Xianxian Li , Zeming Gan , Yan Bai , Linlin Su , De Li , Jinyan Wang
{"title":"D4A: An efficient and effective defense across agnostic adversarial attacks","authors":"Xianxian Li , Zeming Gan , Yan Bai , Linlin Su , De Li , Jinyan Wang","doi":"10.1016/j.neunet.2024.106938","DOIUrl":null,"url":null,"abstract":"<div><div>Recent studies show that Graph Neural Networks (GNNs) are vulnerable to structure adversarial attacks, which draws attention to adversarial defenses in graph data. Previous defenses designed heuristic defense strategies for specific attacks or graph properties, and are no longer sufficiently robust across all these attacks. To address this problem, we discuss the abnormal behaviors of GNNs in structure perturbations from a posterior distribution perspective. We suggest that the structural vulnerability of GNNs stems from their dependence on local graph smoothing, which can also lead to <em>unfitting</em> — a first-found phenomenon specific to the graph domain. We demonstrate that abnormal behaviors, except for unfitting, can attribute to a posterior distribution shift. To intrinsically prevent the occurrence of abnormal behaviors, we first propose smooth-less message passing to enhance the tolerance with respect to structure perturbations, while significantly mitigating the unfitting. We also propose the distribution shift constraint to restrict other abnormal behaviors of our model. Our approach is evaluated on six different datasets across over four kinds of attacks and compared to 11 representative baselines. The experimental results show that our method improves the defense performance across various attacks, and provides a great trade-off between accuracy and adversarial robustness.</div></div>","PeriodicalId":49763,"journal":{"name":"Neural Networks","volume":"183 ","pages":"Article 106938"},"PeriodicalIF":6.0000,"publicationDate":"2024-11-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Neural Networks","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S0893608024008670","RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE","Score":null,"Total":0}
引用次数: 0
Abstract
Recent studies show that Graph Neural Networks (GNNs) are vulnerable to structure adversarial attacks, which draws attention to adversarial defenses in graph data. Previous defenses designed heuristic defense strategies for specific attacks or graph properties, and are no longer sufficiently robust across all these attacks. To address this problem, we discuss the abnormal behaviors of GNNs in structure perturbations from a posterior distribution perspective. We suggest that the structural vulnerability of GNNs stems from their dependence on local graph smoothing, which can also lead to unfitting — a first-found phenomenon specific to the graph domain. We demonstrate that abnormal behaviors, except for unfitting, can attribute to a posterior distribution shift. To intrinsically prevent the occurrence of abnormal behaviors, we first propose smooth-less message passing to enhance the tolerance with respect to structure perturbations, while significantly mitigating the unfitting. We also propose the distribution shift constraint to restrict other abnormal behaviors of our model. Our approach is evaluated on six different datasets across over four kinds of attacks and compared to 11 representative baselines. The experimental results show that our method improves the defense performance across various attacks, and provides a great trade-off between accuracy and adversarial robustness.
期刊介绍:
Neural Networks is a platform that aims to foster an international community of scholars and practitioners interested in neural networks, deep learning, and other approaches to artificial intelligence and machine learning. Our journal invites submissions covering various aspects of neural networks research, from computational neuroscience and cognitive modeling to mathematical analyses and engineering applications. By providing a forum for interdisciplinary discussions between biology and technology, we aim to encourage the development of biologically-inspired artificial intelligence.