Adversarial Attack and Training for Graph Convolutional Networks Using Focal Loss-Projected Momentum

Mohammed Aburidi, Roummel F. Marcia · 2024

Graph Neural Networks (GNNs) have exhibited remarkable success in various applications such as social and telecommunication networks, yet their vulnerability to adversarial attacks poses significant risks in security-sensitive do-mains. Imperceptible perturbations in graphs can lead to severe performance degradation, necessitating robust GNN models for safety and privacy in critical applications. We address this challenge by proposing optimization-based attacks on GNNs, specifically focusing on modifying graph structures. Our approach leverages convex relaxation and projected momentum optimization. Introducing the focal loss as an attack criterion, we generate perturbations by minimizing a constrained optimization problem. Evaluating on node classification tasks, our attacks outperform state-of-the-art methods under the same perturbation budget, highlighting the effectiveness of our approach. This work contributes to enhancing the robustness of GNNs against adversarial manipulations in real-world scenarios.

Read the paper · More papers on PaperTik