Are Graph Neural Network Explainers Robust to Graph Noises?

被引:4
作者
Li, Yiqiao [1 ]
Verma, Sunny [1 ]
Yang, Shuiqiao [2 ]
Zhou, Jianlong [1 ]
Chen, Fang [1 ]
机构
[1] Univ Technol Sydney, Sydney, NSW, Australia
[2] Univ New South Wales, Sydney, NSW, Australia
来源
AI 2022: ADVANCES IN ARTIFICIAL INTELLIGENCE | 2022年 / 13728卷
关键词
Graph neural networks; GNN explainers; Adversarial attacks; Robustness;
D O I
10.1007/978-3-031-22695-3_12
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the rapid deployment of graph neural networks (GNNs) based techniques in a wide range of applications such as link prediction, community detection, and node classification, the explainability of GNNs become an indispensable component for predictive and trustworthy decision making. To achieve this goal, some recent works focus on designing explainable GNN models such as GNNExplainer, PGExplainer, and Gem. These GNN explainers have shown remarkable performance in explaining the predictive results from GNNs. Despite their success, the robustness of these explainers is less explored in terms of vulnerabilities of GNN explainers. Graph perturbations such as adversarial attacks can lead to inaccurate explanations and consequently cause catastrophes. Thus, in this paper, we take the first step and strive to explore the robustness of GNN explainers. To be specific, we first define two adversarial attack scenarios-aggressive adversary and conservative adversary to contaminate graph structures. We then investigate the impacts of the poisoned graphs on the explainability of three prevalent GNN explainers with three standard evaluation metrics: Fidelity(+), Fidelity(-), and Sparsity. We conduct experiments on synthetic and real-world datasets and focus on two popular graph mining tasks: node classification and graph classification. Our empirical results suggest that GNN explainers are generally not robust to the adversarial attacks caused by graph structural noises.
引用
收藏
页码:161 / 174
页数:14
相关论文
共 34 条
[1]  
Dai HJ, 2018, PR MACH LEARN RES, V80
[2]   STRUCTURE ACTIVITY RELATIONSHIP OF MUTAGENIC AROMATIC AND HETEROAROMATIC NITRO-COMPOUNDS - CORRELATION WITH MOLECULAR-ORBITAL ENERGIES AND HYDROPHOBICITY [J].
DEBNATH, AK ;
DECOMPADRE, RLL ;
DEBNATH, G ;
SHUSTERMAN, AJ ;
HANSCH, C .
JOURNAL OF MEDICINAL CHEMISTRY, 1991, 34 (02) :786-797
[3]  
Dehua Chen, 2021, 2021 IEEE International Conference on Bioinformatics and Biomedicine (BIBM), P3341, DOI 10.1109/BIBM52615.2021.9669648
[4]  
Doshi-Velez F, 2017, Arxiv, DOI [arXiv:1702.08608, 10.48550/arXiv.1702.08608, DOI 10.48550/ARXIV.1702.08608]
[5]  
Duan W, 2022, AAAI CONF ARTIF INTE, P6550
[6]  
Fout A, 2017, ADV NEUR IN, V30
[7]  
Fox James, 2019, arXiv, DOI [DOI 10.48550/ARXIV.1912.10206, 10.48550/ARXIV.1912.10206]
[8]   Benchmarking graph neural networks for materials chemistry [J].
Fung, Victor ;
Zhang, Jiaxin ;
Juarez, Eric ;
Sumpter, Bobby G. .
NPJ COMPUTATIONAL MATERIALS, 2021, 7 (01)
[9]  
Ghorbani A, 2019, AAAI CONF ARTIF INTE, P3681
[10]  
Hendrycks D, 2019, ICLR