AIセキュリティポータル K Program
PAC-Bayesian Adversarially Robust Generalization Bounds for Graph Neural Network
Share
Abstract
Graph neural networks (GNNs) have gained popularity for various graph-related tasks. However, similar to deep neural networks, GNNs are also vulnerable to adversarial attacks. Empirical studies have shown that adversarially robust generalization has a pivotal role in establishing effective defense algorithms against adversarial attacks. In this paper, we contribute by providing adversarially robust generalization bounds for two kinds of popular GNNs, graph convolutional network (GCN) and message passing graph neural network, using the PAC-Bayesian framework. Our result reveals that spectral norm of the diffusion matrix on the graph and spectral norm of the weights as well as the perturbation factor govern the robust generalization bounds of both models. Our bounds are nontrivial generalizations of the results developed in (Liao et al., 2020) from the standard setting to adversarial setting while avoiding exponential dependence of the maximum node degree. As corollaries, we derive better PAC-Bayesian robust generalization bounds for GCN in the standard setting, which improve the bounds in (Liao et al., 2020) by avoiding exponential dependence on the maximum node degree.
Neural network learning: Theoretical foundations
Anthony, M., Bartlett, P.L.
Published: 2009
Adversarial Learning Guarantees for Linear Hypotheses and Neural Networks
Pranjal Awasthi, Natalie Frank, Mehryar Mohri
Published: 2020.4.29
Spectrally-normalized margin bounds for neural networks
Bartlett, P.L., Foster, D.J., Telgarsky, M.J.
Published: 2017
Rademacher and gaussian complexities: Risk bounds and structural results
Bartlett, P.L., Mendelson, S.
Published: 2002
Discriminative embeddings of latent variable models for structured data
Dai, H., Dai, B., Song, L.
Published: 2016
Graph neural tangent kernel: Fusing graph neural networks with graph kernels
S. S. Du, K. Hou, R. R. Salakhutdinov, B. Poczos, R. Wang, K. Xu
Published: 2019
All you need is low (rank) defending against adversarial attacks on graphs
Entezari, N., Al-Sayouri, S.A., Darvishzadeh, A., Papalexakis, E.E.
Published: 2020
Learning theory can (sometimes) explain generalisation in graph neural networks
Esser, P., Chennuru Vankadara, L., Ghoshdastidar, D.
Published: 2021
Generalizable adversarial training via spectral normalization
Farnia, F., Zhang, J.M., Tse, D.
Published: 2019
Theoretical investigation of generalization bounds for adversarial learning of deep neural networks
Gao, Q., Wang, X.
Published: 2021
Generalization and representational limits of graph neural networks
Garg, V., Jegelka, S., Jaakkola, T.
Published: 2020
Neural message passing for quantum chemistry
Gilmer, J., Schoenholz, S.S., Riley, P.F., Vinyals, O., Dahl, G.E.
Published: 2017
Size-independent sample complexity of neural networks
Golowich, N., Rakhlin, A., Shamir, O.
Published: 2018
Explaining and harnessing adversarial examples
Goodfellow, I.J., Shlens, J., Szegedy, C.
Published: 2015
Neural tangent kernel: Convergence and generalization in neural networks
Jacot, A., Gabriel, F., Hongler, C.
Published: 2018
Junction tree variational autoencoder for molecular graph generation
Jin, W., Barzilay, R., Jaakkola, T.
Published: 2018
Learning multimodal graph-to-graph translation for molecular optimization
Jin, W., Yang, K., Barzilay, R., Jaakkola, T.
Published: 2019
Generalization in graph neural networks: Improved PAC-bayesian bounds on graph diffusion
Ju, H., Li, D., Sharma, A., Zhang, H.R.
Published: 2023
Semi-supervised classification with graph convolutional networks
Thomas N Kipf, Max Welling
Published: 2017
A PAC-bayesian approach to generalization bounds for graph neural networks
Liao, R., Urtasun, R., Zemel, R.
Published: 2020
Simplified PAC-bayesian margin bounds
McAllester, D.
Published: 2003
On the generalization analysis of adversarial learning
Mustafa, W., Lei, Y., Kloft, M.
Published: 2022
Norm-based capacity control in neural networks
Neyshabur, B., Tomioka, R., Srebro, N.
Published: 2015
Task sensitive feature exploration and learning for multitask graph classification
Pan, S., Wu, J., Zhu, X., Long, G., Zhang, C.
Published: 2016
Joint structure feature exploration and regularization for multi-task graph classification
Pan, S., Wu, J., Zhu, X., Zhang, C., Philip, S.Y.
Published: 2015
The graph neural network model
Scarselli, F., Gori, M., Tsoi, A.C., Hagenbuchner, M., Monfardini, G.
Published: 2009
The vapnik–chervonenkis dimension of graph and recursive neural networks
Scarselli, F., Tsoi, A.C., Hagenbuchner, M.
Published: 2018
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, R. Fergus
Published: 2014
Transferring Robustness for Graph Neural Network Against Poisoning Attacks
Xianfeng Tang, Yandong Li, Yiwei Sun, Huaxiu Yao, Prasenjit Mitra, Suhang Wang
Published: 2019.8.21
User-friendly tail bounds for sums of random matrices
Tropp, J.A.
Published: 2012
Stability and generalization of graph convolutional neural networks
Verma, S., Zhang, Z.L.
Published: 2019
PAC-bayesian adversarially robust generalization bounds for deep neural networks
Xiao, J., Sun, R., Luo, Z.Q.
Published: 2023
Rademacher Complexity for Adversarially Robust Generalization
Dong Yin, Kannan Ramchandran, Peter Bartlett
Published: 2018.10.29
Hierarchical graph representation learning with differentiable pooling
Ying, Z., You, J., Morris, C., Ren, X., Hamilton, W., Leskovec, J.
Published: 2018
An end-to-end deep learning architecture for graph classification
Zhang, M., Cui, Z., Neumann, M., Chen, Y.
Published: 2018
GNNGuard: Defending Graph Neural Networks against Adversarial Attacks
Xiang Zhang, Marinka Zitnik
Published: 2020.6.15
Robust graph convolutional networks against adversarial attacks
Zhu, D., Zhang, Z., Cui, P., Zhu, W.
Published: 2019
Adversarial attacks on graph neural networks: Perturbations and their patterns
Zügner, D., Borchert, O., Akbarnejad, A., Günnemann, S.
Published: 2020
Adversarial attacks on neural networks for graph data
Daniel Zügner, Amir Akbarnejad, Stephan Günnemann
Published: 2018
Share