Our new X account is live! Follow @wizwand_team for updates
WorkDL logo mark

Robustness of Graph Neural Networks at Scale

About

Graph Neural Networks (GNNs) are increasingly important given their popularity and the diversity of applications. Yet, existing studies of their vulnerability to adversarial attacks rely on relatively small graphs. We address this gap and study how to attack and defend GNNs at scale. We propose two sparsity-aware first-order optimization attacks that maintain an efficient representation despite optimizing over a number of parameters which is quadratic in the number of nodes. We show that common surrogate losses are not well-suited for global attacks on GNNs. Our alternatives can double the attack strength. Moreover, to improve GNNs' reliability we design a robust aggregation function, Soft Median, resulting in an effective defense at all scales. We evaluate our attacks and defense with standard GNNs on graphs more than 100 times larger compared to previous work. We even scale one order of magnitude further by extending our techniques to a scalable GNN.

Simon Geisler, Tobias Schmidt, Hakan \c{S}irin, Daniel Z\"ugner, Aleksandar Bojchevski, Stephan G\"unnemann• 2021

Related benchmarks

TaskDatasetResultRank
Node ClassificationCiteseer
Accuracy74.6
804
Node ClassificationCiteseer (test)
Accuracy0.746
729
Node ClassificationCora-ML
Accuracy85
228
Node ClassificationCiteseer original (test)
Accuracy74.6
84
Node ClassificationCora ML original (test)
Accuracy85
84
Node ClassificationCora ML (test)
Accuracy (General)85
83
Node ClassificationCora-ML standard (test)
Accuracy (Clean)73.2
16
Node ClassificationCiteseer (test)
Accuracy (Clean)0.9
16
Node ClassificationCiteseer standard (test)
Accuracy (Clean)74.6
16
Node ClassificationCiteseer standard (test)
Node Classification Accuracy78.7
14
Showing 10 of 12 rows

Other info

Follow for update