Certifiable Robustness and Robust Training for Graph Convolutional Networks

被引:77
|
作者
Zuegner, Daniel [1 ]
Guennemann, Stephan [1 ]
机构
[1] Tech Univ Munich, Munich, Germany
关键词
D O I
10.1145/3292500.3330905
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent works show that Graph Neural Networks (GNNs) are highly non-robust with respect to adversarial attacks on both the graph structure and the node attributes, making their outcomes unreliable. We propose the first method for certifiable (non-)robustness of graph convolutional networks with respect to perturbations of the node attributes'. We consider the case of binary node attributes (e.g. bag-of-words) and perturbations that are L-0-bounded. If a node has been certified with our method, it is guaranteed to be robust under any possible perturbation given the attack model. Likewise, we can certify non-robustness. Finally, we propose a robust semi supervised training procedure that treats the labeled and unlabeled nodes jointly. As shown in our experimental evaluation, our method significantly improves the robustness of the GNN with only minimal effect on the predictive accuracy.
引用
收藏
页码:246 / 256
页数:11
相关论文
共 50 条
  • [41] Adversarial immunization for Certifiable Robustness on Graphs
    Tao, Shuchang
    Shen, Huawei
    Cao, Qi
    Hou, Liang
    Cheng, Xueqi
    [J]. WSDM '21: PROCEEDINGS OF THE 14TH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, 2021, : 698 - 706
  • [42] Graph Convolutional Networks for Road Networks
    Jepsen, Tobias Skovgaard
    Jensen, Christian S.
    Nielsen, Thomas Dyhre
    [J]. 27TH ACM SIGSPATIAL INTERNATIONAL CONFERENCE ON ADVANCES IN GEOGRAPHIC INFORMATION SYSTEMS (ACM SIGSPATIAL GIS 2019), 2019, : 460 - 463
  • [43] On the limitations of adversarial training for robust image classification with convolutional neural networks
    Carletti, Mattia
    Sinigaglia, Erto
    Terzi, Matteo
    Susto, Gian Antonio
    [J]. INFORMATION SCIENCES, 2024, 675
  • [44] On Robustness and Transferability of Convolutional Neural Networks
    Djolonga, Josip
    Yung, Jessica
    Tschannen, Michael
    Romijnders, Rob
    Beyer, Lucas
    Kolesnikov, Alexander
    Puigcerver, Joan
    Minderer, Matthias
    D'Amour, Alexander
    Moldovan, Dan
    Gelly, Sylvain
    Houlsby, Neil
    Zhai, Xiaohua
    Lucic, Mario
    [J]. 2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 16453 - 16463
  • [45] Robust Graph Convolutional Clustering With Adaptive Graph Learning
    Zhao, Jiayi
    Sun, Yanfeng
    Guo, Jipeng
    Gao, Junbin
    Yin, Baocai
    [J]. 2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,
  • [46] Robustness of Compressed Convolutional Neural Networks
    Wijayanto, Arie Wahyu
    Jin, Choong Jun
    Madhawa, Kaushalya
    Murata, Tsuyoshi
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 4829 - 4836
  • [47] Bayesian Inference with Certifiable Adversarial Robustness
    Wicker, Matthew
    Laurenti, Luca
    Patane, Andrea
    Chen, Zhoutong
    Zhang, Zheng
    Kwiatkowska, Marta
    [J]. 24TH INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS (AISTATS), 2021, 130
  • [48] Convolutional Normalization: Improving Deep Convolutional Network Robustness and Training
    Liu, Sheng
    Li, Xiao
    Zhai, Yuexiang
    You, Chong
    Zhu, Zhihui
    Fernandez-Granda, Carlos
    Qu, Qing
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [49] Fourier analysis on robustness of graph convolutional neural networks for skeleton-based action recognition
    Tanaka, Nariki
    Kera, Hiroshi
    Kawamoto, Kazuhiko
    [J]. Computer Vision and Image Understanding, 2024, 240
  • [50] Graph convolutional networks-based robustness optimization for scale-free Internet of Things
    Peng, Yabin
    Liu, Caixia
    Wu, Yiteng
    Liu, Shuxin
    Wang, Kai
    [J]. INTELLIGENT DATA ANALYSIS, 2022, 26 (06) : 1683 - 1701