Are Defenses for Graph Neural Networks Robust?

被引:0
|
作者
Mujkanovic, Felix [1 ,2 ]
Geisler, Simon [1 ,2 ]
Guennemann, Stephan [1 ,2 ]
Bojchevski, Aleksandar [3 ]
机构
[1] Tech Univ Munich, Dept Comp Sci, Munich, Germany
[2] Tech Univ Munich, Munich Data Sci Inst, Munich, Germany
[3] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
A cursory reading of the literature suggests that we have made a lot of progress in designing effective adversarial defenses for Graph Neural Networks (GNNs). Yet, the standard methodology has a serious flaw - virtually all of the defenses are evaluated against non-adaptive attacks leading to overly optimistic robustness estimates. We perform a thorough robustness analysis of 7 of the most popular defenses spanning the entire spectrum of strategies, i.e., aimed at improving the graph, the architecture, or the training. The results are sobering - most defenses show no or only marginal improvement compared to an undefended baseline. We advocate using custom adaptive attacks as a gold standard and we outline the lessons we learned from successfully designing such attacks. Moreover, our diverse collection of perturbed graphs forms a (black-box) unit test offering a first glance at a model's robustness.(1)
引用
收藏
页数:15
相关论文
共 50 条
  • [1] A Survey on Privacy Attacks and Defenses in Graph Neural Networks
    Luo, Lanhua
    Ren, Wang
    Huang, Huasheng
    Wang, Fengling
    INFORMATION TECHNOLOGY AND CONTROL, 2024, 53 (04):
  • [2] Robust Denoising in Graph Neural Networks
    Zhang, Siying
    Han, Andi
    Gao, Junbin
    2022 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), 2022, : 1088 - 1095
  • [3] Graph Structure Learning for Robust Graph Neural Networks
    Jin, Wei
    Ma, Yao
    Liu, Xiaorui
    Tang, Xianfeng
    Wang, Suhang
    Tang, Jiliang
    KDD '20: PROCEEDINGS OF THE 26TH ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2020, : 66 - 74
  • [4] Robust Counterfactual Explanations on Graph Neural Networks
    Bajaj, Mohit
    Chu, Lingyang
    Xue, Zi Yu
    Pei, Jian
    Wang, Lanjun
    Lam, Peter Cho-Ho
    Zhang, Yong
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [5] Adversarially Robust Neural Architecture Search for Graph Neural Networks
    Xie, Beini
    Chang, Heng
    Zhang, Ziwei
    Wang, Xin
    Wang, Daxin
    Zhang, Zhiqiang
    Ying, Rex
    Zhu, Wenwu
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 8143 - 8152
  • [6] Learning graph in graph convolutional neural networks for robust seizure prediction
    Lian, Qi
    Qi, Yu
    Pan, Gang
    Wang, Yueming
    JOURNAL OF NEURAL ENGINEERING, 2020, 17 (03)
  • [7] Graph alternate learning for robust graph neural networks in node classification
    Zhang, Baoliang
    Guo, Xiaoxin
    Tu, Zhenchuan
    Zhang, Jia
    NEURAL COMPUTING & APPLICATIONS, 2022, 34 (11): : 8723 - 8735
  • [8] Graph alternate learning for robust graph neural networks in node classification
    Baoliang Zhang
    Xiaoxin Guo
    Zhenchuan Tu
    Jia Zhang
    Neural Computing and Applications, 2022, 34 : 8723 - 8735
  • [9] NetFense: Adversarial Defenses Against Privacy Attacks on Neural Networks for Graph Data
    Hsieh, I-Chung
    Li, Cheng-Te
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2023, 35 (01) : 796 - 809
  • [10] Robust Spatial Filtering With Graph Convolutional Neural Networks
    Such, Felipe Petroski
    Sah, Shagan
    Dominguez, Miguel Alexander
    Pillai, Suhas
    Zhang, Chao
    Michael, Andrew
    Cahill, Nathan D.
    Ptucha, Raymond
    IEEE JOURNAL OF SELECTED TOPICS IN SIGNAL PROCESSING, 2017, 11 (06) : 884 - 896