Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective

About

Graph neural networks (GNNs) which apply the deep neural networks to graph data have achieved significant performance for the task of semi-supervised node classification. However, only few work has addressed the adversarial robustness of GNNs. In this paper, we first present a novel gradient-based attack method that facilitates the difficulty of tackling discrete graph data. When comparing to current adversarial attacks on GNNs, the results show that by only perturbing a small number of edge perturbations, including addition and deletion, our optimization-based attack can lead to a noticeable decrease in classification performance. Moreover, leveraging our gradient-based attack, we propose the first optimization-based adversarial training for GNNs. Our method yields higher robustness against both different gradient based and greedy attack methods without sacrificing classification accuracy on original graph.

Kaidi Xu, Hongge Chen, Sijia Liu, Pin-Yu Chen, Tsui-Wei Weng, Mingyi Hong, Xue Lin• 2019

Related benchmarks

TaskDatasetResultRank
Node ClassificationCiteseer
Accuracy70.52
1037
Node ClassificationCiteseer (test)
Accuracy0.7052
1013
Node ClassificationCora (test)
Mean Accuracy76.8
951
Node ClassificationCornell
Accuracy42.97
900
Node ClassificationWisconsin
Accuracy44.71
898
Node ClassificationTexas
Accuracy0.5757
859
Node ClassificationPubMed (test)
Accuracy78.2
628
Node ClassificationActor
Accuracy29.25
598
Node Classificationogbn-arxiv (test)
Accuracy64.7
542
Node ClassificationPhoto
Mean Accuracy91.46
447
Showing 10 of 29 rows

Other info

Follow for update