Black-Box Attacks on Graph Neural Networks via White-Box Methods With Performance Guarantees

被引:0
|
作者
Yang, Jielong [1 ]
Ding, Rui [1 ]
Chen, Jianyu [2 ]
Zhong, Xionghu [3 ]
Zhao, Huarong [1 ]
Xie, Linbo [1 ]
机构
[1] Jiangnan Univ, Sch Internet Things Engn, Wuxi 214122, Jiangsu, Peoples R China
[2] Beihang Univ, Inst Artificial Intelligence, Beijing 100191, Peoples R China
[3] Hunan Univ, Sch Comp Sci & Technol, Changsha 410082, Peoples R China
来源
IEEE INTERNET OF THINGS JOURNAL | 2024年 / 11卷 / 10期
关键词
Glass box; Closed box; Mathematical models; Laplace equations; Training; Graph neural networks; Perturbation methods; Attack performance guarantees; black-box attack; graph neural network (GNN);
D O I
10.1109/JIOT.2024.3360982
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Graph adversarial attacks can be classified as either white-box or black-box attacks. White-box attackers typically exhibit better performance because they can exploit the known structure of victim models. However, in practical settings, most attackers generate perturbations under black-box conditions, where the victim model is unknown. A fundamental question is how to leverage a white-box attacker to attack a black-box model. Some current black-box attack approaches employ white-box techniques to attack a surrogate model, resulting in satisfactory outcomes. Nonetheless, such white-box attackers must be meticulously designed and lack theoretical assurances for attack effectiveness. In this article, we propose a novel framework that utilizes simple white-box techniques to conduct black-box attacks and provides the lower bound for attack performance. Specifically, we first employ a more comprehensive GCN technique named BiasGCN to approximate the victim model, and subsequently, use a simple white-box approach to attack the approximate model. We provide a generalization guarantee for our BiasGCN and employ it to obtain the lower bound on attack performance. Our method is evaluated on various data sets, and the experimental results indicate that our approach surpasses recently proposed baselines.
引用
收藏
页码:18193 / 18204
页数:12
相关论文
共 50 条
  • [21] Investigating Top-k White-Box and Transferable Black-box Attack
    Zhang, Chaoning
    Benz, Philipp
    Karjauv, Adil
    Cho, Jae Won
    Zhang, Kang
    Kweon, In So
    2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2022), 2022, : 15064 - 15073
  • [22] White-Box or Black-Box Decision Tree Algorithms: Which to Use in Education?
    Delibasic, Boris
    Vukicevic, Milan
    Jovanovic, Milos
    Suknovic, Milija
    IEEE TRANSACTIONS ON EDUCATION, 2013, 56 (03) : 287 - 291
  • [23] White-box vs Black-box: Bayes Optimal Strategies for Membership Inference
    Sablayrolles, Alexandre
    Douze, Matthijs
    Ollivier, Yann
    Schmid, Cordelia
    Jegou, Nerve
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 97, 2019, 97
  • [24] Spectral Privacy Detection on Black-box Graph Neural Networks
    Yang, Yining
    Lu, Jialiang
    2023 IEEE 98TH VEHICULAR TECHNOLOGY CONFERENCE, VTC2023-FALL, 2023,
  • [25] Black-box Adversarial Attack and Defense on Graph Neural Networks
    Li, Haoyang
    Di, Shimin
    Li, Zijian
    Chen, Lei
    Cao, Jiannong
    2022 IEEE 38TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE 2022), 2022, : 1017 - 1030
  • [26] A comparative study of black-box and white-box data-driven methods to predict landfill leachate permeability
    Ghasemi, Mahdi
    Samadi, Mehrshad
    Soleimanian, Elham
    Chau, Kwok-Wing
    ENVIRONMENTAL MONITORING AND ASSESSMENT, 2023, 195 (07)
  • [27] Black-Box and White-Box Test Case Generation for RESTful APIs: Enemies or Allies?
    Martin-Lopez, Alberto
    Arcuri, Andrea
    Segura, Sergio
    Ruiz-Cortes, Antonio
    2021 IEEE 32ND INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE 2021), 2021, : 231 - 241
  • [28] A Black-Box Approach to Interfacing White-Box Transformer Models With Electromagnetic Transients Programs
    Gustavsen, Bjorn
    Portillo, Alvaro
    2014 IEEE PES GENERAL MEETING - CONFERENCE & EXPOSITION, 2014,
  • [29] Towards Lightweight Black-Box Attacks Against Deep Neural Networks
    Sun, Chenghao
    Zhang, Yonggang
    Wan Chaoqun
    Wang, Qizhou
    Li, Ya
    Liu, Tongliang
    Han, Bo
    Tian, Xinmei
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [30] A Grey-Box Ensemble Model Exploiting Black-Box Accuracy and White-Box Intrinsic Interpretability
    Pintelas, Emmanuel
    Livieris, Ioannis E.
    Pintelas, Panagiotis
    ALGORITHMS, 2020, 13 (01)