| 引用本文: | 初旭,马辛宇,林阳,王鑫,王亚沙,朱文武,梅宏.面向鲁棒图结构防御的过参数化图神经网络.软件学报,2024,35(8):3878-3896 |
| |
|
| |
|
|
| 本文已被:浏览 1771次 下载 2643次 |
 码上扫一扫! |
|
|
| 面向鲁棒图结构防御的过参数化图神经网络 |
|
初旭1, 马辛宇2,3, 林阳2,3, 王鑫1,4, 王亚沙3,5, 朱文武1,4, 梅宏3
|
|
1.清华大学 计算机科学与技术系, 北京 100084;2.北京大学 计算机学院, 北京 100871;3.高可信软件技术教育部重点实验室 (北京大学), 北京 100871;4.清华大学 北京信息科学与技术国家研究中心, 北京 102206;5.北京大学 软件工程国家工程研究中心, 北京 100871
|
|
| 摘要: |
| 图数据在现实应用中普遍存在, 图神经网络(GNN)被广泛应用于分析图数据, 然而 GNN的性能会被图结构上的对抗攻击剧烈影响. 应对图结构上的对抗攻击, 现有的防御方法一般基于图内聚先验进行低秩图结构重构. 但是现有的图结构对抗防御方法无法自适应秩真值进行低秩图结构重构, 同时低秩图结构与下游任务语义存在错配. 为了解决以上问题, 基于过参数化的隐式正则效应提出过参数化图神经网络(OPGNN)方法, 并形式化证明所提方法可以自适应求解低秩图结构, 同时证明节点深层表征上的过参数化残差链接可以有效解决语义错配. 在真实数据集上的实验结果表明, OPGNN方法相对于现有基线方法具有更好的鲁棒性, 同时, OPGNN 方法框架在不同的图神经网络骨干上如 GCN、APPNP 和 GPRGNN 上显著有效. |
| 关键词: 图节点半监督分类 图结构对抗防御 过参数化 隐式正则化 图神经网络 |
| DOI:10.13328/j.cnki.jos.007065 |
| 分类号:TP18 |
| 基金项目:国家科技攻关计划 (2020AAA0106300); 国家自然科学基金 (62250008, 62222209, 62102222, 61936011); 北京信息科学与技术国家研究中心基金 (BNR2023RC01003) |
|
| Over-parameterized Graph Neural Network Towards Robust Graph Structure Defending |
|
CHU Xu1, MA Xin-Yu2,3, LIN Yang2,3, WANG Xin1,4, WANG Ya-Sha3,5, ZHU Wen-Wu1,4, MEI Hong3
|
|
1.Department of Computer Science and Technology, Tsinghua University, Beijing 100084, China;2.School of Computer Science, Peking University, Beijing 100871, China;3.Key Laboratory of High Confidence Software Technologies (Peking University ), Ministry of Education, Beijing 100871, China;4.Beijing National Research Center for Information Science and Technology, Tsinghua University, Beijing 102206, China;5.National Engineering Research Center for Software Engineering, Peking University, Beijing 100871, China
|
| Abstract: |
| Graph data is ubiquitous in real-world applications, and graph neural networks (GNNs) have been widely used in graph data analysis. However, the performance of GNNs can be severely impacted by adversarial attacks on graph structures. Existing defense methods against adversarial attacks generally rely on low-rank graph structure reconstruction based on graph community preservation priors. However, existing graph structure adversarial defense methods cannot adaptively seek the true low-rank value for graph structure reconstruction, and low-rank graph structures are semantically mismatched with downstream tasks. To address these problems, this study proposes the over-parameterized graph neural network (OPGNN) method based on the implicit regularization effect of over-parameterization. In addition, it formally proves that this method can adaptively solve the low-rank graph structure problem and also proves that over-parameterized residual links on node deep representations can effectively address semantic mismatch. Experimental results on real datasets demonstrate that the OPGNN method is more robust than existing baseline methods, and the OPGNN framework is notably effective on different graph neural network backbones such as GCN, APPNP, and GPRGNN. |
| Key words: semi-supervised classification of graph nodes graph structure adversarial defense over-parameterization implicit regularization graph neural network (GNN) |
|
|
|
|