• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

D4A:针对不可知对抗攻击的高效防御。

D4A: An efficient and effective defense across agnostic adversarial attacks.

作者信息

Li Xianxian, Gan Zeming, Bai Yan, Su Linlin, Li De, Wang Jinyan

机构信息

Key Lab of Education Blockchain and Intelligent Technology, Ministry of Education, Guangxi Normal University, Guilin, China; Guangxi Key Lab of Multi-source Information Mining and Security, Guangxi Normal University, Guilin, China; School of Computer Science and Engineering, Guangxi Normal University, Guilin, China.

School of Computer Science and Engineering, Guangxi Normal University, Guilin, China.

出版信息

Neural Netw. 2025 Mar;183:106938. doi: 10.1016/j.neunet.2024.106938. Epub 2024 Nov 26.

DOI:10.1016/j.neunet.2024.106938
PMID:39615452
Abstract

Recent studies show that Graph Neural Networks (GNNs) are vulnerable to structure adversarial attacks, which draws attention to adversarial defenses in graph data. Previous defenses designed heuristic defense strategies for specific attacks or graph properties, and are no longer sufficiently robust across all these attacks. To address this problem, we discuss the abnormal behaviors of GNNs in structure perturbations from a posterior distribution perspective. We suggest that the structural vulnerability of GNNs stems from their dependence on local graph smoothing, which can also lead to unfitting - a first-found phenomenon specific to the graph domain. We demonstrate that abnormal behaviors, except for unfitting, can attribute to a posterior distribution shift. To intrinsically prevent the occurrence of abnormal behaviors, we first propose smooth-less message passing to enhance the tolerance with respect to structure perturbations, while significantly mitigating the unfitting. We also propose the distribution shift constraint to restrict other abnormal behaviors of our model. Our approach is evaluated on six different datasets across over four kinds of attacks and compared to 11 representative baselines. The experimental results show that our method improves the defense performance across various attacks, and provides a great trade-off between accuracy and adversarial robustness.

摘要

最近的研究表明,图神经网络(GNN)容易受到结构对抗攻击,这引发了对图数据中对抗防御的关注。先前的防御措施针对特定攻击或图属性设计启发式防御策略,在面对所有这些攻击时不再具有足够的鲁棒性。为了解决这个问题,我们从后验分布的角度讨论了GNN在结构扰动中的异常行为。我们认为,GNN的结构脆弱性源于它们对局部图平滑的依赖,这也可能导致不匹配——一种在图领域首次发现的特定现象。我们证明,除了不匹配之外,异常行为还可归因于后验分布的偏移。为了从本质上防止异常行为的发生,我们首先提出无平滑消息传递,以增强对结构扰动的容忍度,同时显著减轻不匹配。我们还提出了分布偏移约束,以限制我们模型的其他异常行为。我们的方法在六种不同数据集上针对四种以上攻击进行了评估,并与11个有代表性的基线进行了比较。实验结果表明,我们的方法提高了对各种攻击的防御性能,并在准确性和对抗鲁棒性之间实现了很好的权衡。

相似文献

1
D4A: An efficient and effective defense across agnostic adversarial attacks.D4A:针对不可知对抗攻击的高效防御。
Neural Netw. 2025 Mar;183:106938. doi: 10.1016/j.neunet.2024.106938. Epub 2024 Nov 26.
2
A Dual Robust Graph Neural Network Against Graph Adversarial Attacks.一种对抗图对抗攻击的双重鲁棒图神经网络。
Neural Netw. 2024 Jul;175:106276. doi: 10.1016/j.neunet.2024.106276. Epub 2024 Mar 28.
3
Spectral adversarial attack on graph via node injection.基于节点注入的图的频谱对抗攻击。
Neural Netw. 2025 Apr;184:107046. doi: 10.1016/j.neunet.2024.107046. Epub 2025 Jan 1.
4
DropAGG: Robust Graph Neural Networks via Drop Aggregation.DropAGG:通过随机聚合的鲁棒图神经网络。
Neural Netw. 2023 Jun;163:65-74. doi: 10.1016/j.neunet.2023.03.022. Epub 2023 Mar 29.
5
Evaluating and enhancing the robustness of vision transformers against adversarial attacks in medical imaging.评估并增强视觉Transformer在医学成像中抵御对抗攻击的鲁棒性。
Med Biol Eng Comput. 2025 Mar;63(3):673-690. doi: 10.1007/s11517-024-03226-5. Epub 2024 Oct 25.
6
Auto encoder-based defense mechanism against popular adversarial attacks in deep learning.基于自动编码器的深度学习中流行对抗攻击防御机制。
PLoS One. 2024 Oct 21;19(10):e0307363. doi: 10.1371/journal.pone.0307363. eCollection 2024.
7
Beyond smoothness: A general optimization framework for graph neural networks with negative Laplacian regularization.超越平滑性:具有负拉普拉斯正则化的图神经网络的通用优化框架。
Neural Netw. 2024 Dec;180:106704. doi: 10.1016/j.neunet.2024.106704. Epub 2024 Sep 16.
8
Path reliability-based graph attention networks.基于路径可靠性的图注意力网络
Neural Netw. 2023 Feb;159:153-160. doi: 10.1016/j.neunet.2022.11.021. Epub 2022 Nov 19.
9
Contrastive Graph Representation Learning with Adversarial Cross-View Reconstruction and Information Bottleneck.基于对抗性跨视图重建和信息瓶颈的对比图表示学习
Neural Netw. 2025 Apr;184:107094. doi: 10.1016/j.neunet.2024.107094. Epub 2025 Jan 9.
10
A Lightweight Method for Defense Graph Neural Networks Adversarial Attacks.一种用于防御图神经网络对抗攻击的轻量级方法。
Entropy (Basel). 2022 Dec 25;25(1):39. doi: 10.3390/e25010039.