Indirect Adversarial Attacks via Poisoning Neighbors for Graph Convolutional Networks
arXiv:2002.08012 · doi:10.1109/BigData47090.2019.9006004
Abstract
Graph convolutional neural networks, which learn aggregations over neighbor nodes, have achieved great performance in node classification tasks. However, recent studies reported that such graph convolutional node classifier can be deceived by adversarial perturbations on graphs. Abusing graph convolutions, a node's classification result can be influenced by poisoning its neighbors. Given an attributed graph and a node classifier, how can we evaluate robustness against such indirect adversarial attacks? Can we generate strong adversarial perturbations which are effective on not only one-hop neighbors, but more far from the target? In this paper, we demonstrate that the node classifier can be deceived with high-confidence by poisoning just a single node even two-hops or more far from the target. Towards achieving the attack, we propose a new approach which searches smaller perturbations on just a single node far from the target. In our experiments, our proposed method shows 99% attack success rate within two-hops from the target in two datasets. We also demonstrate that m-layer graph convolutional neural networks have chance to be deceived by our indirect attack within m-hop neighbors. The proposed attack can be used as a benchmark in future defense attempts to develop graph convolutional neural networks with having adversary robustness.
Accepted in IEEE BigData 2019
References in corpus (10)
- Explaining and Harnessing Adversarial Examples
- Graph Convolutional Neural Networks for Web-Scale Recommender Systems
- Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples
- Adversarial Attacks on Neural Networks for Graph Data
- Provable defenses against adversarial examples via the convex outer adversarial polytope
- Adversarial Attacks on Graph Neural Networks via Meta Learning
- Neural Relational Inference for Interacting Systems
- Robust Audio Adversarial Example for a Physical Attack
- Lipschitz-Margin Training: Scalable Certification of Perturbation Invariance for Deep Neural Networks
- Indirect Adversarial Attacks via Poisoning Neighbors for Graph Convolutional Networks
Cited by in corpus (7)
- Adversarial Attack and Defense on Graph Data: A Survey
- Indirect Adversarial Attacks via Poisoning Neighbors for Graph Convolutional Networks
- FaceLeaks: Inference Attacks against Transfer Learning Models via Black-box Queries
- GraphAttacker: A General Multi-Task GraphAttack Framework
- A Targeted Universal Attack on Graph Convolutional Network
- A Hard Label Black-box Adversarial Attack Against Graph Neural Networks
- Certifying Robustness of Graph Convolutional Networks for Node Perturbation with Polyhedra Abstract Interpretation