A Secure GNN Training Framework for Partially Observable Graph

被引:0
|
作者
An, Dongdong [1 ]
Yang, Yi [1 ]
Liu, Wenyan [2 ,3 ]
Zhao, Qin [1 ]
Liu, Jing [4 ]
Qi, Hongda [1 ]
Lian, Jie [1 ]
机构
[1] Shanghai Normal Univ, Shanghai Engn Res Ctr Intelligent Educ & Bigdata, Shanghai 200234, Peoples R China
[2] Ant Grp, Hangzhou 310023, Peoples R China
[3] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou 310058, Peoples R China
[4] East China Normal Univ, Shanghai Key Lab Trustworthy Comp, Shanghai 200062, Peoples R China
基金
中国国家自然科学基金;
关键词
Graph Neural Networks; adversarial injection attack; partial observability; reinforcement learning;
D O I
10.3390/electronics13142721
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Graph Neural Networks (GNNs) are susceptible to adversarial injection attacks, potentially compromising the model integrity, reducing accuracy, and posing security risks. However, most of the current countermeasures focus on enhancing the robustness of GNNs rather than directly addressing these specific attacks. The challenge stems from the difficulty of protecting all nodes in the entire graph and the agnostic of the attackers. Therefore, we propose a secure training strategy for GNNs that counters the vulnerability to adversarial injection attacks and overcomes the obstacle of partial observability in existing defense mechanisms-where defenders are only aware of the graph's post-attack structure and node attributes, without the identification of compromised nodes. Our strategy not only protects specific nodes but also extends security to all nodes in the graph. We model the graph security issues as a Partially Observable Markov Decision Process (POMDP) and use Graph Convolutional Memory (GCM) to transform the observations of a POMDP into states with temporal memory proceeding to use reinforcement learning to solve for the optimal defensive strategy. Finally, we prevent learning from malicious nodes by limiting the convolutional scope, thus defending against adversarial injection attacks. Our defense method is evaluated on five datasets, achieving an accuracy range of 74% to 86.7%, which represents an enhancement of approximately 5.09% to 100.26% over post-attack accuracies. Compared with various traditional experimental models, our method shows an accuracy improvement ranging from 0.82% to 100.26%.
引用
收藏
页数:20
相关论文
共 50 条
  • [1] GNN-Aided Distributed GAN with Partially Observable Social Graph
    Chen, Ming
    Wang, Shangshang
    Zhang, Tianyi
    Shao, Ziyu
    Yang, Yang
    2024 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE, WCNC 2024, 2024,
  • [2] NeutronStream: A Dynamic GNN Training Framework with Sliding Window for Graph Streams
    Chen, Chaoyi
    Gao, Dechao
    Zhang, Yanfeng
    Wang, Qiange
    Fu, Zhenbo
    Zhang, Xuecang
    Zhu, Junhua
    Gu, Yu
    Yu, Ge
    PROCEEDINGS OF THE VLDB ENDOWMENT, 2023, 17 (03): : 455 - 468
  • [3] Partially Observable Games for Secure Autonomy
    Ahmadi, Mohamadreza
    Viswanathan, Arun A.
    Ingham, Michel D.
    Tan, Kymie
    Ames, Aaron D.
    2020 IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2020), 2020, : 185 - 188
  • [4] Bidding Graph Games with Partially-Observable Budgets
    Avni, Guy
    Jecker, Ismael
    Zikelic, Dorde
    THIRTY-SEVENTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 37 NO 5, 2023, : 5464 - 5471
  • [5] Secure Control in Partially Observable Environments to Satisfy LTL Specifications
    Ramasubramanian, Bhaskar
    Niu, Luyao
    Clark, Andrew
    Bushnell, Linda
    Poovendran, Radha
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2021, 66 (12) : 5665 - 5679
  • [6] DeepGD: A Deep Learning Framework for Graph Drawing Using GNN
    Wang, Xiaoqi
    Yen, Kevin
    Hu, Yifan
    Shen, Han-Wei
    IEEE COMPUTER GRAPHICS AND APPLICATIONS, 2021, 41 (05) : 32 - 44
  • [7] FlexGraph: A Flexible and Efficient Distributed Framework for GNN Training
    Wang, Lei
    Yin, Qiang
    Tian, Chao
    Yang, Jianbang
    Chen, Rong
    Yu, Wenyuan
    Yao, Zihang
    Zhou, Jingren
    PROCEEDINGS OF THE SIXTEENTH EUROPEAN CONFERENCE ON COMPUTER SYSTEMS (EUROSYS '21), 2021, : 67 - 82
  • [8] Towards More Robust GNN Training with Graph Normalization for GraphSAINT
    Wang, Yuying
    Hao, Qinfen
    APPLIED INFORMATICS (ICAI 2021), 2021, 1455 : 82 - 93
  • [9] DGS: Communication-Efficient Graph Sampling for Distributed GNN Training
    Wan, Xinchen
    Chen, Kai
    Zhang, Yiming
    2022 IEEE 30TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP 2022), 2022,
  • [10] Enhanced Spatial Attention Graph for Motion Planning in Crowded, Partially Observable Environments
    Shi, Weixian
    Zhou, Yanying
    Zeng, Xiangyu
    Li, Shijie
    Bennewitz, Maren
    2022 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION (ICRA 2022), 2022, : 4750 - 4756