AI Chat Paper
Note: Please note that the following content is generated by AMiner AI. SciOpen does not take any responsibility related to this content.
{{lang === 'zh_CN' ? '文章概述' : 'Summary'}}
{{lang === 'en_US' ? '中' : 'Eng'}}
Chat more with AI
Article Link
Collect
Submit Manuscript
Show Outline
Outline
Show full outline
Hide outline
Outline
Show full outline
Hide outline
Regular Paper

Towards Defense Against Adversarial Attacks on Graph Neural Networks via Calibrated Co-Training

College of Computer, National University of Defense Technology, Changsha 410073, China
College of Systems Engineering, National University of Defense Technology, Changsha 410073, China
Show Author Information

Abstract

Graph neural networks (GNNs) have achieved significant success in graph representation learning. Nevertheless, the recent work indicates that current GNNs are vulnerable to adversarial perturbations, in particular structural perturbations. This, therefore, narrows the application of GNN models in real-world scenarios. Such vulnerability can be attributed to the model's excessive reliance on incomplete data views (e.g., graph convolutional networks (GCNs) heavily rely on graph structures to make predictions). By integrating the information from multiple perspectives, this problem can be effectively addressed, and typical views of graphs include the node feature view and the graph structure view. In this paper, we propose C2oG, which combines these two typical views to train sub-models and fuses their knowledge through co-training. Due to the orthogonality of the views, sub-models in the feature view tend to be robust against the perturbations targeted at sub-models in the structure view. C2oG allows sub-models to correct one another mutually and thus enhance the robustness of their ensembles. In our evaluations, C2oG significantly improves the robustness of graph models against adversarial attacks without sacrificing their performance on clean datasets.

Electronic Supplementary Material

Download File(s)
jcst-37-5-1161-Highlights.pdf (100.3 KB)

References

【1】
【1】
 
 
Journal of Computer Science and Technology
Pages 1161-1175

{{item.num}}

Comments on this article

Go to comment

< Back to all reports

Review Status: {{reviewData.commendedNum}} Commended , {{reviewData.revisionRequiredNum}} Revision Required , {{reviewData.notCommendedNum}} Not Commended Under Peer Review

Review Comment

Close
Close
Cite this article:
Wu X-G, Wu H-J, Zhou X, et al. Towards Defense Against Adversarial Attacks on Graph Neural Networks via Calibrated Co-Training. Journal of Computer Science and Technology, 2022, 37(5): 1161-1175. https://doi.org/10.1007/s11390-022-2129-2

1116

Views

11

Crossref

9

Web of Science

10

Scopus

1

CSCD

Received: 31 December 2021
Accepted: 27 September 2022
Published: 30 September 2022
©Institute of Computing Technology, Chinese Academy of Sciences 2022