TY - JOUR
T1 - DeepInsight
T2 - Topology Changes Assisting Detection of Adversarial Samples on Graphs
AU - Zhu, Junhao
AU - Wang, Jinhuan
AU - Shan, Yalu
AU - Yu, Shanqing
AU - Chen, Guanrong
AU - Xuan, Qi
PY - 2024/2
Y1 - 2024/2
N2 - With the rapid development of artificial intelligence, a number of machine learning algorithms, such as graph neural networks (GNNs), have been proposed to facilitate network analysis or graph data mining. Although effective, recent studies show that these advanced methods may suffer from adversarial attacks, i.e., they may lose effectiveness when only a small fraction of links are unexpectedly changed. This article investigates three well-known adversarial attack methods, i.e., Nettack, Meta Attack, and GradArgmax. It is found that different attack methods have their specific attack preferences on changing the target network structures. Such attack patterns are further verified by experimental results on some real-world networks, revealing that, generally, the top-4 most important network attributes on detecting adversarial samples suffice to explain the preference of an attack method. Based on these findings, the network attributes are utilized to design machine learning models for adversarial sample detection and attack method recognition with outstanding performance. © 2022 IEEE.
AB - With the rapid development of artificial intelligence, a number of machine learning algorithms, such as graph neural networks (GNNs), have been proposed to facilitate network analysis or graph data mining. Although effective, recent studies show that these advanced methods may suffer from adversarial attacks, i.e., they may lose effectiveness when only a small fraction of links are unexpectedly changed. This article investigates three well-known adversarial attack methods, i.e., Nettack, Meta Attack, and GradArgmax. It is found that different attack methods have their specific attack preferences on changing the target network structures. Such attack patterns are further verified by experimental results on some real-world networks, revealing that, generally, the top-4 most important network attributes on detecting adversarial samples suffice to explain the preference of an attack method. Based on these findings, the network attributes are utilized to design machine learning models for adversarial sample detection and attack method recognition with outstanding performance. © 2022 IEEE.
KW - Adversarial attack
KW - adversarial defense
KW - Anomaly detection
KW - Detectors
KW - Feature extraction
KW - graph data mining
KW - Image edge detection
KW - network structure
KW - node classification
KW - Security
KW - social network
KW - Task analysis
KW - Topology
UR - https://www.scopus.com/pages/publications/85141441764
UR - https://www.scopus.com/record/pubmetrics.uri?eid=2-s2.0-85141441764&origin=recordpage
U2 - 10.1109/TCSS.2022.3213329
DO - 10.1109/TCSS.2022.3213329
M3 - RGC 21 - Publication in refereed journal
SN - 2329-924X
VL - 11
SP - 76
EP - 88
JO - IEEE Transactions on Computational Social Systems
JF - IEEE Transactions on Computational Social Systems
IS - 1
ER -