Adversarial Fairness Attacks on Graph Neural Networks
AI & Ethics, IIT Kharagpur
1
Sandipan Sikdar
About Myself
AI & Ethics, IIT Kharagpur
2
Agenda
AI & Ethics, IIT Kharagpur
3
Networks
AI & Ethics, IIT Kharagpur
4
A general model for describing and modeling complex systems
Many Data are Networks
AI & Ethics, IIT Kharagpur
5
Universal language for describing complex data
Machine Learning with Networks
AI & Ethics, IIT Kharagpur
6
Example: Node classification
AI & Ethics, IIT Kharagpur
7
Example: Link Prediction
AI & Ethics, IIT Kharagpur
8
Machine Learning
Sikdar, Textmining, SS-24
9
1.5 |
0.2 |
24 |
16 |
2.9 |
Data
Machine learning algorithm
Prediction, recommendation,….
How to fit a Network?
Sikdar, Textmining, SS-24
10
Machine learning algorithm
Prediction, recommendation,….
How to fit more complex inputs?
Sikdar, Textmining, SS-24
11
Machine learning algorithm
Prediction, recommendation,….
1.5 |
0.2 |
24 |
16 |
2.9 |
“Representation”
Automatically learn features
Feature Learning in Graphs
AI & Ethics, IIT Kharagpur
12
Efficient task-independent feature learning for machine learning in networks!
Node Embedding
AI & Ethics, IIT Kharagpur
13
Node Embedding
AI & Ethics, IIT Kharagpur
14
Need to define
Similarity function
Node Embedding
AI & Ethics, IIT Kharagpur
15
Setup
AI & Ethics, IIT Kharagpur
16
Neighborhood Aggregation
AI & Ethics, IIT Kharagpur
17
Neighborhood Aggregation
AI & Ethics, IIT Kharagpur
18
Neighborhood Aggregation
AI & Ethics, IIT Kharagpur
19
Neighborhood Aggregation
AI & Ethics, IIT Kharagpur
20
Neighborhood Aggregation
AI & Ethics, IIT Kharagpur
21
Neighborhood Aggregation
AI & Ethics, IIT Kharagpur
22
Mathematically speaking
AI & Ethics, IIT Kharagpur
23
Initial layer-0 embeddings are equal to node features
Non-linearity (ReLU, tanh)
average of neighbor’s previous layer embeddings
Training the Model
AI & Ethics, IIT Kharagpur
24
Trainable parameters
Training the Model
AI & Ethics, IIT Kharagpur
25
otherwise
Training the Model
AI & Ethics, IIT Kharagpur
26
Random distribution over all nodes
Training the Model
AI & Ethics, IIT Kharagpur
27
Training the Model
AI & Ethics, IIT Kharagpur
28
Node labels
Output node embeddings
Classifier parameters
Model design
AI & Ethics, IIT Kharagpur
29
Inductive capability
AI & Ethics, IIT Kharagpur
30
Inductive capability
AI & Ethics, IIT Kharagpur
31
Graph Convolution Networks
AI & Ethics, IIT Kharagpur
32
Basic neighborhood aggregation
GCN neighborhood aggregation
Graph Convolution Networks
AI & Ethics, IIT Kharagpur
33
Summary
AI & Ethics, IIT Kharagpur
34
Adversarial robustness
AI & Ethics, IIT Kharagpur
35
Adversarial Robustness
AI & Ethics, IIT Kharagpur
36
Poisoning Attacks
AI & Ethics, IIT Kharagpur
37
What about Networks?
AI & Ethics, IIT Kharagpur
38
What about Networks?
AI & Ethics, IIT Kharagpur
39
What about Networks?
AI & Ethics, IIT Kharagpur
40
Poisoning Attacks
AI & Ethics, IIT Kharagpur
41
Poisoning Attacks on Node Classification
AI & Ethics, IIT Kharagpur
42
Experiments: Adversarial Attacks
AI & Ethics, IIT Kharagpur
43
Experiments: Adversarial Attacks
AI & Ethics, IIT Kharagpur
44
Attack Comparison
AI & Ethics, IIT Kharagpur
45
GCN is not robust to adversarial attacks but it is somewhat robust to indirect attacks and random noise.
Adversarial Attacks on Fairness
AI & Ethics, IIT Kharagpur
46
Motivation
AI & Ethics, IIT Kharagpur
47
Example: NBA network
AI & Ethics, IIT Kharagpur
48
Example: NBA network
AI & Ethics, IIT Kharagpur
49
Attack Strategies
AI & Ethics, IIT Kharagpur
50
Attack Strategies
AI & Ethics, IIT Kharagpur
51
Attack Strategies
AI & Ethics, IIT Kharagpur
52
If we consider even a perfect classifier, it would be as fair as the original label distribution.
Attack Strategies
AI & Ethics, IIT Kharagpur
53
Attack Strategies
AI & Ethics, IIT Kharagpur
54
Attack Strategies
AI & Ethics, IIT Kharagpur
55
Attack Strategies
AI & Ethics, IIT Kharagpur
56
Attack Strategies: Summary
AI & Ethics, IIT Kharagpur
57
Results on Synthetic Graphs
AI & Ethics, IIT Kharagpur
58
On Real-world Datasets
AI & Ethics, IIT Kharagpur
59
FA-GNN degrades the fairness of various GNN models (incl. GAT, GraphSAGE, FairGNN), DD strategy is the most effective one
Are these Attacks Deceptive?
AI & Ethics, IIT Kharagpur
60
No! FA-GNN can go unnoticed if only model accuracy is monitored.
What about other Fairness Metrics?
AI & Ethics, IIT Kharagpur
61
Discussion
AI & Ethics, IIT Kharagpur
62
What followed
AI & Ethics, IIT Kharagpur
63
Summary
AI & Ethics, IIT Kharagpur
64
References
AI & Ethics, IIT Kharagpur
65