REVIEW 3 cited by
Adversarial Attacks and Defenses on Graphs: A Review, A Tool and Empirical Studies
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
Deep neural networks (DNNs) have achieved significant performance in various tasks. However, recent studies have shown that DNNs can be easily fooled by small perturbation on the input, called adversarial attacks. As the extensions of DNNs to graphs, Graph Neural Networks (GNNs) have been demonstrated to inherit this vulnerability. Adversary can mislead GNNs to give wrong predictions by modifying the graph structure such as manipulating a few edges. This vulnerability has arisen tremendous concerns for adapting GNNs in safety-critical applications and has attracted increasing research attention in recent years. Thus, it is necessary and timely to provide a comprehensive overview of existing graph adversarial attacks and the countermeasures. In this survey, we categorize existing attacks and defenses, and review the corresponding state-of-the-art methods. Furthermore, we have developed a repository with representative algorithms (https://github.com/DSE-MSU/DeepRobust/tree/master/deeprobust/graph). The repository enables us to conduct empirical studies to deepen our understandings on attacks and defenses on graphs.
Forward citations
Cited by 3 Pith papers
-
Same Graph Cross-Task Transfer in GNNs: Protocols and Predictors
Under a fixed leakage-free protocol, NC→LP transfer reliably helps on homophilic graphs while LP→NC helps mainly when LP is easy and NC is unsaturated; homophily and CoTask Score guide mechanism choice.
-
Quantifying the Noise of Structural Perturbations on Graph Adversarial Attacks
A new link-noise metric, computed from node degrees and entropy-based dissimilarity, ranks candidate adversarial edges and prunes the search space for targeted graph attacks, yielding competitive or better attack succ...
-
Mitigating the Structural Bias in Graph Adversarial Defenses
De2GNN reduces degree bias in adversarial defenses by removing heterophilic links, adding homophilic links to tail nodes, and fusing a kNN feature view through node-wise attention, improving tail-node accuracy under M...
Discussion (0). Continue with ORCID to comment.