Saved in:
Bibliographic Details
Main Authors: Yu, Jianke, Wang, Hanchen, Chen, Chen, Wang, Xiaoyang, Qin, Lu, Zhang, Wenjie, Zhang, Ying, Liu, Xijuan
Format: Preprint
Published: 2024
Subjects:
Online Access:https://arxiv.org/abs/2407.18170
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913853635297280
author Yu, Jianke
Wang, Hanchen
Chen, Chen
Wang, Xiaoyang
Qin, Lu
Zhang, Wenjie
Zhang, Ying
Liu, Xijuan
author_facet Yu, Jianke
Wang, Hanchen
Chen, Chen
Wang, Xiaoyang
Qin, Lu
Zhang, Wenjie
Zhang, Ying
Liu, Xijuan
contents Graph Neural Networks (GNNs) are vital in data science but are increasingly susceptible to adversarial attacks. To help researchers develop more robust GNN models, it's essential to focus on designing strong attack models as foundational benchmarks and guiding references. Among adversarial attacks, gray-box poisoning attacks are noteworthy due to their effectiveness and fewer constraints. These attacks exploit GNNs' need for retraining on updated data, thereby impacting their performance by perturbing these datasets. However, current research overlooks the real-world scenario of incomplete graphs. To address this gap, we introduce the Robust Incomplete Deep Attack Framework (RIDA). It is the first algorithm for robust gray-box poisoning attacks on incomplete graphs. The approach innovatively aggregates distant vertex information and ensures powerful data utilization. Extensive tests against 9 SOTA baselines on 3 real-world datasets demonstrate that RIDA's superiority in handling incompleteness and high attack performance on the incomplete graph.
format Preprint
id arxiv_https___arxiv_org_abs_2407_18170
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle RIDA: A Robust Attack Framework on Incomplete Graphs
Yu, Jianke
Wang, Hanchen
Chen, Chen
Wang, Xiaoyang
Qin, Lu
Zhang, Wenjie
Zhang, Ying
Liu, Xijuan
Machine Learning
Graph Neural Networks (GNNs) are vital in data science but are increasingly susceptible to adversarial attacks. To help researchers develop more robust GNN models, it's essential to focus on designing strong attack models as foundational benchmarks and guiding references. Among adversarial attacks, gray-box poisoning attacks are noteworthy due to their effectiveness and fewer constraints. These attacks exploit GNNs' need for retraining on updated data, thereby impacting their performance by perturbing these datasets. However, current research overlooks the real-world scenario of incomplete graphs. To address this gap, we introduce the Robust Incomplete Deep Attack Framework (RIDA). It is the first algorithm for robust gray-box poisoning attacks on incomplete graphs. The approach innovatively aggregates distant vertex information and ensures powerful data utilization. Extensive tests against 9 SOTA baselines on 3 real-world datasets demonstrate that RIDA's superiority in handling incompleteness and high attack performance on the incomplete graph.
title RIDA: A Robust Attack Framework on Incomplete Graphs
topic Machine Learning
url https://arxiv.org/abs/2407.18170