GNNGuard: Defending Graph Neural Networks against Adversarial Attacks
arXiv:2006.08149
Abstract
Deep learning methods for graphs achieve remarkable performance across a variety of domains. However, recent findings indicate that small, unnoticeable perturbations of graph structure can catastrophically reduce performance of even the strongest and most popular Graph Neural Networks (GNNs). Here, we develop GNNGuard, a general algorithm to defend against a variety of training-time attacks that perturb the discrete graph structure. GNNGuard can be straight-forwardly incorporated into any GNN. Its core principle is to detect and quantify the relationship between the graph structure and node features, if one exists, and then exploit that relationship to mitigate negative effects of the attack.GNNGuard learns how to best assign higher weights to edges connecting similar nodes while pruning edges between unrelated nodes. The revised edges allow for robust propagation of neural messages in the underlying GNN. GNNGuard introduces two novel components, the neighbor importance estimation, and the layer-wise graph memory, and we show empirically that both components are necessary for a successful defense. Across five GNNs, three defense methods, and five datasets,including a challenging human disease graph, experiments show that GNNGuard outperforms existing defense approaches by 15.3% on average. Remarkably, GNNGuard can effectively restore state-of-the-art performance of GNNs in the face of various adversarial attacks, including targeted and non-targeted attacks, and can defend against attacks on heterophily graphs.
Accepted by NeurIPS 2020. More info about GNNGuard: https://zitniklab.hms.harvard.edu/projects/GNNGuard/
References in corpus (8)
- Adversarial Examples on Graph Data: Deep Insights into Attack and Defense
- DeepRobust: A PyTorch Library for Adversarial Attacks and Defenses
- Certifiable Robustness to Graph Perturbations
- Adversarial Attacks and Defenses on Graphs: A Review, A Tool and Empirical Studies
- Policy Teaching via Environment Poisoning: Training-time Adversarial Attacks against Reinforcement Learning
- A Unified Framework for Data Poisoning Attack to Graph-based Semi-supervised Learning
- Adversarial Defense Framework for Graph Neural Network
- Label Propagation on K-partite Graphs with Heterophily
Cited by in corpus (19)
- A Comprehensive Survey on Deep Graph Representation Learning
- A Comprehensive Survey on Trustworthy Graph Neural Networks: Privacy, Robustness, Fairness, and Explainability
- Unnoticeable Backdoor Attacks on Graph Neural Networks
- SE-GSL: A General and Effective Graph Structure Learning Framework through Structural Entropy Optimization
- Robust Mid-Pass Filtering Graph Convolutional Networks
- Adversarial Attack Framework on Graph Embedding Models with Limited Knowledge
- Learning to Denoise Biomedical Knowledge Graph for Robust Molecular Interaction Prediction
- How does Heterophily Impact the Robustness of Graph Neural Networks? Theoretical Connections and Practical Implications
- Sequential Recommendation with Graph Neural Networks
- Can Large Language Models Improve the Adversarial Robustness of Graph Neural Networks?
- Adversarial Inter-Group Link Injection Degrades the Fairness of Graph Neural Networks
- Node Injection for Class-specific Network Poisoning
- Single-Node Attacks for Fooling Graph Neural Networks
- Collaborate to Adapt: Source-Free Graph Domain Adaptation via Bi-directional Adaptation
- Simple and Efficient Partial Graph Adversarial Attack: A New Perspective
- Residual Network and Embedding Usage: New Tricks of Node Classification with Graph Convolutional Networks
- Node Injection Attack Based on Label Propagation Against Graph Neural Network
- Robust Node Classification on Graphs: Jointly from Bayesian Label Transition and Topology-based Label Propagation
- GraphAttacker: A General Multi-Task GraphAttack Framework