Analyzing Adversarial Vulnerabilities of Graph Lottery Tickets
1
Graph Neural Networks (GNNs): Applications
Traffic Forecasting
Drug Discovery
Recommendation
Uber Eats
Google Map
Aspirin
2
Unified Graph Sparsification (UGS): Prune the Graph and GNNs Iteratively
Prune
Iterative pruning
Sparse graph
Sparse GNNs
Chen, Tianlong, et al. "A unified lottery ticket hypothesis for graph neural networks." International conference on machine learning. PMLR, 2021.
Computation cost and inference time are reduced
3
Graph Lottery Tickets (GLTs): Maintain Model Performance After Pruning
Accuracy maintained!
Classification accuracy of the original model
Model: 2-layer Graph Convolution Network (GCN) Dataset: Cora
4
Are GLTs Vulnerable to Adversarial Attacks?
Attacked graph
Clean graph
GNNs
Attack
Sparse attacked graph
Sparse GNNs
Iterative pruning
Will GLTs be robust to the attack?
5
Outline
6
Adversarial Attacks on Graphs Degrade the Model Performance
+
=
Perturbations
Attacker’s objective:
Degrade the overall classification accuracy of the GNNs,
by maliciously adding edges to the original graph before the GNNs training.
Structural global poisoning attack:
7
Robustness of GLTs to Adversarial Attacks
Attacked graph
GNNs
Sparse attacked graph
Sparse GNNs
Iterative pruning
20%
Model: 2-layer GCN Dataset: Cora
Attack: PGD Attack Perturbation Rate: 20%
8
GLTs Perform Worse as Perturbation Rate Increases
Model: 2-layer GCN Dataset: Cora Attack: PGD Attack
Datasets: Cora, Citeseer, PubMed
GNNs:
Graph Convolution Network (GCN),
Graph Isomorphism Network (GIN),
Graph Attention Network (GAT)
Attacks: PGD, MetaAttack
Perturbation rates: 5%, 10%, 15%, 20%
The vulnerability of GLTs to adversarial attacks is common:
9
Adversarial Attacks Non-uniformly Perturb the Graphs
: Test nodes
: Train nodes
Attack
Boundary between train and test nodes
Test-Test
Train-Train
Train-Test
Train-Test
Blue pots: Original edges
Red pots: Adversarial edges
Almost not been attacked!
The edges between test nodes are not being attacked!
Li, Kuan, et al. "Revisiting graph adversarial attack and defense from a data distribution perspective." ICLR. 2022.
Clean graph
Attacked graph
Test
nodes
Train
nodes
10
Self-Training: Generate Pseudo-Labels for Test Nodes using a MLP
MLP
Train
MLP
Inference
Select
11
How to Generate Pseudo-Labels?
Data | class 0 | class 1 |
Train | 0.1 | 0.9 |
0.9 | 0.1 | |
Test | 0.4 | 0.6 |
0.2 | 0.8 | |
0.3 | 0.7 | |
0.7 | 0.3 | |
0.6 | 0.4 | |
0.8 | 0.2 |
MLP Prediction:
Select top 2
|
|
|
0.7 |
|
0.8 |
|
|
|
0 |
|
0 |
Select top 2
Selected
test nodes
|
0.8 |
0.7 |
|
|
|
|
1 |
1 |
|
|
|
Selected
test nodes
|
1 |
1 |
0 |
|
0 |
12
Replace Train Labels with Test Pseudo-Labels
Original Loss function:
CE loss
Proposed Loss function:
Pseudo-labels generated by MLP
Sparse attacked graph
Sparse GNNs
Training on the pruned graph and GNNs
Masks fixed after pruning
Labels of train nodes
Replace with
13
Improved Performance of GLTs on Attacked Graphs
Model: 2-layer GCN Dataset: Cora
Attack: PGD Attack Perturbation Rate: 20%
14
Improved Robustness of GLTs
33%
32%
41%
43%
11%
5%
14%
6%
15
Conclusion
16
Thank you.
Email: zhiyuni@usc.edu
17