Adversarial Attacks on Graph Neural Networks via Meta Learning
arXiv:1902.08412
Abstract
Deep learning models for graphs have advanced the state of the art on many tasks. Despite their recent success, little is known about their robustness. We investigate training time attacks on graph neural networks for node classification that perturb the discrete graph structure. Our core principle is to use meta-gradients to solve the bilevel problem underlying training-time attacks, essentially treating the graph as a hyperparameter to optimize. Our experiments show that small graph perturbations consistently lead to a strong decrease in performance for graph convolutional networks, and even transfer to unsupervised embeddings. Remarkably, the perturbations created by our algorithm can misguide the graph neural networks such that they perform worse than a simple baseline that ignores all relational information. Our attacks do not assume any knowledge about or access to the target classifiers.
ICLR submission
Cited by in corpus (90)
- Adversarial Attack and Defense on Graph Data: A Survey
- Transferring Robustness for Graph Neural Network Against Poisoning Attacks
- Deep Learning on Graphs: A Survey
- Graph Neural Networks: Taxonomy, Advances and Trends
- GNNGuard: Defending Graph Neural Networks against Adversarial Attacks
- Trustworthy Graph Neural Networks: Aspects, Methods and Trends
- A Comprehensive Survey on Trustworthy Graph Neural Networks: Privacy, Robustness, Fairness, and Explainability
- Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective
- DeepRobust: A PyTorch Library for Adversarial Attacks and Defenses
- Subgraph Federated Learning with Missing Neighbor Generation
- Unnoticeable Backdoor Attacks on Graph Neural Networks
- Single Node Injection Attack against Graph Neural Networks
- Attacking Graph Convolutional Networks via Rewiring
- A Survey of Adversarial Learning on Graphs
- Node-Level Membership Inference Attacks Against Graph Neural Networks
- Graph Structure Learning for Robust Graph Neural Networks
- Query-efficient Meta Attack to Deep Neural Networks
- Indirect Adversarial Attacks via Poisoning Neighbors for Graph Convolutional Networks
- Robust Mid-Pass Filtering Graph Convolutional Networks
- Adversarial Attacks and Defenses on Graphs: A Review, A Tool and Empirical Studies
- Stealing Links from Graph Neural Networks
- Robust Counterfactual Explanations on Graph Neural Networks
- Adversarial Robustness for Code
- Towards Robust Graph Contrastive Learning
- Adversarial Attack Framework on Graph Embedding Models with Limited Knowledge
- How does Heterophily Impact the Robustness of Graph Neural Networks? Theoretical Connections and Practical Implications
- Task-Robust Model-Agnostic Meta-Learning
- NetFense: Adversarial Defenses against Privacy Attacks on Neural Networks for Graph Data
- Adversarial Attack on Hierarchical Graph Pooling Neural Networks
- GraphDefense: Towards Robust Graph Convolutional Networks
- Automated Self-Supervised Learning for Graphs
- Towards a Unified Framework for Fair and Stable Graph Representation Learning
- Can Large Language Models Improve the Adversarial Robustness of Graph Neural Networks?
- Adversarial Inter-Group Link Injection Degrades the Fairness of Graph Neural Networks
- Node Injection for Class-specific Network Poisoning
- Structack: Structure-based Adversarial Attacks on Graph Neural Networks
- A Meta-Learning Approach for Graph Representation Learning in Multi-Task Settings
- The Effects of Randomness on the Stability of Node Embeddings
- Single-Node Attacks for Fooling Graph Neural Networks
- Simple and Efficient Partial Graph Adversarial Attack: A New Perspective
- Towards More Practical Adversarial Attacks on Graph Neural Networks
- Surrogate Representation Learning with Isometric Mapping for Gray-box Graph Adversarial Attacks
- Graph Neural Networks Inspired by Classical Iterative Algorithms
- Node Similarity Preserving Graph Convolutional Networks
- Attacking Graph-based Classification via Manipulating the Graph Structure
- Backdoor Attacks to Graph Neural Networks
- Node Injection Attack Based on Label Propagation Against Graph Neural Network
- Contrastive Graph Neural Network Explanation
- Robust Node Classification on Graphs: Jointly from Bayesian Label Transition and Topology-based Label Propagation
- Learning Robust Representation through Graph Adversarial Contrastive Learning
- Efficient Robustness Certificates for Discrete Data: Sparsity-Aware Randomized Smoothing for Graphs, Images and More
- Private Graph Extraction via Feature Explanations
- Certified Robustness of Community Detection against Adversarial Structural Perturbation via Randomized Smoothing
- Recognizing Predictive Substructures with Subgraph Information Bottleneck
- Black-box Gradient Attack on Graph Neural Networks: Deeper Insights in Graph-based Attack and Defense
- Adversarial Diffusion Attacks on Graph-based Traffic Prediction Models
- Jointly Attacking Graph Neural Network and its Explanations
- GraphAttacker: A General Multi-Task GraphAttack Framework
- A Restricted Black-box Adversarial Framework Towards Attacking Graph Embedding Models
- Uncertainty-aware Attention Graph Neural Network for Defending Adversarial Attacks
- Adversarial Attack on Network Embeddings via Supervised Network Poisoning
- UFO-BLO: Unbiased First-Order Bilevel Optimization
- Certified Robustness of Graph Neural Networks against Adversarial Structural Perturbation
- Adversarial Attack and Defense of Structured Prediction Models
- Understanding Structural Vulnerability in Graph Convolutional Networks
- Bilevel Optimization for Machine Learning: Algorithm Design and Convergence Analysis
- Adversarial Attack on Large Scale Graph
- Virtual Adversarial Training on Graph Convolutional Networks in Node Classification
- Robust Collective Classification against Structural Attacks
- Stacked Graph Filter
- I-GCN: Robust Graph Convolutional Network via Influence Mechanism
- Towards an Efficient and General Framework of Robust Training for Graph Neural Networks
- Improved Robustness and Safety for Pre-Adaptation of Meta Reinforcement Learning with Prior Regularization
- Node Feature Kernels Increase Graph Convolutional Network Robustness
- Value-Function-based Sequential Minimization for Bi-level Optimization
- Resilient UAV Swarm Communications with Graph Convolutional Neural Network
- DeepInsight: Interpretability Assisting Detection of Adversarial Samples on Graphs
- Topological Effects on Attacks Against Vertex Classification
- CoG: a Two-View Co-training Framework for Defending Adversarial Attacks on Graph
- Towards Self-Explainable Graph Neural Network
- Do Deep Minds Think Alike? Selective Adversarial Attacks for Fine-Grained Manipulation of Multiple Deep Neural Networks
- Spatio-Temporal Sparsification for General Robust Graph Convolution Networks
- AN-GCN: An Anonymous Graph Convolutional Network Defense Against Edge-Perturbing Attack
- Node Copying for Protection Against Graph Neural Network Topology Attacks
- MetAL: Active Semi-Supervised Learning on Graphs via Meta Learning
- Debiasing a First-order Heuristic for Approximate Bi-level Optimization
- Certified Robustness of Graph Classification against Topology Attack with Randomized Smoothing
- Implicit vs Unfolded Graph Neural Networks
- Scalable Adversarial Attack on Graph Neural Networks with Alternating Direction Method of Multipliers
- Non-Recursive Graph Convolutional Networks