AN-GCN

An Anonymous Graph Convolutional Network Against Edge-Perturbing Attacks

Journal Article (2024)
Author(s)

Ao Liu (Sichuan University)

Beibei Li (Sichuan University)

Tao Li (Sichuan University)

Pan Zhou (Huazhong University of Science and Technology)

Rui Wang (TU Delft - Cyber Security)

Research Group
Cyber Security
DOI related publication
https://doi.org/10.1109/TNNLS.2022.3172296
More Info
expand_more
Publication Year
2024
Language
English
Research Group
Cyber Security
Issue number
1
Volume number
35
Pages (from-to)
88-102
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Recent studies have revealed the vulnerability of graph convolutional networks (GCNs) to edge-perturbing attacks, such as maliciously inserting or deleting graph edges. However, theoretical proof of such vulnerability remains a big challenge, and effective defense schemes are still open issues. In this article, we first generalize the formulation of edge-perturbing attacks and strictly prove the vulnerability of GCNs to such attacks in node classification tasks. Following this, an anonymous GCN, named AN-GCN, is proposed to defend against edge-perturbing attacks. In particular, we present a node localization theorem to demonstrate how GCNs locate nodes during their training phase. In addition, we design a staggered Gaussian noise-based node position generator and a spectral graph convolution-based discriminator (in detecting the generated node positions). Furthermore, we provide an optimization method for the designed generator and discriminator. It is demonstrated that the AN-GCN is secure against edge-perturbing attacks in node classification tasks, as AN-GCN is developed to classify nodes without the edge information (making it impossible for attackers to perturb edges anymore). Extensive evaluations verify the effectiveness of the general edge-perturbing attack (G-EPA) model in manipulating the classification results of the target nodes. More importantly, the proposed AN-GCN can achieve 82.7% in node classification accuracy without the edge-reading permission, which outperforms the state-of-the-art GCN.

Files

AN-GCN_An_Anonymous_Graph_Conv... (pdf)
(pdf | 5.3 Mb)
- Embargo expired in 05-07-2024
License info not available