REVIEW 4 cited by
Adversarial Attacks on Graph Neural Networks via Meta Learning
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Deep learning models for graphs have advanced the state of the art on many tasks. Despite their recent success, little is known about their robustness. We investigate training time attacks on graph neural networks for node classification that perturb the discrete graph structure. Our core principle is to use meta-gradients to solve the bilevel problem underlying training-time attacks, essentially treating the graph as a hyperparameter to optimize. Our experiments show that small graph perturbations consistently lead to a strong decrease in performance for graph convolutional networks, and even transfer to unsupervised embeddings. Remarkably, the perturbations created by our algorithm can misguide the graph neural networks such that they perform worse than a simple baseline that ignores all relational information. Our attacks do not assume any knowledge about or access to the target classifiers.
Forward citations
Cited by 4 Pith papers
-
GJDNet: Robust Graph Neural Networks via Joint Disentangled Learning Against Adversarial Attacks
GJDNet proposes feature-driven soft structural disentanglement and a Spherical Decision Boundary to achieve robust node classification on graphs with varying assortativity against adversarial attacks.
-
T2T-LA: A Topology-to-Topology LLM Agent for Graph Learning with Neither Feature Access nor Task Knowledge
T2T-LA is an LLM agent that generates a useful graph topology in one shot from failed topologies and scores without feature access or task knowledge.
-
Community detection robustness of graph neural networks
Supervised GNNs show higher baseline accuracy on community detection while unsupervised ones like DMoN prove more resilient to attribute shifts, edge deletions, and adversarial perturbations, with stronger communities...
-
Budgeted Indirect Adversarial Attack on Graph-Based Anomaly Detection in Sensor Networks
BETA, a budget-limited indirect attack, uses a graph explainer and centrality ranking to pick sensors to perturb, cutting F1 scores of GDN and TopoGDN anomaly detectors by large margins across three sensor datasets.
Discussion (0). Sign in to comment.