3.8 Proceedings Paper

Robust Graph Convolutional Networks Against Adversarial Attacks

出版社

ASSOC COMPUTING MACHINERY
DOI: 10.1145/3292500.3330851

关键词

Graph Convolutional Networks; Robustness; Adversarial Attacks; Deep Learning

资金

  1. Beijing Academy of Artificial Intelligence (BAAI)
  2. National Program on Key Basic Research Project [2015CB352300]
  3. National Natural Science Foundation of China Major Project [U1611461]
  4. National Natural Science Foundation of China [61772304, 61521002, 61531006]
  5. Tsinghua-Tencent Joint Laboratory for Internet Innovation Technology
  6. Young Elite Scientist Sponsorship Program by CAST

向作者/读者索取更多资源

Graph Convolutional Networks (GCNs) are an emerging type of neural network model on graphs which have achieved state-of-the-art performance in the task of node classification. However, recent studies show that GCNs are vulnerable to adversarial attacks, i.e. small deliberate perturbations in graph structures and node attributes, which poses great challenges for applying GCNs to real world applications. How to enhance the robustness of GCNs remains a critical open problem. To address this problem, we propose Robust GCN (RGCN), a novel model that fortifies GCNs against adversarial attacks. Specifically, instead of representing nodes as vectors, our method adopts Gaussian distributions as the hidden representations of nodes in each convolutional layer. In this way, when the graph is attacked, our model can automatically absorb the effects of adversarial changes in the variances of the Gaussian distributions. Moreover, to remedy the propagation of adversarial attacks in GCNs, we propose a variance-based attention mechanism, i.e. assigning different weights to node neighborhoods according to their variances when performing convolutions. Extensive experimental results demonstrate that our proposed method can effectively improve the robustness of GCNs. On three benchmark graphs, our RGCN consistently shows a substantial gain in node classification accuracy compared with state-of-the-art GCNs against various adversarial attack strategies.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

3.8
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据