Adversarial Label Poisoning Attack on Graph Neural Networks via Label Propagation

被引:1
|
作者
Liu, Ganlin [1 ]
Huang, Xiaowei [1 ]
Yi, Xinping [1 ]
机构
[1] Univ Liverpool, Liverpool, England
来源
基金
英国工程与自然科学研究理事会;
关键词
Label poisoning attack; Graph neural networks; Label propagation; Graph convolutional network;
D O I
10.1007/978-3-031-20065-6_14
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Graph neural networks (GNNs) have achieved outstanding performance in semi-supervised learning tasks with partially labeled graph structured data. However, labeling graph data for training is a challenging task, and inaccurate labels may mislead the training process to erroneous GNN models for node classification. In this paper, we consider label poisoning attacks on training data, where the labels of input data are modified by an adversary before training, to understand to what extent the state-of-the-art GNN models are resistant/vulnerable to such attacks. Specifically, we propose a label poisoning attack framework for graph convolutional networks (GCNs), inspired by the equivalence between label propagation and decoupled GCNs that separate message passing from neural networks. Instead of attacking the entire GCN models, we propose to attack solely label propagation for message passing. It turns out that a gradient-based attack on label propagation is effective and efficient towards the misleading of GCN training. More remarkably, such label attack can be topology-agnostic in the sense that the labels to be attacked can be efficiently chosen without knowing graph structures. Extensive experimental results demonstrate the effectiveness of the proposed method against state-of-the-art GCN-like models.
引用
收藏
页码:227 / 243
页数:17
相关论文
共 50 条
  • [41] Adversarial Label Flips Attack on Support Vector Machines
    Xiao, Han
    Xiao, Huang
    Eckert, Claudia
    20TH EUROPEAN CONFERENCE ON ARTIFICIAL INTELLIGENCE (ECAI 2012), 2012, 242 : 870 - 875
  • [42] Clean-label attack based on negative afterimage on neural networks
    Zang, Liguang
    Li, Yuancheng
    INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2024, : 449 - 460
  • [43] Deep graph fusion for graph based label propagation
    Saeedeh, Bahrami
    Bosaghzadeh, Alireza
    2017 10TH IRANIAN CONFERENCE ON MACHINE VISION AND IMAGE PROCESSING (MVIP), 2017, : 149 - 153
  • [44] Detecting overlapping communities in networks via dominant label propagation
    孙鹤立
    黄健斌
    田勇强
    宋擒豹
    刘怀亮
    Chinese Physics B, 2015, 24 (01) : 555 - 563
  • [45] Detecting overlapping communities in networks via dominant label propagation
    Sun He-Li
    Huang Jian-Bin
    Tian Yong-Qiang
    Song Qin-Bao
    Liu Huai-Liang
    CHINESE PHYSICS B, 2015, 24 (01)
  • [46] Community detection in dynamic networks via adaptive label propagation
    Han, Jihui
    Li, Wei
    Zhao, Longfeng
    Su, Zhu
    Zou, Yijiang
    Deng, Weibing
    PLOS ONE, 2017, 12 (11):
  • [47] Unsupervised Graph Poisoning Attack via Contrastive Loss Back-propagation
    Zhang, Sixiao
    Chen, Hongxu
    Sun, Xiangguo
    Li, Yicong
    Xu, Guandong
    PROCEEDINGS OF THE ACM WEB CONFERENCE 2022 (WWW'22), 2022, : 1322 - 1330
  • [48] Unsupervised Graph Poisoning Attack via Contrastive Loss Back-propagation
    Zhang, Sixiao
    Chen, Hongxu
    Sun, Xiangguo
    Li, Yicong
    Xu, Guandong
    WWW 2022 - Proceedings of the ACM Web Conference 2022, 2022, : 1322 - 1330
  • [49] Integrating Multi-Label Contrastive Learning With Dual Adversarial Graph Neural Networks for Cross-Modal Retrieval
    Qian, Shengsheng
    Xue, Dizhan
    Fang, Quan
    Xu, Changsheng
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2023, 45 (04) : 4794 - 4811
  • [50] Data Poisoning Attack by Label Flipping on SplitFed Learning
    Gajbhiye, Saurabh
    Singh, Priyanka
    Gupta, Shaifu
    RECENT TRENDS IN IMAGE PROCESSING AND PATTERN RECOGNITION, RTIP2R 2022, 2023, 1704 : 391 - 405