Bandits for Structure Perturbation-based Black-box Attacks to Graph Neural Networks with Theoretical Guarantees

被引:3
|
作者
Wang, Binghui [1 ]
Li, Youqi [2 ,3 ]
Zhou, Pan [4 ]
机构
[1] IIT, Dept Comp Sci, Chicago, IL 60616 USA
[2] Beijing Inst Technol, Sch Cyberspace Sci & Technol, Beijing, Peoples R China
[3] Beijing Inst Technol, Sch Comp Sci, Beijing, Peoples R China
[4] Huazhong Univ Sci & Technol, Hubei Engn Res Ctr Big Data Secur, Sch Cyber Sci & Engn, Wuhan, Peoples R China
基金
中国博士后科学基金; 中国国家自然科学基金;
关键词
D O I
10.1109/CVPR52688.2022.01302
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Graph neural networks (GNNs) have achieved state-of-the-art performance in many graph-based tasks such as node classification and graph classification. However, many recent works have demonstrated that an attacker can mislead GNN models by slightly perturbing the graph structure. Existing attacks to GNNs are either under the less practical threat model where the attacker is assumed to access the GNN model parameters, or under the practical black-box threat model but consider perturbing node features that are shown to be not enough effective. In this paper, we aim to bridge this gap and consider black-box attacks to GNNs with structure perturbation as well as with theoretical guarantees. We propose to address this challenge through bandit techniques. Specifically, we formulate our attack as an online optimization with bandit feedback. This original problem is essentially NP-hard due to the fact that perturbing the graph structure is a binary optimization problem. We then propose an online attack based on bandit optimization which is proven to be sublinear to the query number T, i.e., O(root NT3/4) where N is the number of nodes in the graph. Finally, we evaluate our proposed attack by conducting experiments over multiple datasets and GNN models. The experimental results on various citation graphs and image graphs show that our attack is both effective and efficient.
引用
收藏
页码:13369 / 13377
页数:9
相关论文
共 50 条
  • [41] NeuralBO: A black-box optimization algorithm using deep neural networks
    Dat, Phan-Trong
    Hung, Tran-The
    Gupta, Sunil
    [J]. NEUROCOMPUTING, 2023, 559
  • [42] Query efficient black-box adversarial attack on deep neural networks
    Bai, Yang
    Wang, Yisen
    Zeng, Yuyuan
    Jiang, Yong
    Xia, Shu-Tao
    [J]. PATTERN RECOGNITION, 2023, 133
  • [43] COLORED INFORMATION FROM A BLACK-BOX - VALIDATION AND EVALUATION OF NEURAL NETWORKS
    KATEMAN, G
    SMITS, JRM
    [J]. ANALYTICA CHIMICA ACTA, 1993, 277 (02) : 179 - 188
  • [44] SOTER: Guarding Black-box Inference for General Neural Networks at the Edge
    Shen, Tianxiang
    Qi, Ji
    Jiang, Jianyu
    Wang, Xian
    Wen, Siyuan
    Chen, Xusheng
    Zhao, Shixiong
    Wang, Sen
    Chen, Li
    Luo, Xiapu
    Zhang, Fengwei
    Cui, Heming
    [J]. PROCEEDINGS OF THE 2022 USENIX ANNUAL TECHNICAL CONFERENCE, 2022, : 723 - 737
  • [45] Cyclical Adversarial Attack Pierces Black-box Deep Neural Networks
    Huang, Lifeng
    Wei, Shuxin
    Gao, Chengying
    Liu, Ning
    [J]. PATTERN RECOGNITION, 2022, 131
  • [46] Automated Side-Channel Attacks using Black-Box Neural Architecture Search
    Gupta, Pritha
    Drees, Jan Peter
    Huellermeier, Eyke
    [J]. 18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,
  • [47] Topic-oriented Adversarial Attacks against Black-box Neural Ranking Models
    Liu, Yu-An
    Zhang, Ruqing
    Guo, Jiafeng
    de Rijke, Maarten
    Chen, Wei
    Fan, Yixing
    Cheng, Xueqi
    [J]. PROCEEDINGS OF THE 46TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, SIGIR 2023, 2023, : 1700 - 1709
  • [48] Multi-granular Adversarial Attacks against Black-box Neural Ranking Models
    Liu, Yu-An
    Zhang, Ruqing
    Guo, Jiafeng
    de Rijke, Maarten
    Fan, Yixing
    Cheng, Xueqi
    [J]. PROCEEDINGS OF THE 47TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, SIGIR 2024, 2024, : 1391 - 1400
  • [49] Template based black-box optimization of dynamic neural fields
    Fix, Jeremy
    [J]. NEURAL NETWORKS, 2013, 46 : 40 - 49
  • [50] Black-Box Modeling of DC-DC Converters Based on Wavelet Convolutional Neural Networks
    Rojas-Duenas, Gabriel
    Riba, Jordi-Roger
    Moreno-Eguilaz, Manuel
    [J]. IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2021, 70