AIセキュリティポータル K Program
Adversarial Attacks on Graph Neural Networks via Meta Learning
Share
Abstract
Deep learning models for graphs have advanced the state of the art on many tasks. Despite their recent success, little is known about their robustness. We investigate training time attacks on graph neural networks for node classification that perturb the discrete graph structure. Our core principle is to use meta-gradients to solve the bilevel problem underlying training-time attacks, essentially treating the graph as a hyperparameter to optimize. Our experiments show that small graph perturbations consistently lead to a strong decrease in performance for graph convolutional networks, and even transfer to unsupervised embeddings. Remarkably, the perturbations created by our algorithm can misguide the graph neural networks such that they perform worse than a simple baseline that ignores all relational information. Our attacks do not assume any knowledge about or access to the target classifiers.
The political blogosphere and the 2004 US election: divided they blog
Lada A Adamic, Natalie Glance
Published: 2005
On the optimization of a synaptic learning rule
Samy Bengio, Yoshua Bengio, Jocelyn Cloutier, Jan Gecsei
Published: 1992
Gradient-based optimization of hyperparameters
Yoshua Bengio
Published: 2000
Deep gaussian embedding of graphs: Unsupervised inductive learning via ranking
Aleksandar Bojchevski, Stephan G ¨unnemann
Published: 2018
Bayesian robust attributed graph clustering: Joint learning of partial anomalies and group structure
Aleksandar Bojchevski, Stephan G ¨unnemann
Published: 2018
NetGAN: Generating graphs via random walks
Aleksandar Bojchevski, Oleksandr Shchur, Daniel Z ¨ugner, Stephan G ¨unnemann
Published: 2018
Semi-Supervised Learning
Olivier Chapelle, Bernhard Sch ¨olkopf, Alexander Zien
Published: 2006
Model-agnostic meta-learning for fast adaptation of deep networks
Chelsea Finn, Pieter Abbeel, Sergey Levine
Published: 2017
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., Szegedy, C.
Published: 2015
Semi-supervised classification with graph convolutional networks
Thomas N Kipf, Max Welling
Published: 2017
Predict then propagate: Graph neural networks meet personalized pagerank
Johannes Klicpera, Aleksandar Bojchevski, Stephan G ¨unnemann
Published: 2019
Collective classification of network data
Ben London, Lise Getoor
Published: 2014
Automating the construction of internet portals with machine learning
Andrew Kachites McCallum, Kamal Nigam, Jason Rennie, Kristie Seymore
Published: 2000
Using machine teaching to identify optimal training-set attacks on machine learners
Shike Mei, Xiaojin Zhu
Published: 2015
Geometric deep learning on graphs and manifolds using mixture model cnns
Federico Monti, Davide Boscaini, Jonathan Masci, Emanuele Rodola, Jan Svoboda, Michael M Bronstein
Published: 2017
Towards poisoning of deep learning algorithms with back-gradient optimization
L. Mu˜noz-Gonz´alez, B. Biggio, A. Demontis
Published: 2017
Meta-neural networks that learn by learning
Devang K Naik, RJ Mammone
Published: 1992
DeepWalk: Online learning of social representations
B. Perozzi, R. Al-Rfou, S. Skiena
Published: 2014
Column networks for collective classification
Trang Pham, Truyen Tran, Dinh Q. Phung, Svetha Venkatesh
Published: 2017
Learning to control fast-weight memories: An alternative to dynamic recurrent networks
J¨urgen Schmidhuber
Published: 1992
Collective classification in network data
Prithviraj Sen, Galileo Namata, Mustafa Bilgic, Lise Getoor, Brian Galligher, Tina Eliassi-Rad
Published: 2008
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, R. Fergus
Published: 2014
Learning to learn: Introduction and overview
Sebastian Thrun, Lorien Pratt
Published: 1998
Convex adversarial collective classification
Mohamad Ali Torkamani, Daniel Lowd
Published: 2013
Adversarial attacks on neural networks for graph data
Daniel Zügner, Amir Akbarnejad, Stephan Günnemann
Published: 2018
Share