Hypergraph neural networks (HGNN) have shown superior performance in various deep learning tasks, leveraging the high-order representation ability to formulate complex correlations among data by connecting two or more nodes through hyperedge modeling. Despite the well-studied adversarial attacks on Graph Neural Networks (GNN), there is few study on adversarial attacks against HGNN, which leads to a threat to the safety of HGNN applications. In this paper, we introduce HyperAttack, the first white-box adversarial attack framework against hypergraph neural networks. HyperAttack conducts a white-box structure attack by perturbing hyperedge link status towards the target node with the guidance of both gradients and integrated gradients. We evaluate HyperAttack on the widely-used Cora and PubMed datasets and three hypergraph neural networks with typical hypergraph modeling techniques. Compared to state-of-the-art white-box structural attack methods for GNN, HyperAttack achieves a 10-20X improvement in time efficiency while also increasing attack success rates by 1.3%-3.7%. The results show that HyperAttack can achieve efficient adversarial attacks that balance effectiveness and time costs.
翻译:超图神经网络(HGNN)凭借其高阶表示能力,通过超边建模连接两个及以上节点以刻画数据间复杂关联,已在多种深度学习任务中展现出优越性能。尽管针对图神经网络(GNN)的对抗性攻击已得到充分研究,但面向HGNN的对抗性攻击研究仍十分匮乏,这给HGNN应用的安全性带来潜在威胁。本文提出HyperAttack——首个针对超图神经网络的白盒对抗性攻击框架。该方法通过扰动目标节点的超边连接状态,在梯度与积分梯度的联合引导下实施白盒结构攻击。我们在广泛使用的Cora和PubMed数据集上,针对三种采用典型超图建模技术的超图神经网络进行了评估。与当前最优的GNN白盒结构攻击方法相比,HyperAttack在实现1.3%-3.7%攻击成功率提升的同时,将时间效率提升10-20倍。实验结果表明,HyperAttack能够实现兼顾有效性与时间成本的高效对抗性攻击。