Topological Vulnerability-Based Imperceptible Node Injection Attack Against Dynamic Graph Neural Network
摘要
Dynamic graph neural networks (DGNNs) have achieved excellent performance in various real-world applications. However, the intrinsic vulnerability of DGNNs cannot be ignored, and the addition of small perturbations to the model can degrade model performance significantly. The existing attack methods against graph neural network focus on static graph field, and the direct migration to the dynamic graph is poor. In this paper, we focus on dynamic graph neural networks and first propose the Topological Vulnerability-based Node Injection Attack against Dynamic Graph Neural Network, named TVIA. TVIA firstly uses the interval selection method to locate the target moment and allocate the injection budget. Secondly, the topological vulnerability edge selection strategy is designed to determine the target nodes. Finally, a smoothing mapping function is introduced to generate adversarial features. In particular, we propose a Dynamic Homogeneity Constraint, named DHC. DHC further improves the imperceptibility of TVIA by regularizing the homogeneity distribution shift. Experiments show that when injecting only 1 \(\%\) of the total number of nodes into the graph, TVIA decreased the target DGNN link prediction Recall by 13.8 \(\%\) . In addition, TVIA combined with DHC decreases the amount of integral change to the original graph homogeneity distribution curve by 12 \(\%\) .