1 of 17

Analyzing Adversarial Vulnerabilities of Graph Lottery Tickets

 

1

2 of 17

Graph Neural Networks (GNNs): Applications

Traffic Forecasting

Drug Discovery

Recommendation

Uber Eats

Google Map

Aspirin

2

3 of 17

Unified Graph Sparsification (UGS): Prune the Graph and GNNs Iteratively

Prune

Iterative pruning

Sparse graph

Sparse GNNs

Chen, Tianlong, et al. "A unified lottery ticket hypothesis for graph neural networks." International conference on machine learning. PMLR, 2021.

 

Computation cost and inference time are reduced

3

4 of 17

Graph Lottery Tickets (GLTs): Maintain Model Performance After Pruning

Accuracy maintained!

Classification accuracy of the original model

Model: 2-layer Graph Convolution Network (GCN) Dataset: Cora

4

5 of 17

Are GLTs Vulnerable to Adversarial Attacks?

Attacked graph

Clean graph

GNNs

Attack

Sparse attacked graph

Sparse GNNs

Iterative pruning

Will GLTs be robust to the attack?

5

6 of 17

Outline

  • Analyzing Adversarial Robustness of GLTs

  • Improving the Robustness of GLTs

  • Evaluation

  • Conclusion

6

7 of 17

Adversarial Attacks on Graphs Degrade the Model Performance

+

=

 

Perturbations

 

Attacker’s objective:

Degrade the overall classification accuracy of the GNNs,

by maliciously adding edges to the original graph before the GNNs training.

Structural global poisoning attack:

 

7

8 of 17

Robustness of GLTs to Adversarial Attacks

Attacked graph

GNNs

Sparse attacked graph

Sparse GNNs

Iterative pruning

20%

Model: 2-layer GCN Dataset: Cora

Attack: PGD Attack Perturbation Rate: 20%

8

9 of 17

GLTs Perform Worse as Perturbation Rate Increases

Model: 2-layer GCN Dataset: Cora Attack: PGD Attack

Datasets: Cora, Citeseer, PubMed

GNNs:

Graph Convolution Network (GCN),

Graph Isomorphism Network (GIN),

Graph Attention Network (GAT)

Attacks: PGD, MetaAttack

Perturbation rates: 5%, 10%, 15%, 20%

The vulnerability of GLTs to adversarial attacks is common:

9

10 of 17

Adversarial Attacks Non-uniformly Perturb the Graphs

: Test nodes

: Train nodes

Attack

 

Boundary between train and test nodes

Test-Test

Train-Train

Train-Test

Train-Test

Blue pots: Original edges

Red pots: Adversarial edges

Almost not been attacked!

The edges between test nodes are not being attacked!

Li, Kuan, et al. "Revisiting graph adversarial attack and defense from a data distribution perspective." ICLR. 2022.

Clean graph

Attacked graph

Test

nodes

Train

nodes

10

11 of 17

Self-Training: Generate Pseudo-Labels for Test Nodes using a MLP

MLP

 

Train

MLP

 

Inference

 

Select

11

12 of 17

How to Generate Pseudo-Labels?

Data

class

0

class

1

Train

0.1

0.9

0.9

0.1

Test

0.4

0.6

0.2

0.8

0.3

0.7

0.7

0.3

0.6

0.4

0.8

0.2

MLP Prediction:

Select top 2

0.7

0.8

 

0

0

Select top 2

Selected

test nodes

0.8

0.7

 

1

1

Selected

test nodes

 

1

1

0

0

12

13 of 17

Replace Train Labels with Test Pseudo-Labels

Original Loss function:

CE loss

Proposed Loss function:

Pseudo-labels generated by MLP

Sparse attacked graph

Sparse GNNs

Training on the pruned graph and GNNs

Masks fixed after pruning

Labels of train nodes

Replace with

13

14 of 17

Improved Performance of GLTs on Attacked Graphs

Model: 2-layer GCN Dataset: Cora

Attack: PGD Attack Perturbation Rate: 20%

14

15 of 17

Improved Robustness of GLTs

33%

32%

41%

43%

11%

5%

14%

6%

15

16 of 17

Conclusion

  • The performance of GLTs is significantly affected by global structural poisoning attacks.
  • Adversarial attacks (PGD and MetaAttack) non-uniformly perturb the graph structure.
  • Clean neighborhood information of test nodes helps improve the robustness of GLTs effectively.

16

17 of 17

Thank you.

17