Certifiable Robustness and Robust Training for Graph Convolutional Networks

被引:77
|
作者
Zuegner, Daniel [1 ]
Guennemann, Stephan [1 ]
机构
[1] Tech Univ Munich, Munich, Germany
关键词
D O I
10.1145/3292500.3330905
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent works show that Graph Neural Networks (GNNs) are highly non-robust with respect to adversarial attacks on both the graph structure and the node attributes, making their outcomes unreliable. We propose the first method for certifiable (non-)robustness of graph convolutional networks with respect to perturbations of the node attributes'. We consider the case of binary node attributes (e.g. bag-of-words) and perturbations that are L-0-bounded. If a node has been certified with our method, it is guaranteed to be robust under any possible perturbation given the attack model. Likewise, we can certify non-robustness. Finally, we propose a robust semi supervised training procedure that treats the labeled and unlabeled nodes jointly. As shown in our experimental evaluation, our method significantly improves the robustness of the GNN with only minimal effect on the predictive accuracy.
引用
收藏
页码:246 / 256
页数:11
相关论文
共 50 条
  • [1] Certifiable Robustness of Graph Convolutional Networks under Structure Perturbations
    Zuegner, Daniel
    Guennemann, Stephan
    [J]. KDD '20: PROCEEDINGS OF THE 26TH ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2020, : 1656 - 1665
  • [2] Robust graph convolutional networks with directional graph adversarial training
    Weibo Hu
    Chuan Chen
    Yaomin Chang
    Zibin Zheng
    Yunfei Du
    [J]. Applied Intelligence, 2021, 51 : 7812 - 7826
  • [3] Robust graph convolutional networks with directional graph adversarial training
    Hu, Weibo
    Chen, Chuan
    Chang, Yaomin
    Zheng, Zibin
    Du, Yunfei
    [J]. APPLIED INTELLIGENCE, 2021, 51 (11) : 7812 - 7826
  • [4] Certifiable Robustness to Graph Perturbations
    Bojchevski, Aleksandar
    Guennemann, Stephan
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 32 (NIPS 2019), 2019, 32
  • [5] Graph Adversarial Immunization for Certifiable Robustness
    Tao, Shuchang
    Cao, Qi
    Shen, Huawei
    Wu, Yunfan
    Hou, Liang
    Cheng, Xueqi
    [J]. IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2024, 36 (04) : 1597 - 1610
  • [6] Robust Training of Graph Convolutional Networks via Latent Perturbation
    Jin, Hongwei
    Zhang, Xinhua
    [J]. MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2020, PT III, 2021, 12459 : 394 - 411
  • [7] Distributed Training of Graph Convolutional Networks
    Scardapane, Simone
    Spinelli, Indro
    Di Lorenzo, Paolo
    [J]. IEEE TRANSACTIONS ON SIGNAL AND INFORMATION PROCESSING OVER NETWORKS, 2021, 7 : 87 - 100
  • [8] Complex network effects on the robustness of graph convolutional networks
    Benjamin A. Miller
    Kevin Chan
    Tina Eliassi-Rad
    [J]. Applied Network Science, 9
  • [9] Complex network effects on the robustness of graph convolutional networks
    Miller, Benjamin A.
    Chan, Kevin
    Eliassi-Rad, Tina
    [J]. APPLIED NETWORK SCIENCE, 2024, 9 (01)
  • [10] Enhancing Robustness of Graph Convolutional Networks via Dropping Graph Connections
    Chen, Lingwei
    Li, Xiaoting
    Wu, Dinghao
    [J]. MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2020, PT III, 2021, 12459 : 412 - 428