<p>Graph Neural Networks (GNNs) have demonstrated exceptional performance across a wide range of graph-related applications. However, GNN models are susceptible to adversarial perturbations that can significantly degrade their performance. Existing studies on graph adversarial attacks predominantly rely on modifications to the graph structure, which disrupt critical topological features and make such attacks easier to detect, limiting their practical applicability. To address these limitations, this paper proposes a Reinforcement Learning-based Single Node Adversarial Attack (RLSNA), which enhances the stealth of graph attacks by perturbing the feature vector of a single non-target node rather than directly modifying the target node or the graph topology. RLSNA leverages the graph’s topology to identify the most effective non-target node for perturbation, thereby improving attack efficiency and effectiveness. Additionally, by employing reinforcement learning, RLSNA minimizes the required perturbation magnitude to achieve successful attacks on target nodes, reducing detectability and enhancing the robustness of graph adversarial attacks. Experimental results on multiple datasets demonstrate that RLSNA delivers strong attack performance across various GNN models while supporting both targeted and untargeted attack scenarios, underscoring its versatility and efficacy.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Single node adversarial attack via reinforcement learning on non-target node features for graph neural networks

  • Zhengli Zhai,
  • Chunyu Qu,
  • Penghui Li,
  • Shiya Xu,
  • Niuwangjie Niu

摘要

Graph Neural Networks (GNNs) have demonstrated exceptional performance across a wide range of graph-related applications. However, GNN models are susceptible to adversarial perturbations that can significantly degrade their performance. Existing studies on graph adversarial attacks predominantly rely on modifications to the graph structure, which disrupt critical topological features and make such attacks easier to detect, limiting their practical applicability. To address these limitations, this paper proposes a Reinforcement Learning-based Single Node Adversarial Attack (RLSNA), which enhances the stealth of graph attacks by perturbing the feature vector of a single non-target node rather than directly modifying the target node or the graph topology. RLSNA leverages the graph’s topology to identify the most effective non-target node for perturbation, thereby improving attack efficiency and effectiveness. Additionally, by employing reinforcement learning, RLSNA minimizes the required perturbation magnitude to achieve successful attacks on target nodes, reducing detectability and enhancing the robustness of graph adversarial attacks. Experimental results on multiple datasets demonstrate that RLSNA delivers strong attack performance across various GNN models while supporting both targeted and untargeted attack scenarios, underscoring its versatility and efficacy.