Attacking Graph Convolutional Networks via Rewiring
arXiv:1906.03750
Abstract
Graph Neural Networks (GNNs) have boosted the performance of many graph related tasks such as node classification and graph classification. Recent researches show that graph neural networks are vulnerable to adversarial attacks, which deliberately add carefully created unnoticeable perturbation to the graph structure. The perturbation is usually created by adding/deleting a few edges, which might be noticeable even when the number of edges modified is small. In this paper, we propose a graph rewiring operation which affects the graph in a less noticeable way compared to adding/deleting edges. We then use reinforcement learning to learn the attack strategy based on the proposed rewiring operation. Experiments on real world graphs demonstrate the effectiveness of the proposed framework. To understand the proposed framework, we further analyze how its generated perturbation to the graph structure affects the output of the target model.
References in corpus (11)
- Semi-Supervised Classification with Graph Convolutional Networks
- The Emerging Field of Signal Processing on Graphs: Extending High-Dimensional Data Analysis to Networks and Other Irregular Domains
- Inductive Representation Learning on Large Graphs
- Spectral Networks and Locally Connected Networks on Graphs
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Adversarial Attacks on Neural Networks for Graph Data
- Hierarchical Graph Representation Learning with Differentiable Pooling
- Adversarial Attacks on Graph Neural Networks via Meta Learning
- Black-box Adversarial Attacks with Limited Queries and Information
- Query-Efficient Hard-label Black-box Attack:An Optimization-based Approach
- Attack Graph Convolutional Networks by Adding Fake Nodes
Cited by in corpus (18)
- Adversarial Attack and Defense on Graph Data: A Survey
- Transferring Robustness for Graph Neural Network Against Poisoning Attacks
- A Survey of Adversarial Learning on Graphs
- Graph Structure Learning for Robust Graph Neural Networks
- Adversarial Attacks and Defenses on Graphs: A Review, A Tool and Empirical Studies
- Robust Mid-Pass Filtering Graph Convolutional Networks
- Adversarial Attack on Hierarchical Graph Pooling Neural Networks
- Adversarial Inter-Group Link Injection Degrades the Fairness of Graph Neural Networks
- Structack: Structure-based Adversarial Attacks on Graph Neural Networks
- Surrogate Representation Learning with Isometric Mapping for Gray-box Graph Adversarial Attacks
- Learning to Deceive Knowledge Graph Augmented Models via Targeted Perturbation
- Information Obfuscation of Graph Neural Networks
- Adversarial Attacks on Graph Classification via Bayesian Optimisation
- Jointly Attacking Graph Neural Network and its Explanations
- Black-box Gradient Attack on Graph Neural Networks: Deeper Insights in Graph-based Attack and Defense
- A Hard Label Black-box Adversarial Attack Against Graph Neural Networks
- On the Stability of Graph Convolutional Neural Networks under Edge Rewiring
- DeepInsight: Interpretability Assisting Detection of Adversarial Samples on Graphs