make A Stronger Defender: Unsupervised Structure Refinement for Robust GNN
- When Does Self-Supervision Help Graph Convolutional Networks?
- DropMessage: Unifying Random Dropping for Graph Neural Networks
- Augmentation-Free Graph Contrastive Learning of Invariant-Discriminative Representations
- Attacking Graph Convolutional Networks via Rewiring
- Node-Level Membership Inference Attacks Against Graph Neural Networks
- Graph Structure Learning for Robust Graph Neural Networks
- Batch Virtual Adversarial Training for Graph Convolutional Networks
- Data Poisoning Attack against Unsupervised Node Embedding Methods
- Unsupervised Graph Poisoning Attack via Contrastive Loss Back-propagation
- Transferable Graph Backdoor Attack
- DECOR: Degree-Corrected Social Graph Refinement for Fake News Detection
- Indirect Adversarial Attacks via Poisoning Neighbors for Graph Convolutional Networks
- Robust Mid-Pass Filtering Graph Convolutional Networks
- Adversarial Attacks and Defenses on Graphs: A Review, A Tool and Empirical Studies
- Stealing Links from Graph Neural Networks
- Robust Counterfactual Explanations on Graph Neural Networks
- Adversarial Robustness for Code
- Tensor Graph Convolutional Networks for Multi-relational and Robust Learning
- Heterogeneous Network Representation Learning: A Unified Framework with Survey and Benchmark
- Graph Adversarial Training: Dynamically Regularizing Based on Graph Structure
- Towards Robust Graph Contrastive Learning
- Adversarial Attack Framework on Graph Embedding Models with Limited Knowledge
- How does Heterophily Impact the Robustness of Graph Neural Networks? Theoretical Connections and Practical Implications
- NetFense: Adversarial Defenses against Privacy Attacks on Neural Networks for Graph Data
- SLAPS: Self-Supervision Improves Structure Learning for Graph Neural Networks
- Graph Random Neural Network for Semi-Supervised Learning on Graphs
- Adversarial Attack on Hierarchical Graph Pooling Neural Networks
- GraphDefense: Towards Robust Graph Convolutional Networks
- GraphSAC: Detecting anomalies in large-scale graphs
- Adversarial Defense Framework for Graph Neural Network
- Can Adversarial Network Attack be Defended?
- AdvFlow: Inconspicuous Black-box Adversarial Attacks using Normalizing Flows
- Projective Ranking-based GNN Evasion Attacks
- SCARA: Scalable Graph Neural Networks with Feature-Oriented Optimization
- Don't Trigger Me! A Triggerless Backdoor Attack Against Deep Neural Networks
- Can Large Language Models Improve the Adversarial Robustness of Graph Neural Networks?
- SIGL: Securing Software Installations Through Deep Graph Learning
- Adversarial Inter-Group Link Injection Degrades the Fairness of Graph Neural Networks
- DefenseVGAE: Defending against Adversarial Attacks on Graph Data via a Variational Graph Autoencoder
- Node Injection for Class-specific Network Poisoning
- The Effects of Randomness on the Stability of Node Embeddings
- Structack: Structure-based Adversarial Attacks on Graph Neural Networks
- Simple and Efficient Partial Graph Adversarial Attack: A New Perspective
- Single-Node Attacks for Fooling Graph Neural Networks
- Data Poisoning Attacks on Federated Machine Learning
- Surrogate Representation Learning with Isometric Mapping for Gray-box Graph Adversarial Attacks
- Minimum Topology Attacks for Graph Neural Networks
- Node Similarity Preserving Graph Convolutional Networks
- Attacking Graph-based Classification via Manipulating the Graph Structure
- Time-aware Gradient Attack on Dynamic Network Link Prediction
- Backdoor Attacks to Graph Neural Networks
- Joint Air Quality and Weather Prediction Based on Multi-Adversarial Spatiotemporal Networks
- Node Injection Attack Based on Label Propagation Against Graph Neural Network
- Contrastive Graph Neural Network Explanation
- Adversarially Regularized Graph Attention Networks for Inductive Learning on Partially Labeled Graphs
- Resurrecting Label Propagation for Graphs with Heterophily and Label Noise
- Robust Node Classification on Graphs: Jointly from Bayesian Label Transition and Topology-based Label Propagation
- Learning Robust Representation through Graph Adversarial Contrastive Learning
- The Robustness of Graph k-shell Structure under Adversarial Attacks
- Adversarial Model Extraction on Graph Neural Networks
- DSRNA: Differentiable Search of Robust Neural Architectures
- Edge Dithering for Robust Adaptive Graph Convolutional Networks
- Adversarial Immunization for Certifiable Robustness on Graphs
- Evaluation of Generalizability of Neural Program Analyzers under Semantic-Preserving Transformations
- Self-Enhanced GNN: Improving Graph Neural Networks Using Model Outputs
- Efficient Robustness Certificates for Discrete Data: Sparsity-Aware Randomized Smoothing for Graphs, Images and More
- WebGraph: Capturing Advertising and Tracking Information Flows for Robust Blocking
- Do Fine-tuned Commonsense Language Models Really Generalize?
- Adversarial Attacks on Graph Classification via Bayesian Optimisation
- A Robust Hierarchical Graph Convolutional Network Model for Collaborative Filtering
- Identifying Classes Susceptible to Adversarial Attacks
- Certified Robustness of Community Detection against Adversarial Structural Perturbation via Randomized Smoothing
- Adversarial Attacks and Defenses: An Interpretation Perspective
- Geometric graphs from data to aid classification tasks with graph convolutional networks
- Debiased Graph Poisoning Attack via Contrastive Surrogate Objective
- Mask-GVAE: Blind Denoising Graphs via Partition
- Jointly Attacking Graph Neural Network and its Explanations
- Unsupervised Euclidean Distance Attack on Network Embedding
- Black-box Gradient Attack on Graph Neural Networks: Deeper Insights in Graph-based Attack and Defense
- Customizing Graph Neural Networks using Path Reweighting
- Learning Stochastic Graph Neural Networks with Constrained Variance
- Data Poisoning Attack against Knowledge Graph Embedding
- Influence Function based Data Poisoning Attacks to Top-N Recommender Systems
- GraphAttacker: A General Multi-Task GraphAttack Framework
- Probabilistic Entity Representation Model for Reasoning over Knowledge Graphs
- Attacking Black-box Recommendations via Copying Cross-domain User Profiles
- A Survey on Learning from Graphs with Heterophily: Recent Advances and Future Directions
- A Restricted Black-box Adversarial Framework Towards Attacking Graph Embedding Models
- Uncertainty-aware Attention Graph Neural Network for Defending Adversarial Attacks
- Adaptive Backdoor Attacks with Reasonable Constraints on Graph Neural Networks
- Preserve, Promote, or Attack? GNN Explanation via Topology Perturbation
- Generalizable Adversarial Attacks with Latent Variable Perturbation Modelling
- Adversarial Attack on Network Embeddings via Supervised Network Poisoning
- Nudge Attacks on Point-Cloud DNNs
- Adversarial Reinforcement Learning under Partial Observability in Autonomous Computer Network Defence
- Evaluating Robustness of Predictive Uncertainty Estimation: Are Dirichlet-based Models Reliable?
- Perturb and Combine to Identify Influential Spreaders in Real-World Networks
- Attacking Graph Neural Networks with Bit Flips: Weisfeiler and Lehman Go Indifferent
- Differentiable Language Model Adversarial Attacks on Categorical Sequence Classifiers
- Scalable Attack on Graph Data by Injecting Vicious Nodes
- Semantic-preserving Reinforcement Learning Attack Against Graph Neural Networks for Malware Detection
- QFCNN: Quantum Fourier Convolutional Neural Network
- Interpretable Stability Bounds for Spectral Graph Filters
- CommPOOL: An Interpretable Graph Pooling Framework for Hierarchical Graph Representation Learning
- Node Copying: A Random Graph Model for Effective Graph Sampling
- Robustness of Graph Neural Networks at Scale
- Certified Robustness of Graph Neural Networks against Adversarial Structural Perturbation
- Understanding Structural Vulnerability in Graph Convolutional Networks
- A Targeted Universal Attack on Graph Convolutional Network
- Adversarial Attack on Large Scale Graph
- Collective Robustness Certificates: Exploiting Interdependence in Graph Neural Networks
- Fast Inference of Removal-Based Node Influence
- Financial Crime & Fraud Detection Using Graph Computing: Application Considerations & Outlook
- Graph Convolutional Neural Networks Sensitivity under Probabilistic Error Model
- Virtual Adversarial Training on Graph Convolutional Networks in Node Classification
- Stacked Graph Filter
- Stability of Graph Convolutional Neural Networks to Stochastic Perturbations
- MG-GCN: Fast and Effective Learning with Mix-grained Aggregators for Training Large Graph Convolutional Networks
- On the Stability of Graph Convolutional Neural Networks under Edge Rewiring
- TEGDetector: A Phishing Detector that Knows Evolving Transaction Behaviors
- Robust Collective Classification against Structural Attacks
- Gradient-based Adversarial Attacks against Text Transformers
- Investigating Robustness and Interpretability of Link Prediction via Adversarial Modifications
- A Hard Label Black-box Adversarial Attack Against Graph Neural Networks
- Robust Spammer Detection by Nash Reinforcement Learning
- I-GCN: Robust Graph Convolutional Network via Influence Mechanism
- RIDA: A Robust Attack Framework on Incomplete Graphs
- 10 Security and Privacy Problems in Large Foundation Models
- Defending Network Intrusion Detection Systems Based on Graph Neural Networks Against Structural Adversarial Attacks
- Leveraging Vulnerabilities in Temporal Graph Neural Networks via Strategic High-Impact Assaults
- Auditing the Sensitivity of Graph-based Ranking with Visual Analytics
- Topological Effects on Attacks Against Vertex Classification
- DeepInsight: Interpretability Assisting Detection of Adversarial Samples on Graphs
- Adversarial Edit Attacks for Tree Data
- Towards an Efficient and General Framework of Robust Training for Graph Neural Networks
- Scalable Adversarial Attack on Graph Neural Networks with Alternating Direction Method of Multipliers
- AN-GCN: An Anonymous Graph Convolutional Network Defense Against Edge-Perturbing Attack
- Node Copying for Protection Against Graph Neural Network Topology Attacks
- Oriole: Thwarting Privacy against Trustworthy Deep Learning Models
- Non-Recursive Graph Convolutional Networks
- MGA: Momentum Gradient Attack on Network
- Network representation learning: A macro and micro view
- Spatio-Temporal Sparsification for General Robust Graph Convolution Networks
- Network Representation Learning: From Traditional Feature Learning to Deep Learning
- Adversarial Training Methods for Network Embedding
- Certifying Robustness of Graph Convolutional Networks for Node Perturbation with Polyhedra Abstract Interpretation
- Certified Robustness of Graph Classification against Topology Attack with Randomized Smoothing
- LiSA: Leveraging Link Recommender to Attack Graph Neural Networks via Subgraph Injection
- Understanding Adversarial Examples Through Deep Neural Network's Response Surface and Uncertainty Regions
- Optimal Edge Weight Perturbations to Attack Shortest Paths
- Short Text Classification via Term Graph
- Target Privacy Preserving for Social Networks
- Towards Self-Explainable Graph Neural Network
- CoG: a Two-View Co-training Framework for Defending Adversarial Attacks on Graph
- Adversarial Attacks on Knowledge Graph Embeddings via Instance Attribution Methods