Data Poisoning Attack against Unsupervised Node Embedding Methods
arXiv:1810.12881
Abstract
Unsupervised node embedding methods (e.g., DeepWalk, LINE, and node2vec) have attracted growing interests given their simplicity and effectiveness. However, although these methods have been proved effective in a variety of applications, none of the existing work has analyzed the robustness of them. This could be very risky if these methods are attacked by an adversarial party. In this paper, we take the task of link prediction as an example, which is one of the most fundamental problems for graph analysis, and introduce a data positioning attack to node embedding methods. We give a complete characterization of attacker's utilities and present efficient solutions to adversarial attacks for two popular node embedding methods: DeepWalk and LINE. We evaluate our proposed attack model on multiple real-world graphs. Experimental results show that our proposed model can significantly affect the results of link prediction by slightly changing the graph structures (e.g., adding or removing a few edges). We also show that our proposed model is very general and can be transferable across different embedding methods. Finally, we conduct a case study on a coauthor network to better understand our attack method.
References in corpus (8)
- Distributed Representations of Words and Phrases and their Compositionality
- Adversarial Attacks on Neural Networks for Graph Data
- Variational Graph Auto-Encoders
- Spatially Transformed Adversarial Examples
- Generating Adversarial Examples with Adversarial Networks
- Houdini: Fooling Deep Structured Prediction Models
- Adversarial Attack on Graph Structured Data
- Characterizing Adversarial Examples Based on Spatial Consistency Information for Semantic Segmentation
Cited by in corpus (13)
- Adversarial Attack and Defense on Graph Data: A Survey
- Adversarial Objects Against LiDAR-Based Autonomous Driving Systems
- A Survey of Adversarial Learning on Graphs
- Towards Resilient Artificial Intelligence: Survey and Research Issues
- Adversarial Attack on Hierarchical Graph Pooling Neural Networks
- Regional Homogeneity: Towards Learning Transferable Universal Adversarial Perturbations Against Defenses
- Time-aware Gradient Attack on Dynamic Network Link Prediction
- Attacking Graph-based Classification via Manipulating the Graph Structure
- Data Poisoning Attack against Knowledge Graph Embedding
- Unsupervised Euclidean Distance Attack on Network Embedding
- A Targeted Universal Attack on Graph Convolutional Network
- Auditing the Sensitivity of Graph-based Ranking with Visual Analytics
- How Does Counterfactually Augmented Data Impact Models for Social Computing Constructs?