REVIEW 4 cited by
Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Graph neural networks (GNNs) which apply the deep neural networks to graph data have achieved significant performance for the task of semi-supervised node classification. However, only few work has addressed the adversarial robustness of GNNs. In this paper, we first present a novel gradient-based attack method that facilitates the difficulty of tackling discrete graph data. When comparing to current adversarial attacks on GNNs, the results show that by only perturbing a small number of edge perturbations, including addition and deletion, our optimization-based attack can lead to a noticeable decrease in classification performance. Moreover, leveraging our gradient-based attack, we propose the first optimization-based adversarial training for GNNs. Our method yields higher robustness against both different gradient based and greedy attack methods without sacrificing classification accuracy on original graph.
Forward citations
Cited by 4 Pith papers
-
Attacking Graph Foundation Models Through Their Shared Representation
A shared representation layer in graph foundation models is a distinct attack surface: input edits break three of six models and one spectral tokenizer is uniquely fragile.
-
EvA: Evolutionary Attacks on Graphs
EvA, an evolutionary search over edge flips, outperforms gradient-based attacks on GNNs and extends to breaking conformal and certificate guarantees.
-
Robust Learning on Noisy Graphs via Latent Space Constraints with External Knowledge
LSC-GNN uses a clean external graph to regularize the latent representations of a noisy target graph, improving node classification under moderate edge noise.
-
Unifying Adversarial Perturbation for Graph Neural Networks
Adding perturbations directly to every hidden embedding of a GNN is claimed to subsume existing feature-, edge-, and weight-perturbation defenses, but the claim rests on simplifications that the experiments do not act...
Discussion (0). Continue with ORCID to comment.