REVIEW 1 cited by
Adversarial Attacks on Graph Neural Networks via Meta Learning
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Deep learning models for graphs have advanced the state of the art on many tasks. Despite their recent success, little is known about their robustness. We investigate training time attacks on graph neural networks for node classification that perturb the discrete graph structure. Our core principle is to use meta-gradients to solve the bilevel problem underlying training-time attacks, essentially treating the graph as a hyperparameter to optimize. Our experiments show that small graph perturbations consistently lead to a strong decrease in performance for graph convolutional networks, and even transfer to unsupervised embeddings. Remarkably, the perturbations created by our algorithm can misguide the graph neural networks such that they perform worse than a simple baseline that ignores all relational information. Our attacks do not assume any knowledge about or access to the target classifiers.
Forward citations
Cited by 1 Pith paper
-
Budgeted Indirect Adversarial Attack on Graph-Based Anomaly Detection in Sensor Networks
BETA, a budget-limited indirect attack, uses a graph explainer and centrality ranking to pick sensors to perturb, cutting F1 scores of GDN and TopoGDN anomaly detectors by large margins across three sensor datasets.
Discussion (0). Sign in to comment.