Adversarial Label Poisoning Attack on Graph Neural Networks via Label Propagation

被引:1
|
作者
Liu, Ganlin [1 ]
Huang, Xiaowei [1 ]
Yi, Xinping [1 ]
机构
[1] Univ Liverpool, Liverpool, England
来源
基金
英国工程与自然科学研究理事会;
关键词
Label poisoning attack; Graph neural networks; Label propagation; Graph convolutional network;
D O I
10.1007/978-3-031-20065-6_14
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Graph neural networks (GNNs) have achieved outstanding performance in semi-supervised learning tasks with partially labeled graph structured data. However, labeling graph data for training is a challenging task, and inaccurate labels may mislead the training process to erroneous GNN models for node classification. In this paper, we consider label poisoning attacks on training data, where the labels of input data are modified by an adversary before training, to understand to what extent the state-of-the-art GNN models are resistant/vulnerable to such attacks. Specifically, we propose a label poisoning attack framework for graph convolutional networks (GCNs), inspired by the equivalence between label propagation and decoupled GCNs that separate message passing from neural networks. Instead of attacking the entire GCN models, we propose to attack solely label propagation for message passing. It turns out that a gradient-based attack on label propagation is effective and efficient towards the misleading of GCN training. More remarkably, such label attack can be topology-agnostic in the sense that the labels to be attacked can be efficiently chosen without knowing graph structures. Extensive experimental results demonstrate the effectiveness of the proposed method against state-of-the-art GCN-like models.
引用
收藏
页码:227 / 243
页数:17
相关论文
共 50 条
  • [21] Dual Adversarial Graph Neural Networks for Multi-label Cross-modal Retrieval
    Qian, Shengsheng
    Xue, Dizhan
    Zhang, Huaiwen
    Fang, Quan
    Xu, Changsheng
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 2440 - 2448
  • [22] Label Incorporated Graph Neural Networks for Text Classification
    Xin, Yuan
    Xu, Linli
    Guo, Junliang
    Li, Jiquan
    Sheng, Xin
    Zhou, Yuanyuan
    2020 25TH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION (ICPR), 2021, : 8892 - 8898
  • [23] Towards Label Position Bias in Graph Neural Networks
    Han, Haoyu
    Liu, Xiaorui
    Shi, Feng
    Torkamani, MohamadAli
    Aggarwal, Charu C.
    Tang, Jiliang
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [24] Adversarial Attack on Graph Neural Networks as An Influence Maximization Problem
    Ma, Jiaqi
    Deng, Junwei
    Mei, Qiaozhu
    WSDM'22: PROCEEDINGS OF THE FIFTEENTH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, 2022, : 675 - 685
  • [25] Task and Model Agnostic Adversarial Attack on Graph Neural Networks
    Sharma, Kartik
    Verma, Samidha
    Medya, Sourav
    Bhattacharya, Arnab
    Ranu, Sayan
    THIRTY-SEVENTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 37 NO 12, 2023, : 15091 - 15099
  • [26] Bayesian Adversarial Attack on Graph Neural Networks (Student Abstract)
    Liu, Xiao
    Zhao, Jing
    Sun, Shiliang
    THIRTY-FOURTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THE THIRTY-SECOND INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE AND THE TENTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2020, 34 : 13867 - 13868
  • [27] An Improved Label Initialization based Label Propagation Method for Detecting Graph Clusters in Complex Networks
    Chandran, Jyothimon
    Viswanatham, V. Madhu
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (05) : 766 - 776
  • [28] Imperceptible Adversarial Attack via Invertible Neural Networks
    Chen, Zihan
    Wang, Ziyue
    Huang, Jun-Jie
    Zhao, Wentao
    Liu, Xiao
    Guan, Dejian
    THIRTY-SEVENTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 37 NO 1, 2023, : 414 - 424
  • [29] LABEL PROPAGATION BASED SALIENCY DETECTION VIA GRAPH DESIGN
    Zhang, Tianhao
    Zhou, Yuan
    Huo, Shuwei
    Hou, Chunping
    2017 24TH IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2017, : 460 - 464
  • [30] Debiased Graph Neural Networks With Agnostic Label Selection Bias
    Fan, Shaohua
    Wang, Xiao
    Shi, Chuan
    Kuang, Kun
    Liu, Nian
    Wang, Bai
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, 35 (04) : 4411 - 4422