Novel method HAO mitigates Graph Injection Attack by preserving homophily.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
Real-world graph applications, such as advertisements and product recommendations make profits based on accurately classify the label of the nodes. However, in such scenarios, there are high incentives for the adversaries to attack such graph to reduce the node classification performance. Previous work on graph adversa…
Recommender system is an important component of many web services to help users locate items that match their interests. Several studies showed that recommender systems are vulnerable to poisoning attacks, in which an attacker injects fake data to a given system such that the system makes recommendations as the attacke…
Defense against user shilling attacks in collaborative filtering using edge reweighting.
This paper improves attacks on recommender systems by solving optimization problems more precisely.
Deep neural networks have been demonstrated to be vulnerable to backdoor attacks. Specifically, by injecting a small number of maliciously constructed inputs into the training set, an adversary is able to plant a backdoor into the trained model. This backdoor can then be activated during inference by a backdoor trigger…
Deep learning models have consistently outperformed traditional machine learning models in various classification tasks, including image classification. As such, they have become increasingly prevalent in many real world applications including those where security is of great concern. Such popularity, however, may attr…
Artificial neural network (ANN) provides superior accuracy for nonlinear alternating current (AC) state estimation (SE) in smart grid over traditional methods. However, research has discovered that ANN could be easily fooled by adversarial examples. In this paper, we initiate a new study of adversarial false data injec…
Injecting adversarial examples during training, known as adversarial training, can improve robustness against one-step attacks, but not for unknown iterative attacks. To address this challenge, we first show iteratively generated adversarial images easily transfer between networks trained with the same strategy. Inspir…
Paper presents faster, robust adversarial training methods.
Lecture notes on group actions on injective spaces and Helly graphs.
Researchers develop method to protect against 'weight poisoning' attacks on pre-trained models.
Clustering algorithms have become a popular tool in computer security to analyze the behavior of malware variants, identify novel malware families, and generate signatures for antivirus systems. However, the suitability of clustering algorithms for security-sensitive settings has been recently questioned by showing tha…
With the great success of graph embedding model on both academic and industry area, the robustness of graph embedding against adversarial attack inevitably becomes a central problem in graph learning domain. Regardless of the fruitful progress, most of the current works perform the attack in a white-box fashion: they n…
Proposes a method to enhance graph models by injecting unseen connections.
Colored noise improves neural network robustness against adversarial attacks.
Finite subgraphs in flip graphs ensure unique surface embeddings.
The paper proves that certain spaces are injective and Helly graphs.
Efficiently attacks large-scale graphs without using the whole graph.
Clean-label poisoning attacks inject innocuous looking (and "correctly" labeled) poison images into training data, causing a model to misclassify a targeted image after being trained on this data. We consider transferable poisoning attacks that succeed without access to the victim network's outputs, architecture, or (i…
Many machine learning systems rely on data collected in the wild from untrusted sources, exposing the learning algorithms to data poisoning. Attackers can inject malicious data in the training dataset to subvert the learning process, compromising the performance of the algorithm producing errors in a targeted or an ind…
Data poisoning attacks can manipulate recommender systems to recommend target items.
Automorphisms and subdivisions of Helly graphs are studied, leading to explicit models and rational translation lengths.
Pro-GNN defends graph neural networks from adversarial attacks by learning graph structure.
Attack graphs are a powerful tool for security risk assessment by analysing network vulnerabilities and the paths attackers can use to compromise network resources. The uncertainty about the attacker's behaviour makes Bayesian networks suitable to model attack graphs to perform static and dynamic analysis. Previous app…
New attacks and defenses for GNNs on large graphs.
Knowledge graph embedding (KGE) is a technique for learning continuous embeddings for entities and relations in the knowledge graph.Due to its benefit to a variety of downstream tasks such as knowledge graph completion, question answering and recommendation, KGE has gained significant attention recently. Despite its ef…
We prove that, except in some low-complexity cases, every locally injective simplicial map between pants graphs is induced by a -injective embedding between the corresponding surfaces.
Graph deep learning models, such as graph convolutional networks (GCN) achieve remarkable performance for tasks on graph data. Similar to other types of deep models, graph deep learning models often suffer from adversarial attacks. However, compared with non-graph data, the discrete features, graph connections and diff…
Graph neural networks are vulnerable to adversarial attacks by manipulating graph structure.
New black-box attack method improves GNN defense without needing training data.
Adversarial examples have been shown to exist for a variety of deep learning architectures. Deep reinforcement learning has shown promising results on training agent policies directly on raw inputs such as image pixels. In this paper we present a novel study into adversarial attacks on deep reinforcement learning polic…
Indirect attacks can fool graph classifiers even with poisoned neighbors.
Bayesian optimisation method targets graph classification models against adversarial attacks.
DefenseVGAE defends graph neural networks against adversarial attacks.
FATE framework attacks graph learning models to amplify bias deceptively.
UM-GNN improves GNN robustness against poisoning attacks.
Proposes using mode connectivity to improve adversarial robustness of neural networks.
Graph embedding leaks sensitive graph properties and subgraphs.
Despite the great achievements of deep neural networks (DNNs), the vulnerability of state-of-the-art DNNs raises security concerns of DNNs in many application domains requiring high reliability.We propose the fault sneaking attack on DNNs, where the adversary aims to misclassify certain input images into any target lab…
This work explores limits of machine learning robustness against adversarial attacks.
Graph neural networks (GNNs) which apply the deep neural networks to graph data have achieved significant performance for the task of semi-supervised node classification. However, only few work has addressed the adversarial robustness of GNNs. In this paper, we first present a novel gradient-based attack method that fa…
AdvImmune improves certifiable robustness of GNNs against adversarial attacks.
Attack graphs provide compact representations of the attack paths that an attacker can follow to compromise network resources by analysing network vulnerabilities and topology. These representations are a powerful tool for security risk assessment. Bayesian inference on attack graphs enables the estimation of the risk …
GNNGuard defends Graph Neural Networks against structural perturbations.
This paper explores vulnerabilities in hierarchical graph pooling neural networks for graph classification.
Adversarial perturbations dramatically decrease the accuracy of state-of-the-art image classifiers. In this paper, we propose and analyze a simple and computationally efficient defense strategy: inject random Gaussian noise, discretize each pixel, and then feed the result into any pre-trained classifier. Theoretically,…
We prove that every injective simplicial map between flip graphs is induced by a subsurface inclusion , except in finitely many cases. This extends a result of Korkmaz--Papadopoulos which asserts that every automorphism of the flip graph of a surface without boundary is ind…