nav emailalert searchbtn searchbox tablepage yinyongbenwen piczone journalimg journalInfo journalinfonormal searchdiv searchzone qikanlogo popupnotification paper paperNew
2026, 02, No.241 84-93
面向图中毒攻击的节点级自适应特征稀疏防御策略
基金项目(Foundation): 国家社科基金(No.24XTQ005); 四川省科技厅重点研发项目(No.2023YFG0144); 四川省区域创新合作项目(No.2024YFHZ0086)
邮箱(Email):
DOI: 10.19370/j.cnki.cn10-1886/ts.2026.02.009
发布时间: 2026-04-10
出版时间: 2026-04-10
移动端阅读
摘要:

现有图神经网络(Graph Neural Networks,GNN)对抗防御多依赖对中毒图结构的净化,易破坏原始拓扑且在非攻击场景下出现性能退化。为解决此问题,本研究提出一种不改图结构的防御新方法,即节点级自适应特征稀疏防御策略——FeatGuard-Drop。首先,从GNN消息传递与特征聚合过程出发,通过自适应特征稀疏机制抑制低值、易受扰动影响的特征维度,优先保留对分类更关键的高值特征,从而阻断攻击在特征通道的传播。其次,依据节点特征的重要性与分布熵估计节点专属的稀疏强度。最后,通过低秩参数化学习可解释的特征权重矩阵,并施加平滑与稀疏正则,实现端到端联合优化。在Cora、CiteSeer、PubMed等公开数据集上的实验结果表明,本研究方法在干净图以及在不同扰动率与攻击类型下均维持较高准确率,实现了对中毒传播的有效阻断。

Abstract:

Existing adversarial defense methods for Graph Neural Networks(GNN) mainly rely on the purification of poisoned graph structures, which can easily damage the original topology and cause performance degradation in non-attack scenarios. To address this issue, a new defense method that does not modify the graph structure, namely a node-level adaptive feature sparse defense strategy(FeatGuard-Drop), was proposed in this study. Firstly, starting from the message-passing and feature-aggregation processes of GNN, an adaptive feature sparsity mechanism was employed to suppress low-value, noise-sensitive feature dimensions, while retaining high-valued features that are more critical for classification, thereby blocking the propagation of adversarial perturbations through feature channels. Then, the method estimated node-specific sparse strengths according to the importance and distribution entropy of node features. Finally, an interpretable feature-weight matrix was learned through low-rank parameterization, and smoothness and sparse regularization were imposed to achieve end-to-end joint optimization. The experimental results on public datasets, including Cora, CiteSeer, and PubMed datasets showed that FeatGuard-Drop maintained high accuracy on both clean and poisoned graphs across different perturbation rates and attack types, effectively mitigating the spread of poisoning effects.

参考文献

[1]HUANG Z,WANG Z,ZHANG R.Cascade2vec:Learning Dynamic Cascade Representation by Recurrent Graph Neural Networks[J].IEEE Access,2019,7:144800-144812.

[2]LI C,MA J,GUO X,et al.Deepcas:An End-to-End Predictor of Information Cascades[C]//Proceedings of the 26th International Conference on World Wide Web.2017:577-586.

[3]GÜNNEMANN S.Graph Neural Networks:Adversarial Robustness[M].Singapore:Springer Nature,2022:149-176.

[4]SUN L,DOU Y,YANG C,et al.Adversarial Attack and Defense on Graph Data:A Survey[J].IEEE Transactions on Knowledge and Data Engineering,2022,35(8):7693-7711.

[5]JIN W,LI Y,XU H,et al.Adversarial Attacks and Defenses on Graphs:A Review and Empirical Study[DB/OL].(2020-12-12).https://doi.org/10.48550/arXiv.2003.0065 3.

[6]WU H,WANG C,TYSHETSKIY Y O,et al.The Vulnerabilities of Graph Convolutional Networks:Stronger Attacks and Defensive Techniques[DB/OL].(2019-05-22).https://doi.org/10.48 5 5 0/arXiv.1903.01610.

[7]ENTEZARI N,AL-SAYOURI S A,DARVISHZADEH A,et al.All You Need Is Low(Rank):Defending Against Adversarial Attacks on Graphs[C]//Proceedings of the 13th International Conference on Web Search and Data Mining.2020:169-177.

[8]JIN W,MA Y,LIU X,et al.Graph Structure Learning for Robust Graph Neural Networks[C]//Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery&Data Mining.2020:66-74.

[9]ZHU D,ZHANG Z,CUI P,et al.Robust Graph Convolutional Networks Against Adversarial Attacks[C]//Proceedings of the 25 th ACM SIGKDD International Conference on Knowledge Discovery&Data Mining.2019:1399-1407.

[10]LI J,LIAO J,WU R,et al.GUARD:Graph Universal Adversarial Defense[C]//Proceedings of the 32nd ACM International Conference on Information and Knowledge Management.2023:1198-1207.

[11]ZHANG X,ZITNIK M.GNNGuard:Defending Graph Neural Networks Against Adversarial Attacks[J].Advances in Neural Information Processing Systems,2020,33:9263-9275.

[12]BIGGIO B,FUMERA G,ROLI F.Security Evaluation of Pattern Classifiers under Attack[J].IEEE Transactions on Knowledge and Data Engineering,2013,26(4):984-996.

[13]PAPERNOT N,MCDANIEL P,JHA S,et al.The Limitations of Deep Learning in Adversarial Settings[C]//Proceedings of the 2016 IEEE European Symposium on Security and Privacy.IEEE,2016:372-387.

[14]ZÜGNER D,AKBARNEJAD A,GÜNNEMANN S.Adversarial Attacks on Neural Networks for Graph Data[C]//Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery&Data Mining.2018:2847-2856.

[15]ZÜGNER D,GÜNNEMANN S.Adversarial Attacks on Graph Neural Networks via Meta Learning[DB/OL].(2024-01-28).https://doi.org/10.48550/arXiv.1902.08412.

[16]SEN P,NAMATA G,BILGIC M,et al.Collective Classification in Network Data[J].AI Magazine,2008,29(3):93-93.

[17]WU F,SOUZA A,ZHANG T,et al.Simplifying Graph Convolutional Networks[C]//Proceedings of the 36th International Conference on Machine Learning.2019:6861-6871.

基本信息:

DOI:10.19370/j.cnki.cn10-1886/ts.2026.02.009

中图分类号:TP183

引用信息:

[1]林嘉君,冯丽,彭商濂,等.面向图中毒攻击的节点级自适应特征稀疏防御策略[J].印刷与数字媒体技术研究,2026,No.241(02):84-93.DOI:10.19370/j.cnki.cn10-1886/ts.2026.02.009.

基金信息:

国家社科基金(No.24XTQ005); 四川省科技厅重点研发项目(No.2023YFG0144); 四川省区域创新合作项目(No.2024YFHZ0086)

发布时间:

2026-04-10

出版时间:

2026-04-10

检 索 高级检索