Skip to main navigation Skip to search Skip to main content

DeepInsight: Topology Changes Assisting Detection of Adversarial Samples on Graphs

  • Junhao Zhu (Co-first Author)
  • , Jinhuan Wang (Co-first Author)
  • , Yalu Shan
  • , Shanqing Yu
  • , Guanrong Chen
  • , Qi Xuan*
  • *Corresponding author for this work

Research output: Journal Publications and ReviewsRGC 21 - Publication in refereed journalpeer-review

Abstract

With the rapid development of artificial intelligence, a number of machine learning algorithms, such as graph neural networks (GNNs), have been proposed to facilitate network analysis or graph data mining. Although effective, recent studies show that these advanced methods may suffer from adversarial attacks, i.e., they may lose effectiveness when only a small fraction of links are unexpectedly changed. This article investigates three well-known adversarial attack methods, i.e., Nettack, Meta Attack, and GradArgmax. It is found that different attack methods have their specific attack preferences on changing the target network structures. Such attack patterns are further verified by experimental results on some real-world networks, revealing that, generally, the top-4 most important network attributes on detecting adversarial samples suffice to explain the preference of an attack method. Based on these findings, the network attributes are utilized to design machine learning models for adversarial sample detection and attack method recognition with outstanding performance. © 2022 IEEE.
Original languageEnglish
Pages (from-to)76-88
Number of pages13
JournalIEEE Transactions on Computational Social Systems
Volume11
Issue number1
Online published27 Oct 2022
DOIs
Publication statusPublished - Feb 2024

Funding

This work was supported in part by the Key R&D Program of Zhejiang under Grant 2022C01018, in part by the National Natural Science Foundation of China under Grant U21B2001 and Grant 61973273, in part by the Zhejiang Provincial Natural Science Foundation of China under Grant LR19F030001, in part by the Research and Development Center of Transport Industry of New Generation of Artificial Intelligence Technology under Grant 202102H, and in part by the Hong Kong Research Grants Council under the GRF Grant CityU11206320.

Research Keywords

  • Adversarial attack
  • adversarial defense
  • Anomaly detection
  • Detectors
  • Feature extraction
  • graph data mining
  • Image edge detection
  • network structure
  • node classification
  • Security
  • social network
  • Task analysis
  • Topology

RGC Funding Information

  • RGC-funded

Fingerprint

Dive into the research topics of 'DeepInsight: Topology Changes Assisting Detection of Adversarial Samples on Graphs'. Together they form a unique fingerprint.

Cite this