Node Injection Attack Based on Label Propagation Against Graph Neural Network

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Zhu, Peican, Pan, Zechen, Tang, Keke, Cui, Xiaodong, Wang, Jinhuan, Xuan, Qi
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866910462111645696
author Zhu, Peican
Pan, Zechen
Tang, Keke
Cui, Xiaodong
Wang, Jinhuan
Xuan, Qi
author_facet Zhu, Peican
Pan, Zechen
Tang, Keke
Cui, Xiaodong
Wang, Jinhuan
Xuan, Qi
contents Graph Neural Network (GNN) has achieved remarkable success in various graph learning tasks, such as node classification, link prediction and graph classification. The key to the success of GNN lies in its effective structure information representation through neighboring aggregation. However, the attacker can easily perturb the aggregation process through injecting fake nodes, which reveals that GNN is vulnerable to the graph injection attack. Existing graph injection attack methods primarily focus on damaging the classical feature aggregation process while overlooking the neighborhood aggregation process via label propagation. To bridge this gap, we propose the label-propagation-based global injection attack (LPGIA) which conducts the graph injection attack on the node classification task. Specifically, we analyze the aggregation process from the perspective of label propagation and transform the graph injection attack problem into a global injection label specificity attack problem. To solve this problem, LPGIA utilizes a label propagation-based strategy to optimize the combinations of the nodes connected to the injected node. Then, LPGIA leverages the feature mapping to generate malicious features for injected nodes. In extensive experiments against representative GNNs, LPGIA outperforms the previous best-performing injection attack method in various datasets, demonstrating its superiority and transferability.
format Preprint
id arxiv_https___arxiv_org_abs_2405_18824
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Node Injection Attack Based on Label Propagation Against Graph Neural Network
Zhu, Peican
Pan, Zechen
Tang, Keke
Cui, Xiaodong
Wang, Jinhuan
Xuan, Qi
Cryptography and Security
Graph Neural Network (GNN) has achieved remarkable success in various graph learning tasks, such as node classification, link prediction and graph classification. The key to the success of GNN lies in its effective structure information representation through neighboring aggregation. However, the attacker can easily perturb the aggregation process through injecting fake nodes, which reveals that GNN is vulnerable to the graph injection attack. Existing graph injection attack methods primarily focus on damaging the classical feature aggregation process while overlooking the neighborhood aggregation process via label propagation. To bridge this gap, we propose the label-propagation-based global injection attack (LPGIA) which conducts the graph injection attack on the node classification task. Specifically, we analyze the aggregation process from the perspective of label propagation and transform the graph injection attack problem into a global injection label specificity attack problem. To solve this problem, LPGIA utilizes a label propagation-based strategy to optimize the combinations of the nodes connected to the injected node. Then, LPGIA leverages the feature mapping to generate malicious features for injected nodes. In extensive experiments against representative GNNs, LPGIA outperforms the previous best-performing injection attack method in various datasets, demonstrating its superiority and transferability.
title Node Injection Attack Based on Label Propagation Against Graph Neural Network
topic Cryptography and Security
url https://arxiv.org/abs/2405.18824