A Secure GNN Training Framework for Partially Observable Graph

被引:0
|
作者
An, Dongdong [1 ]
Yang, Yi [1 ]
Liu, Wenyan [2 ,3 ]
Zhao, Qin [1 ]
Liu, Jing [4 ]
Qi, Hongda [1 ]
Lian, Jie [1 ]
机构
[1] Shanghai Normal Univ, Shanghai Engn Res Ctr Intelligent Educ & Bigdata, Shanghai 200234, Peoples R China
[2] Ant Grp, Hangzhou 310023, Peoples R China
[3] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou 310058, Peoples R China
[4] East China Normal Univ, Shanghai Key Lab Trustworthy Comp, Shanghai 200062, Peoples R China
基金
中国国家自然科学基金;
关键词
Graph Neural Networks; adversarial injection attack; partial observability; reinforcement learning;
D O I
10.3390/electronics13142721
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Graph Neural Networks (GNNs) are susceptible to adversarial injection attacks, potentially compromising the model integrity, reducing accuracy, and posing security risks. However, most of the current countermeasures focus on enhancing the robustness of GNNs rather than directly addressing these specific attacks. The challenge stems from the difficulty of protecting all nodes in the entire graph and the agnostic of the attackers. Therefore, we propose a secure training strategy for GNNs that counters the vulnerability to adversarial injection attacks and overcomes the obstacle of partial observability in existing defense mechanisms-where defenders are only aware of the graph's post-attack structure and node attributes, without the identification of compromised nodes. Our strategy not only protects specific nodes but also extends security to all nodes in the graph. We model the graph security issues as a Partially Observable Markov Decision Process (POMDP) and use Graph Convolutional Memory (GCM) to transform the observations of a POMDP into states with temporal memory proceeding to use reinforcement learning to solve for the optimal defensive strategy. Finally, we prevent learning from malicious nodes by limiting the convolutional scope, thus defending against adversarial injection attacks. Our defense method is evaluated on five datasets, achieving an accuracy range of 74% to 86.7%, which represents an enhancement of approximately 5.09% to 100.26% over post-attack accuracies. Compared with various traditional experimental models, our method shows an accuracy improvement ranging from 0.82% to 100.26%.
引用
收藏
页数:20
相关论文
共 50 条
  • [31] Smoothing Adversarial Training for GNN
    Chen, Jinyin
    Lin, Xiang
    Xiong, Hui
    Wu, Yangyang
    Zheng, Haibin
    Xuan, Qi
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2021, 8 (03) : 618 - 629
  • [32] Betty: Enabling Large-Scale GNN Training with Batch-Level Graph Partitioning
    Yang, Shuangyan
    Zhang, Minjia
    Dong, Wenqian
    Li, Dong
    PROCEEDINGS OF THE 28TH ACM INTERNATIONAL CONFERENCE ON ARCHITECTURAL SUPPORT FOR PROGRAMMING LANGUAGES AND OPERATING SYSTEMS, VOL 2, ASPLOS 2023, 2023, : 103 - 117
  • [33] BGL: GPU-Efficient GNN Training by Optimizing Graph Data I/O and Preprocessing
    Liu, Tianfeng
    Chen, Yangrui
    Li, Dan
    Wu, Chuan
    Zhu, Yibo
    He, Jun
    Peng, Yanghua
    Chen, Hongzheng
    Chen, Hongzhi
    Guo, Chuanxiong
    PROCEEDINGS OF THE 20TH USENIX SYMPOSIUM ON NETWORKED SYSTEMS DESIGN AND IMPLEMENTATION, NSDI 2023, 2023, : 103 - 118
  • [34] Selective maintenance and inspection optimization for partially observable systems: An interactively sequential decision framework
    Liu, Yu
    Gao, Jian
    Jiang, Tao
    Zeng, Zhiguo
    IISE TRANSACTIONS, 2023, 55 (05) : 463 - 479
  • [35] PSA-GNN: An augmented GNN framework with priori subgraph knowledge
    Xue, Guotong
    Zhong, Ming
    Qian, Tieyun
    Li, Jianxin
    NEURAL NETWORKS, 2024, 173
  • [36] Auto-Divide GNN: Accelerating GNN Training with Subgraph Division
    Chen, Hongyu
    Ran, Zhejiang
    Ge, Keshi
    Lai, Zhiquan
    Jiang, Jingfei
    Li, Dongsheng
    EURO-PAR 2023: PARALLEL PROCESSING, 2023, 14100 : 367 - 382
  • [37] Solving Partially Observable Environments with Universal Search Using Dataflow Graph-Based Programming Model
    Paul, Swarna Kamal
    Bhaumik, Parama
    IETE JOURNAL OF RESEARCH, 2023, 69 (09) : 6137 - 6151
  • [38] Improved GNN based on Graph-Transformer: A new framework for rolling mill bearing fault diagnosis
    Hou, Dongxiao
    Zhang, Bo
    Chen, Jiahui
    Shi, Peiming
    TRANSACTIONS OF THE INSTITUTE OF MEASUREMENT AND CONTROL, 2024, : 2804 - 2815
  • [39] DeepRank-GNN: a graph neural network framework to learn patterns in protein-protein interfaces
    Reau, Manon
    Renaud, Nicolas
    Xue, Li C.
    Bonvin, Alexandre M. J. J.
    BIOINFORMATICS, 2023, 39 (01)
  • [40] Composition of Partially-Observable Services
    Farhat, Hikmat
    IEEE ACCESS, 2019, 7 : 2281 - 2290