基于标签传播的图神经网络节点注入攻击

IF 4.5 2区 计算机科学 Q1 COMPUTER SCIENCE, CYBERNETICS
Peican Zhu;Zechen Pan;Keke Tang;Xiaodong Cui;Jinhuan Wang;Qi Xuan
{"title":"基于标签传播的图神经网络节点注入攻击","authors":"Peican Zhu;Zechen Pan;Keke Tang;Xiaodong Cui;Jinhuan Wang;Qi Xuan","doi":"10.1109/TCSS.2024.3395794","DOIUrl":null,"url":null,"abstract":"Graph neural network (GNN) has achieved remarkable success in various graph learning tasks, such as node classification, link prediction, and graph classification. The key to the success of GNN lies in its effective structure information representation through neighboring aggregation. However, the attacker can easily perturb the aggregation process through injecting fake nodes, which reveals that GNN is vulnerable to the graph injection attack (GIA). Existing GIA methods primarily focus on damaging the classical feature aggregation process while overlooking the neighborhood aggregation process via label propagation. To bridge this gap, we propose the label-propagation-based global injection attack (LPGIA) which conducts the GIA on the node classification task. Specifically, we analyze the aggregation process from the perspective of label propagation and transform the GIA problem into a global injection label specificity attack problem. To solve this problem, LPGIA utilizes a label-propagation-based strategy to optimize the combinations of the nodes connected to the injected node. Then, LPGIA leverages the feature mapping to generate malicious features for injected nodes. In extensive experiments against representative GNNs, LPGIA outperforms the previous best-performing injection attack method in various datasets, demonstrating its superiority and transferability.","PeriodicalId":13044,"journal":{"name":"IEEE Transactions on Computational Social Systems","volume":"11 5","pages":"5858-5870"},"PeriodicalIF":4.5000,"publicationDate":"2024-06-07","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Node Injection Attack Based on Label Propagation Against Graph Neural Network\",\"authors\":\"Peican Zhu;Zechen Pan;Keke Tang;Xiaodong Cui;Jinhuan Wang;Qi Xuan\",\"doi\":\"10.1109/TCSS.2024.3395794\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Graph neural network (GNN) has achieved remarkable success in various graph learning tasks, such as node classification, link prediction, and graph classification. The key to the success of GNN lies in its effective structure information representation through neighboring aggregation. However, the attacker can easily perturb the aggregation process through injecting fake nodes, which reveals that GNN is vulnerable to the graph injection attack (GIA). Existing GIA methods primarily focus on damaging the classical feature aggregation process while overlooking the neighborhood aggregation process via label propagation. To bridge this gap, we propose the label-propagation-based global injection attack (LPGIA) which conducts the GIA on the node classification task. Specifically, we analyze the aggregation process from the perspective of label propagation and transform the GIA problem into a global injection label specificity attack problem. To solve this problem, LPGIA utilizes a label-propagation-based strategy to optimize the combinations of the nodes connected to the injected node. Then, LPGIA leverages the feature mapping to generate malicious features for injected nodes. In extensive experiments against representative GNNs, LPGIA outperforms the previous best-performing injection attack method in various datasets, demonstrating its superiority and transferability.\",\"PeriodicalId\":13044,\"journal\":{\"name\":\"IEEE Transactions on Computational Social Systems\",\"volume\":\"11 5\",\"pages\":\"5858-5870\"},\"PeriodicalIF\":4.5000,\"publicationDate\":\"2024-06-07\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IEEE Transactions on Computational Social Systems\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://ieeexplore.ieee.org/document/10552077/\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"COMPUTER SCIENCE, CYBERNETICS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Transactions on Computational Social Systems","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/10552077/","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, CYBERNETICS","Score":null,"Total":0}
引用次数: 0

摘要

图神经网络(GNN)在节点分类、链接预测和图分类等各种图学习任务中取得了显著的成功。图神经网络成功的关键在于其通过邻接聚合实现的有效结构信息表示。然而,攻击者可以通过注入假节点轻易扰乱聚合过程,这就揭示了 GNN 容易受到图注入攻击(GIA)。现有的 GIA 方法主要侧重于破坏经典的特征聚合过程,而忽略了通过标签传播的邻域聚合过程。为了弥补这一缺陷,我们提出了基于标签传播的全局注入攻击(LPGIA),它可以对节点分类任务进行 GIA。具体来说,我们从标签传播的角度分析了聚合过程,并将 GIA 问题转化为全局注入标签特异性攻击问题。为了解决这个问题,LPGIA 利用基于标签传播的策略来优化与注入节点相连的节点组合。然后,LPGIA 利用特征映射为注入节点生成恶意特征。在针对具有代表性的 GNN 进行的大量实验中,LPGIA 在各种数据集中的表现都优于之前表现最好的注入攻击方法,这证明了它的优越性和可移植性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Node Injection Attack Based on Label Propagation Against Graph Neural Network
Graph neural network (GNN) has achieved remarkable success in various graph learning tasks, such as node classification, link prediction, and graph classification. The key to the success of GNN lies in its effective structure information representation through neighboring aggregation. However, the attacker can easily perturb the aggregation process through injecting fake nodes, which reveals that GNN is vulnerable to the graph injection attack (GIA). Existing GIA methods primarily focus on damaging the classical feature aggregation process while overlooking the neighborhood aggregation process via label propagation. To bridge this gap, we propose the label-propagation-based global injection attack (LPGIA) which conducts the GIA on the node classification task. Specifically, we analyze the aggregation process from the perspective of label propagation and transform the GIA problem into a global injection label specificity attack problem. To solve this problem, LPGIA utilizes a label-propagation-based strategy to optimize the combinations of the nodes connected to the injected node. Then, LPGIA leverages the feature mapping to generate malicious features for injected nodes. In extensive experiments against representative GNNs, LPGIA outperforms the previous best-performing injection attack method in various datasets, demonstrating its superiority and transferability.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
IEEE Transactions on Computational Social Systems
IEEE Transactions on Computational Social Systems Social Sciences-Social Sciences (miscellaneous)
CiteScore
10.00
自引率
20.00%
发文量
316
期刊介绍: IEEE Transactions on Computational Social Systems focuses on such topics as modeling, simulation, analysis and understanding of social systems from the quantitative and/or computational perspective. "Systems" include man-man, man-machine and machine-machine organizations and adversarial situations as well as social media structures and their dynamics. More specifically, the proposed transactions publishes articles on modeling the dynamics of social systems, methodologies for incorporating and representing socio-cultural and behavioral aspects in computational modeling, analysis of social system behavior and structure, and paradigms for social systems modeling and simulation. The journal also features articles on social network dynamics, social intelligence and cognition, social systems design and architectures, socio-cultural modeling and representation, and computational behavior modeling, and their applications.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信