Everything Perturbed All at Once: Enabling Differentiable Graph Attacks

3Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.
Get full text

Abstract

While revolutionizing social networks, recommendation systems, and online web services, graph neural networks are vulnerable to adversarial attacks. Recent state-of-the-art adversarial attacks rely on gradient-based meta-learning to selectively perturb a single edge with the highest attack score until they reach the budget constraint. While effective in identifying vulnerable links, these methods are plagued by high computational costs. By leveraging continuous relaxation and parameterization of the graph structure, we propose a novel attack method – DGA to efficiently generate effective attacks and meanwhile eliminate the need for costly retraining. Compared to the state-of-the-art, DGA achieves nearly equivalent attack performance with 6 times less training time and 11 times smaller GPU memory footprint on different benchmark datasets. Additionally, we provide extensive experimental analyses of the transferability of DGA among different graph models, as well as its robustness against widely-used defense mechanisms.

Cite

CITATION STYLE

APA

Liu, H., Wang, B., Wang, J., Dong, X., Yang, T., & Caverlee, J. (2024). Everything Perturbed All at Once: Enabling Differentiable Graph Attacks. In WWW 2024 Companion - Companion Proceedings of the ACM Web Conference (pp. 485–488). Association for Computing Machinery, Inc. https://doi.org/10.1145/3589335.3651501

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free