<p>As Graph Neural Networks (GNNs) are increasingly vital, they are becoming primary targets for poisoning attacks. These attacks inject perturbations into the datasets used for retraining, resulting in a decline in model performance. To create robust GNN models, designing strong poisoning attack models as foundational benchmarks and guiding references is crucial. Existing attack models assume that attackers have access to the complete graph structure and attribute information. However, in many scenarios, only partial or incomplete graph data is available due to the data source’s privacy policies. Given this, we propose a practical attack method for incomplete graphs, named Robust Incomplete Deep Attack Framework (RIDA). It is the first approach for robust gray-box poisoning attacks on incomplete graphs. To ensure a reliable surrogate model for attacks, we incorporate a Depth-plus GNN module for long-range information propagation and a Local-global Aggregation module to refine feature aggregation. Additionally, we optimize and execute poisoning attacks on incomplete graphs through the Holistic Adversarial Attack module. Extensive evaluations against 9 state-of-the-art baselines on 3 real-world datasets demonstrate that RIDA outperforms existing methods in attacking GNNs on incomplete graphs.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

RIDA: a robust attack framework on incomplete graphs

  • Jianke Yu,
  • Hanchen Wang,
  • Chen Chen,
  • Xiaoyang Wang,
  • Lu Qin,
  • Wenjie Zhang,
  • Ying Zhang,
  • Xijuan Liu

摘要

As Graph Neural Networks (GNNs) are increasingly vital, they are becoming primary targets for poisoning attacks. These attacks inject perturbations into the datasets used for retraining, resulting in a decline in model performance. To create robust GNN models, designing strong poisoning attack models as foundational benchmarks and guiding references is crucial. Existing attack models assume that attackers have access to the complete graph structure and attribute information. However, in many scenarios, only partial or incomplete graph data is available due to the data source’s privacy policies. Given this, we propose a practical attack method for incomplete graphs, named Robust Incomplete Deep Attack Framework (RIDA). It is the first approach for robust gray-box poisoning attacks on incomplete graphs. To ensure a reliable surrogate model for attacks, we incorporate a Depth-plus GNN module for long-range information propagation and a Local-global Aggregation module to refine feature aggregation. Additionally, we optimize and execute poisoning attacks on incomplete graphs through the Holistic Adversarial Attack module. Extensive evaluations against 9 state-of-the-art baselines on 3 real-world datasets demonstrate that RIDA outperforms existing methods in attacking GNNs on incomplete graphs.