E-SAGE: Explainability-based Defense Against Backdoor Attacks on Graph Neural Networks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yuan, Dingqiang, Xu, Xiaohua, Yu, Lei, Han, Tongchang, Li, Rongchang, Han, Meng
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910489000280064
author Yuan, Dingqiang
Xu, Xiaohua
Yu, Lei
Han, Tongchang
Li, Rongchang
Han, Meng
author_facet Yuan, Dingqiang
Xu, Xiaohua
Yu, Lei
Han, Tongchang
Li, Rongchang
Han, Meng
contents Graph Neural Networks (GNNs) have recently been widely adopted in multiple domains. Yet, they are notably vulnerable to adversarial and backdoor attacks. In particular, backdoor attacks based on subgraph insertion have been shown to be effective in graph classification tasks while being stealthy, successfully circumventing various existing defense methods. In this paper, we propose E-SAGE, a novel approach to defending GNN backdoor attacks based on explainability. We find that the malicious edges and benign edges have significant differences in the importance scores for explainability evaluation. Accordingly, E-SAGE adaptively applies an iterative edge pruning process on the graph based on the edge scores. Through extensive experiments, we demonstrate the effectiveness of E-SAGE against state-of-the-art graph backdoor attacks in different attack settings. In addition, we investigate the effectiveness of E-SAGE against adversarial attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2406_10655
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle E-SAGE: Explainability-based Defense Against Backdoor Attacks on Graph Neural Networks
Yuan, Dingqiang
Xu, Xiaohua
Yu, Lei
Han, Tongchang
Li, Rongchang
Han, Meng
Cryptography and Security
Graph Neural Networks (GNNs) have recently been widely adopted in multiple domains. Yet, they are notably vulnerable to adversarial and backdoor attacks. In particular, backdoor attacks based on subgraph insertion have been shown to be effective in graph classification tasks while being stealthy, successfully circumventing various existing defense methods. In this paper, we propose E-SAGE, a novel approach to defending GNN backdoor attacks based on explainability. We find that the malicious edges and benign edges have significant differences in the importance scores for explainability evaluation. Accordingly, E-SAGE adaptively applies an iterative edge pruning process on the graph based on the edge scores. Through extensive experiments, we demonstrate the effectiveness of E-SAGE against state-of-the-art graph backdoor attacks in different attack settings. In addition, we investigate the effectiveness of E-SAGE against adversarial attacks.
title E-SAGE: Explainability-based Defense Against Backdoor Attacks on Graph Neural Networks
topic Cryptography and Security
url https://arxiv.org/abs/2406.10655