Passer à la navigation principale Passer à la recherche Passer au contenu principal

BOUNDING THE EXPECTED ROBUSTNESS OF GRAPH NEURAL NETWORKS SUBJECT TO NODE FEATURE ATTACKS

  • KTH Royal Institute of Technology

Résultats de recherche: Contribution à une conférencePapierRevue par des pairs

Résumé

Graph Neural Networks (GNNs) have demonstrated state-of-the-art performance in various graph representation learning tasks. Recently, studies revealed their vulnerability to adversarial attacks. In this work, we theoretically define the concept of expected robustness in the context of attributed graphs and relate it to the classical definition of adversarial robustness in the graph representation learning literature. Our definition allows us to derive an upper bound of the expected robustness of Graph Convolutional Networks (GCNs) and Graph Isomorphism Networks subject to node feature attacks. Building on these findings, we connect the expected robustness of GNNs to the orthonormality of their weight matrices and consequently propose an attack-independent, more robust variant of the GCN, called the Graph Convolutional Orthonormal Robust Networks (GCORNs). We further introduce a probabilistic method to estimate the expected robustness, which allows us to evaluate the effectiveness of GCORN on several real-world datasets. Experimental experiments showed that GCORN outperforms available defense methods. Our code is publicly available at: https://github.com/Sennadir/GCORN.

langue originaleAnglais
étatPublié - 1 janv. 2024
Evénement12th International Conference on Learning Representations, ICLR 2024 - Hybrid, Vienna, Autriche
Durée: 7 mai 202411 mai 2024

Une conférence

Une conférence12th International Conference on Learning Representations, ICLR 2024
Pays/TerritoireAutriche
La villeHybrid, Vienna
période7/05/2411/05/24

Empreinte digitale

Examiner les sujets de recherche de « BOUNDING THE EXPECTED ROBUSTNESS OF GRAPH NEURAL NETWORKS SUBJECT TO NODE FEATURE ATTACKS ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation