Are Defenses for Graph Neural Networks Robust?

被引:0
|
作者
Mujkanovic, Felix [1 ,2 ]
Geisler, Simon [1 ,2 ]
Guennemann, Stephan [1 ,2 ]
Bojchevski, Aleksandar [3 ]
机构
[1] Tech Univ Munich, Dept Comp Sci, Munich, Germany
[2] Tech Univ Munich, Munich Data Sci Inst, Munich, Germany
[3] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
A cursory reading of the literature suggests that we have made a lot of progress in designing effective adversarial defenses for Graph Neural Networks (GNNs). Yet, the standard methodology has a serious flaw - virtually all of the defenses are evaluated against non-adaptive attacks leading to overly optimistic robustness estimates. We perform a thorough robustness analysis of 7 of the most popular defenses spanning the entire spectrum of strategies, i.e., aimed at improving the graph, the architecture, or the training. The results are sobering - most defenses show no or only marginal improvement compared to an undefended baseline. We advocate using custom adaptive attacks as a gold standard and we outline the lessons we learned from successfully designing such attacks. Moreover, our diverse collection of perturbed graphs forms a (black-box) unit test offering a first glance at a model's robustness.(1)
引用
收藏
页数:15
相关论文
共 50 条
  • [31] Towards Robust Graph Neural Networks for Noisy Graphs with Sparse Labels
    Dai, Enyan
    Jin, Wei
    Liu, Hui
    Wang, Suhang
    WSDM'22: PROCEEDINGS OF THE FIFTEENTH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, 2022, : 181 - 191
  • [32] Graph neural networks
    Corso G.
    Stark H.
    Jegelka S.
    Jaakkola T.
    Barzilay R.
    Nature Reviews Methods Primers, 4 (1):
  • [33] Graph neural networks
    不详
    NATURE REVIEWS METHODS PRIMERS, 2024, 4 (01):
  • [34] Graph Neural Networks for Graph Drawing
    Tiezzi, Matteo
    Ciravegna, Gabriele
    Gori, Marco
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, 35 (04) : 4668 - 4681
  • [35] Graph Rewriting for Graph Neural Networks
    Machowczyk, Adam
    Heckel, Reiko
    GRAPH TRANSFORMATION, ICGT 2023, 2023, 13961 : 292 - 301
  • [36] Graph Mining with Graph Neural Networks
    Jin, Wei
    WSDM '21: PROCEEDINGS OF THE 14TH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, 2021, : 1119 - 1120
  • [37] Graph Clustering with Graph Neural Networks
    Tsitsulin, Anton
    Palowitch, John
    Perozzi, Bryan
    Mueller, Emmanuel
    JOURNAL OF MACHINE LEARNING RESEARCH, 2023, 24
  • [38] A Survey of Attacks and Defenses for Deep Neural Networks
    Machooka, Daniel
    Yuan, Xiaohong
    Esterline, Albert
    2023 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE, CSR, 2023, : 254 - 261
  • [39] Trojan Attacks and Defenses on Deep Neural Networks
    Liu, Yingqi
    ProQuest Dissertations and Theses Global, 2022,
  • [40] A Survey of Backdoor Attacks and Defenses on Neural Networks
    Wang, Xu-Tong
    Yin, Jie
    Liu, Chao-Ge
    Xu, Chen-Chen
    Huang, Hao
    Wang, Zhi
    Zhang, Fang-Jiao
    Jisuanji Xuebao/Chinese Journal of Computers, 2024, 47 (08): : 1713 - 1743