Are Defenses for Graph Neural Networks Robust?

被引:0
|
作者
Mujkanovic, Felix [1 ,2 ]
Geisler, Simon [1 ,2 ]
Guennemann, Stephan [1 ,2 ]
Bojchevski, Aleksandar [3 ]
机构
[1] Tech Univ Munich, Dept Comp Sci, Munich, Germany
[2] Tech Univ Munich, Munich Data Sci Inst, Munich, Germany
[3] CISPA Helmholtz Ctr Informat Secur, Saarbrucken, Germany
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
A cursory reading of the literature suggests that we have made a lot of progress in designing effective adversarial defenses for Graph Neural Networks (GNNs). Yet, the standard methodology has a serious flaw - virtually all of the defenses are evaluated against non-adaptive attacks leading to overly optimistic robustness estimates. We perform a thorough robustness analysis of 7 of the most popular defenses spanning the entire spectrum of strategies, i.e., aimed at improving the graph, the architecture, or the training. The results are sobering - most defenses show no or only marginal improvement compared to an undefended baseline. We advocate using custom adaptive attacks as a gold standard and we outline the lessons we learned from successfully designing such attacks. Moreover, our diverse collection of perturbed graphs forms a (black-box) unit test offering a first glance at a model's robustness.(1)
引用
收藏
页数:15
相关论文
共 50 条
  • [41] Graphs, Convolutions, and Neural Networks: From Graph Filters to Graph Neural Networks
    Gama, Fernando
    Isufi, Elvin
    Leus, Geert
    Ribeiro, Alejandro
    IEEE SIGNAL PROCESSING MAGAZINE, 2020, 37 (06) : 128 - 138
  • [42] Robust prediction of force chains in jammed solids using graph neural networks
    Mandal, Rituparno
    Casert, Corneel
    Sollich, Peter
    NATURE COMMUNICATIONS, 2022, 13 (01)
  • [43] Robust Training of Deep Neural Networks with Noisy Labels by Graph Label Propagation
    Nomura, Yuichiro
    Kurita, Takio
    FRONTIERS OF COMPUTER VISION, IW-FCV 2021, 2021, 1405 : 281 - 293
  • [44] Robust prediction of force chains in jammed solids using graph neural networks
    Rituparno Mandal
    Corneel Casert
    Peter Sollich
    Nature Communications, 13
  • [45] Neural Pooling for Graph Neural Networks
    Harsha, Sai Sree
    Mishra, Deepak
    PATTERN RECOGNITION AND MACHINE INTELLIGENCE, PREMI 2021, 2024, 13102 : 171 - 180
  • [46] Graphon Neural Networks and the Transferability of Graph Neural Networks
    Ruiz, Luana
    Chamon, Luiz F. O.
    Ribeiro, Alejandro
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33
  • [47] Are Graph Neural Network Explainers Robust to Graph Noises?
    Li, Yiqiao
    Verma, Sunny
    Yang, Shuiqiao
    Zhou, Jianlong
    Chen, Fang
    AI 2022: ADVANCES IN ARTIFICIAL INTELLIGENCE, 2022, 13728 : 161 - 174
  • [48] Robust Graph Neural Network based on Graph Denoising
    Tenorio, Victor M.
    Rey, Samuel
    Marques, Antonio G.
    FIFTY-SEVENTH ASILOMAR CONFERENCE ON SIGNALS, SYSTEMS & COMPUTERS, IEEECONF, 2023, : 578 - 582
  • [49] Graph Neural Tangent Kernel: Fusing Graph Neural Networks with Graph Kernels
    Du, Simon S.
    Hou, Kangcheng
    Poczos, Barnabas
    Salakhutdinov, Ruslan
    Wang, Ruosong
    Xu, Keyulu
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 32 (NIPS 2019), 2019, 32
  • [50] Rethinking Graph Regularization for Graph Neural Networks
    Yang, Han
    Ma, Kaili
    Cheng, James
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 4573 - 4581