Heterogeneous graph neural network anti-attack method based on graph entropy
By introducing graph entropy concepts and adaptive candidate homologous perturbation node selection strategies into heterogeneous graph neural networks, the problem that the heterogeneous graph neural network adversarial attack method in the existing technology is not able to effectively deal with complex node types and edge relationships, and efficient and robust attack performance and generalization capabilities are achieved.
Patent Information
- Application Number
- CN202510075785.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-17
- Publication Date
- 2025-05-09
AI Technical Summary
The existing heterogeneous graph neural network adversarial attack methods cannot effectively deal with the complex node types and edge relationships in heterogeneous graphs, resulting in low attack success rate or inconsistent attack model.
By introducing the concept of graph entropy, combining the two information concepts of node entropy and structural entropy, we accurately locate key nodes and edges that have a greater impact on model prediction, and adopt an adaptive candidate homologous perturbation node selection strategy to design an efficient perturbation generation method based on graph entropy.
It improves attack performance, reduces computational costs, enhances generalization capabilities, can more comprehensively evaluate the robustness of heterogeneous graph neural networks, avoids overfitting, and improves the universality and robustness of attack performance.
Smart Images

Figure CN119962620A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the intersection of artificial intelligence and network security, and specifically relates to the technical fields of heterogeneous graph neural networks (HGNNs) and adversarial attacks. The present invention proposes an adversarial attack method based on graph entropy for heterogeneous graph neural networks, aiming to study the robustness of heterogeneous graphs and their security issues in adversarial environments. Background Art
[0002] Heterogeneous graph neural networks, as an effective tool for processing heterogeneous graphs (containing different types of nodes and edges), have become a research hotspot. HGNNs can better learn the complex relationships and structural features in the graph by processing multiple types of node and edge information at the same time. However, HGNNs still face the threat of adversarial attacks in practical applications. Adversarial attacks can induce the model to make incorrect predictions by making small perturbations to the graph data, greatly affecting the security and stability of the system. Currently, many adversarial attack methods for graph neural networks (GNNs) cannot effectively deal with the complex node types and edge relationships in heterogeneous graphs, resulting in low attack success rates or untargeted attack models. Therefore, proposing an adversarial attack method for HGNNs has become an urgent problem to be solved.
[0003] Heterogeneous graph neural network adversarial attack methods have attracted widespread attention from researchers in recent years, but they still have significant limitations. On the one hand, although the attack strategies used in existing heterogeneous graph neural network adversarial attack methods (such as FGSM and PGD) have been widely studied in the image and text fields, these strategies cannot fully explore the complex structure and semantic information of heterogeneous graph data, thereby limiting the attack performance of heterogeneous graph neural network attack methods and having great limitations in the comprehensive evaluation of the robustness of HGNNs. In addition, although the attack strategies of existing attack methods can reduce the performance of heterogeneous graph neural network models to a certain extent, the implementation of these methods is relatively complex and requires multiple graph sampling and gradient calculations, which increases the computational cost and implementation difficulty of the attack, limiting its widespread use in practical applications. On the other hand, existing attack methods mainly use the significance of gradient information to select perturbation edges, which may cause overfitting of the model, resulting in poor performance in test data and limited generalization ability of the attack methods. Summary of the invention
[0004] To solve the problems existing in the above-mentioned prior art, the present invention introduces the concept of graph entropy, combines the two information concepts of node entropy and structural entropy, and makes full use of the rich structural and semantic information of heterogeneous graph data in heterogeneous graphs to improve attack performance, reduce computing costs and enhance generalization ability.
[0005] Specifically, the present invention first calculates the node entropy of each node in the heterogeneous graph. The node entropy reflects the complexity and uncertainty of the subgraph where a single node is located. The higher the node entropy, the more complex the subgraph structure is, and the node may introduce more noise or irrelevant information, increasing the uncertainty of model prediction; conversely, the lower the node entropy, the simpler the subgraph structure, and the more stable the node feature representation. At the same time, the structural entropy is used as a condition for defining a harmless graph in a heterogeneous graph. As a tool for measuring graph structural information, the structural entropy is associated with the rank of the adjacency matrix. By introducing the structural entropy, it can be combined with the rank condition to construct an objective function to find a harmless graph that meets the conditions. By comprehensively considering the node entropy and the structural entropy, the present invention proposes the concept of graph entropy. The graph entropy can accurately locate the key nodes and edges that have a greater impact on the model prediction, so that when conducting adversarial attacks, they can be perturbed slightly in a targeted manner to induce the model to produce erroneous outputs. In order to more efficiently screen out perturbations that have a significant impact on the target node, the present invention uses an adaptive candidate same-neighbor perturbation node selection strategy to reduce the perturbation search range and improve the attack efficiency. Finally, combining graph entropy with the adaptive candidate same-neighbor perturbation point strategy, an efficient perturbation generation method based on graph entropy is designed, which can effectively destroy the embedded information of the target node, affect the prediction of the heterogeneous graph neural network model on the target node, and produce erroneous output.
[0006] Beneficial effects of the present invention:
[0007] Compared with existing attack strategies, the present invention combines node entropy and structural entropy to propose the concept of graph entropy, making full use of the rich structural and semantic information in heterogeneous graphs. Graph entropy can accurately locate key nodes and edges that have a greater impact on model predictions, reduce dependence on model gradient information, improve attack performance and enhance generalization capabilities. The present invention uses an adaptive candidate same-neighbor perturbation point strategy, which does not require multiple graph sampling and complex gradient calculations, greatly reducing the computational cost and implementation difficulty of the attack, making it easier to be widely deployed in practical applications. In addition, the present invention avoids the overfitting phenomenon that may be caused by relying solely on gradient information through an attack method guided by graph entropy, improves the attack performance of the method, enhances its generalization ability, and can more comprehensively evaluate the robustness of heterogeneous graph neural networks. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Figure 1 It is a flow chart of the heterogeneous graph neural network anti-attack method based on graph entropy of the present invention;
[0009] Figure 2Schematic diagram of the adaptive candidate same-neighbor disturbance node selection strategy of the present invention;
[0010] Figure 3 It is a schematic diagram of the framework of the heterogeneous graph neural network anti-attack method based on graph entropy of the present invention; DETAILED DESCRIPTION
[0011] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0012] A method for countering an attack on a heterogeneous graph neural network based on graph entropy, the method comprising: obtaining a heterogeneous graph with relationship category label information and dividing it into a training set, a validation set, and a test set; using the training set to train the heterogeneous graph neural network to obtain a trained heterogeneous graph node classifier; for a target node to be attacked in the test set, for each relationship category, determining its isomorphic subgraphs respectively; for each relationship category isomorphic subgraph, calculating the node entropy; for each relationship category isomorphic subgraph, calculating the harmless graph entropy based on the structural entropy; determining a candidate perturbation set according to an adaptive candidate same-neighbor perturbation node selection strategy; using a loss function based on graph entropy to calculate the perturbation with the greatest impact on the graph entropy change in the candidate perturbation set, and selecting the perturbation as an attack on the target node; attacking each node in the test set to test the overall attack performance of the attack method;
[0013] A specific implementation method of a heterogeneous graph neural network counterattack method based on graph entropy, such as Figures 1-2 As shown, the method includes:
[0014] S1: Obtain a heterogeneous graph with relationship category label information and divide it into a training set, a validation set, and a test set. Use the training set to train the heterogeneous graph neural network to obtain a trained heterogeneous graph node classifier.
[0015] Data partitioning: Get a heterogeneous graph dataset containing relationship category label information. Divide the dataset into training set, validation set, and test set. Usually, the training set is used for model training, the validation set is used for hyperparameter tuning, and the test set is used to evaluate the final performance of the model.
[0016] Model training: Use the training set to train the heterogeneous graph neural network (HGNNs) to obtain a trained heterogeneous graph node classifier. The specific steps of model training are as follows:
[0017] Select a suitable heterogeneous graph neural network model, such as HAN, HGT, GATNE, etc.
[0018] Define a loss function, usually a cross entropy loss function, to optimize model parameters.
[0019] The model is trained using a gradient descent method (such as the Adam optimizer) until the performance of the model on the validation set stops improving.
[0020] Save the trained model parameters for subsequent attack tests.
[0021] S2: For the target node to be attacked in the test set, determine its isomorphic subgraph for each relationship category.
[0022] Target node selection:
[0023] Select the target node v to be attacked from the test set. The target node can be selected based on a specific attack goal, for example, selecting a node of a specific category or selecting a node that has a greater impact on model performance.
[0024] Isomorphic subgraph extraction:
[0025] For each relationship category, extract the isomorphic subgraph of the target node v. An isomorphic subgraph is a subgraph that contains only nodes and edges of a specific relationship category. The specific steps are as follows:
[0026] Traverse all neighbor nodes of the target node v, and divide the neighbor nodes into different same-neighbor nodes according to the relationship category. The subgraph formed by the nodes connected to the same-neighbor nodes under each relationship and the connection relationship category with the current relationship and the target relationship is defined as an isomorphic subgraph, which is expressed as follows:
[0027]
[0028] Where E is the edge set of the heterogeneous graph, e (u,s) Indicates that there is an edge between node u and node v, r indicates the relationship category, is the node set of the isomorphic subgraph, type(·) represents the type of edge, Represents the edge set of isomorphic subgraphs.
[0029] S3: For each relation category isomorphic subgraph, calculate the node entropy.
[0030] Node entropy is used to measure the complexity and uncertainty of a single node. The higher the node entropy, the more complex the isomorphic subgraph structure is, and the node may introduce more noise or irrelevant information, increasing the uncertainty of model prediction; conversely, the lower the node entropy, the simpler the isomorphic subgraph structure is, and the node feature representation is more stable. Node entropy is used to measure the uncertainty of a single node in a certain relationship isomorphic subgraph. For the case of relationship r, the isomorphic subgraph of node u For each edge (s, t), the cosine similarity sim(s, t) is calculated as follows:
[0031]
[0032] in, are the feature vectors of node s and node t respectively. The cosine similarity of all edges in the neutron graph is normalized so that the sum of all edge weights is 1. After normalization, the weight of the edge (s, t) is q (s,t) It can be expressed as:
[0033]
[0034] in, isomorphic subgraph Finally, it can be deduced that the node entropy h(G u ) is expressed as:
[0035]
[0036] S4: For each relation category isomorphic subgraph, calculate the harmless graph entropy.
[0037] Research and analysis have found that in order for the graph neural network to learn the same embedding as the intrinsic connection graph, it is necessary to find a harmless graph that meets certain conditions. One of the key conditions is that the rank of the adjacency matrix of the harmless graph is not less than the rank of the adjacency matrix of the intrinsic connection graph. Structural entropy, as a tool to measure the structural information of the graph, is associated with the rank of the adjacency matrix. By introducing structural entropy, it can be combined with the rank condition to construct an objective function to find a harmless graph that meets the conditions. The randomness of the input graph data will have an adverse effect on the performance of the graph neural network. The introduction of structural entropy in the objective function enables the model to pay more attention to the intrinsic structural information of the graph during the learning process, rather than being affected by random perturbations. By optimizing the loss function related to structural entropy, the model can learn more stable and robust node embeddings that better reflect the intrinsic connection characteristics of the graph rather than being disturbed by random noise in the input graph. Therefore, the present invention can reversely utilize the harmless graph entropy to make the model susceptible to random perturbations during the learning process and break the quality of node embedding.
[0038] Calculation of harmless graph entropy based on structural entropy:
[0039] 1. Define Network Partition Structural Information (NPSI)
[0040] The network partition structure information is a measure of structural entropy, which is used to measure the quality of graph partitioning. Given a graph G and a partition P(G) = {C 0 ,C 1 ,...,Cr-1}, NPSI is defined as:
[0041]
[0042] Among them, vol k Is divided C k The number of edges with at least one node in g k Is divided C k The number of edges with only one node in vol k It can be expressed in matrix form as:
[0043]
[0044] Where Y is the indicator matrix and trace(·) is the trace of the input matrix. We can use the above definition to incorporate NPSI(A,Y) into heterogeneous graph neural networks and understand the relationship between NPSI(A,Y) and the learning graph.
[0045] 2. Combined with Davis-Bourdin Index (DBI)
[0046] The Davis-Bourdin Index (DBI) is used to measure the similarity of node features within the same partition. DBI is defined as:
[0047]
[0048] The adjacency matrix A′ that satisfies Assumption 1 will make DBI(X,Y) smaller. Based on the necessary conditions for obtaining a harmless graph, a harmless graph entropy is constructed using network partition structure information (NPSI) and Davies-Bouldin index (DBI) to learn the adjacency matrix A that satisfies these conditions. Let β be a hyperparameter. The harmless graph entropy is:
[0049]
[0050] sA i ' j ≥0,A ′ =A ′T
[0051] S5: Determine a candidate disturbance set according to an adaptive candidate same-neighbor disturbance node selection strategy.
[0052] In the HGNNs information aggregation framework, the information of neighbor nodes has a significant impact on the representation of the central node and the final classification result. Therefore, for any given node, establishing new connections with other nodes or destroying existing connections may affect its final classification result. However, if we try to exhaust all possible connection relationships to determine the strategy of adding and deleting edges, we will face huge time complexity challenges. To solve this problem, this work introduces an adaptive candidate same-neighbor perturbation node selection strategy that can dynamically select the category of candidate neighbors according to the node category confidence.
[0053] Adaptive candidate neighbor disturbance node selection strategy:
[0054] According to the adaptive candidate same-neighbor node perturbation node selection strategy, determine the candidate perturbation set. The specific steps are as follows:
[0055] For each relation class isomorphic subgraph The candidate neighbor set S(v) of node v can be expressed as:
[0056]
[0057] About Threshold This work introduces the concept of skewness in statistics. Skewness is a measure of the degree of skewness in the distribution of statistical data. The prediction confidence vector P(v) of node v is removed by the maximum category confidence After that, the remaining confidence is taken as a data sequence D.
[0058] Where K is the number of labels. For the data sequence D, its skewness can be calculated by the following formula:
[0059]
[0060] Where n is the sample size, d i is the i-th sample point, is the sample mean, is the sample standard deviation. When Skew(D)<0, the mean is on the left side of most sample distributions, and the median is greater than the mean. In this case, the mean should be selected as the threshold to exclude most low-level samples; when Skew(D)>0, the mean is on the right side of most samples, and the median is less than the mean. In this case, the median should be selected as the threshold to include more high-level samples. Therefore, the threshold The choice can be expressed as:
[0061]
[0062] in, is the mean of the data sequence D, is the median of the data sequence D. Use As a threshold for screening candidate neighbor categories, it can adaptively select candidate neighbor categories and the number of categories, improving the efficiency of attack method perturbation selection. The candidate perturbation set of node v can be expressed as:
[0063]
[0064] This strategy uses an adaptive candidate same-neighbor disturbance point strategy to reduce the disturbance search range and improve attack efficiency. This strategy can efficiently screen out disturbance points that have a significant impact on the target node, avoid unnecessary calculations, and significantly reduce the computational cost.
[0065] S6: Generate Adversarial Perturbations
[0066] Loss function based on graph entropy:
[0067] Use the loss function based on graph entropy to calculate the perturbation that has the greatest impact on the change in graph entropy in the candidate perturbation set. The specific steps are as follows:
[0068] Define the loss function L, which aims to maximize the node entropy of the target node and the harmless graph entropy of the entire graph, while minimizing the prediction confidence of the target node:
[0069]
[0070] Among them, v is the target node, is the predicted label of the target node, α, β, and γ are hyperparameters used to balance the influence of different terms.
[0071] Gradient Ascent Optimization:
[0072] Optimize the loss function L through the gradient ascent method and generate adversarial perturbation ΔA=κ▽ A L, where κ is the step size, which controls the size of the perturbation. The step size κ can be adjusted experimentally to ensure that the generated adversarial graph A′ is still a valid graph.
[0073] Select the candidate perturbation set, and determine the candidate perturbation set according to the adaptive candidate neighbor node perturbation node selection strategy. These candidate perturbation nodes are neighbor nodes that are directly connected to the target node and have a greater impact on the target node. Calculate the impact of each candidate perturbation, and for each candidate perturbation, calculate its impact on the node entropy H(v) and structural entropy The change of , calculates the impact of each candidate perturbation on the confidence that the target node is predicted as a specific label. Combining these changes, calculate the impact of each candidate perturbation on the loss function L. Select the perturbation with the greatest impact on the loss function L from the candidate perturbation set.
[0074] S7: Attack each node in the test set to test the overall attack performance of the attack method.
[0075] For the overall assessment of the attack method, the following methods can be used:
[0076] Total attack performance score: The overall performance of the attack method is obtained by calculating the average change in the classification performance of all nodes before and after the attack. For example, "average accuracy drop" or "average F1 score drop" can be used as a performance evaluation indicator.
[0077]
[0078] Where N is the number of nodes in the test set.
[0079] Attack intensity analysis: By controlling the intensity of the attack (such as the amount of disturbance in the attack, the amplitude of the modified features, the proportion of deleted edges, etc.), observe the impact of the attack intensity on the model. Generally, as the attack intensity increases, the performance of the model will drop significantly, reflecting the sensitivity of the model to attacks. Model adversarial resistance: If the model can still maintain a high accuracy or other performance indicators under most attacks, it means that the model has strong adversarial resistance. Conversely, if the performance of the model drops sharply after most nodes are attacked, it means that the model is relatively fragile. Run the heterogeneous graph neural network model on the generated adversarial graph to evaluate the attack effect. Specific indicators include the decline in prediction accuracy:
[0080] This paper introduces the concept of graph entropy, combines the two information concepts of node entropy and structural entropy, and makes full use of the rich structural and semantic information in heterogeneous graphs to propose an efficient targeted attack method. By accurately locating key nodes and edges, reducing computing costs, and enhancing generalization capabilities, the method of the present invention provides an efficient and reliable solution for targeted attacks on heterogeneous graph neural networks.
[0081] The main innovations of the present invention include: by comprehensively considering node entropy and structural entropy, graph entropy can accurately identify key nodes and edges that affect model prediction results in complex heterogeneous graphs. This method can not only accurately locate the attack target, but also identify areas with greater influence in complex graph structures, thereby improving the attack effect. The present invention proposes an adaptive candidate same-neighbor perturbation point strategy, which avoids multiple graph sampling and complex gradient calculations. In this way, the attack method can still effectively destroy the model prediction without relying on complex gradient information, thereby improving the attack performance. This not only reduces the computational cost, but also simplifies the implementation difficulty, so that the method can be more conveniently deployed in practical applications. Traditional graph neural network attack methods usually rely on the gradient information of the model, which is prone to overfitting. Through the attack method guided by graph entropy, the present invention can avoid this problem and ensure the universality and robustness of the attack. This advantage makes the method have stronger generalization ability and can achieve stable attack effects on different types of heterogeneous graphs. Through the attack method guided by graph entropy, the robustness of heterogeneous graph neural networks can be evaluated more comprehensively and accurately. This method not only conducts targeted attacks on nodes and edges, but also reveals the weak links of the model when facing complex graph structures.
[0082] Finally, it should be noted that the above embodiments are only used to illustrate the technical solution of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solution of the present invention can be modified or replaced by equivalents without departing from the purpose and scope of the technical solution, which should be included in the scope of the claims of the present invention.
Claims
1. A method for countering attacks on heterogeneous graph neural networks based on graph entropy, characterized by: By comprehensively considering node entropy and structural entropy, graph entropy can accurately identify key nodes and edges that affect model prediction results in complex heterogeneous graphs. This method can not only accurately locate the attack target, but also identify areas with greater influence in complex graph structures, thereby improving the attack effect. The present invention proposes an adaptive candidate same-neighbor perturbation point strategy, which avoids multiple graph sampling and complex gradient calculations. In this way, the attack method can effectively destroy the prediction of heterogeneous graph neural network models without relying on complex gradient information, thereby improving the attack performance. This not only reduces the computational cost, but also simplifies the implementation difficulty, making the method more convenient to deploy in practical applications. Traditional graph neural network attack methods usually rely on the gradient information of the model, which is prone to overfitting. Through the attack method guided by graph entropy, the present invention can avoid this problem and ensure the universality and robustness of the attack. This advantage makes the method more generalizable and can achieve stable attack effects on different types of heterogeneous graphs. The attack method guided by graph entropy can more comprehensively and accurately evaluate the robustness of heterogeneous graph neural networks. This method not only conducts targeted attacks on nodes and edges, but also reveals the weak links of the model when facing complex graph structures.
2. According to claim 1, a heterogeneous graph neural network anti-attack method based on graph entropy is characterized in that: For the target node to be attacked in the test set and each relationship category, determine its isomorphic subgraph respectively. The steps include: a) Target node selection: Select the target node v to be attacked from the test set. The target node selection can be based on a specific attack goal, for example, selecting a node of a specific category or selecting a node that has a greater impact on model performance. b) Isomorphic subgraph extraction: For each relationship category, an isomorphic subgraph of the target node v is extracted. An isomorphic subgraph refers to a subgraph that contains only nodes and edges of a specific relationship category.
3. The isomorphic subgraph of the target node according to claim 2, wherein in step b), the feature is that: The isomorphic subgraph is defined as follows: Where E is the edge set of the heterogeneous graph, e (u,s) Indicates that there is an edge between node u and node v, r indicates the relationship category, is the node set of the isomorphic subgraph, type(·) represents the type of edge, Represents the edge set of isomorphic subgraphs.
4. According to the method for countering attacks on heterogeneous graph neural networks based on graph entropy as described in claim 1, it is characterized in that: The steps to define node entropy are as follows: a) Calculate cosine similarity; b) Normalized cosine similarity; c) Calculation definition of node entropy.
5. A method for defining node entropy according to claim 4, characterized in that: Node entropy is calculated as follows: a) For the case of relationship r, the isomorphic subgraph of node u For each edge (s, t), the cosine similarity sim(s, t) is calculated as follows: in, are the feature vectors of node s and node t respectively. b) For isomorphic subgraphs The cosine similarity of all edges in the neutron graph is normalized so that the sum of all edge weights is 1. After normalization, the weight of the edge (s, t) is q (s,t) It can be expressed as: in, isomorphic subgraph Edge set. c) Finally, it can be deduced that the node entropy h(G u ) is expressed as: The above steps can be used to obtain the calculation method of node entropy.
6. According to claim 1, a method for countering attacks on heterogeneous graph neural networks based on graph entropy, characterized in that: The calculation method of structural entropy is: a) Define Network Partition Structural Information (NPSI); b) Combined with the Davis-Bourdin Index (DBI), it is used to measure the similarity of node features within the same partition.
7. The method for calculating structural entropy according to claim 6, characterized in that: The definition of step a) NPSI is: Network partition structure information is a measure of structural entropy, which is used to measure the quality of graph partitioning. Given a graph G and partitions P(G) = {C0, C1, ..., C r-1 }, NPSI is defined as: Among them, vol k Is divided C k The number of edges with at least one node in g k Is divided C k The number of edges with only one node in vol k It can be expressed in matrix form as: Where Y is the indicator matrix and trace(·) is the trace of the input matrix. We can use the above definition to incorporate NPSI(A,Y) into heterogeneous graph neural networks and understand the relationship between NPSI(A,Y) and the learning graph.
8. The method for calculating structural entropy according to claim 6, characterized in that: The step b) is to calculate harmless graph entropy. Based on the necessary conditions for obtaining a harmless graph, a harmless graph entropy is constructed using network partition structure information (NPSI) and Davies-Bouldin index (DBI): Innocent graph entropy can be used to learn an adjacency matrix A that satisfies these conditions.
9. According to the method for countering attacks on heterogeneous graph neural networks based on graph entropy in claim 1, it is characterized in that: Adaptive candidate same-neighbor perturbation node selection strategy. The candidate same-neighbor perturbation node set S(v) of node v can be expressed as: About Threshold This work introduces the concept of skewness in statistics. For a data sequence D, its skewness can be calculated by the following formula: Threshold The choice can be expressed as: in, is the mean of the data sequence D, is the median of the data sequence D. Use As a threshold for screening candidate neighbor categories, it can adaptively select candidate neighbor categories and the number of categories, thereby improving the efficiency of perturbation selection by attack methods.
10. According to the method for countering attacks on heterogeneous graph neural networks based on graph entropy as described in claim 1, it is characterized in that: The loss function based on graph entropy aims to maximize the node entropy of the target node and the harmless graph entropy of the entire graph, while minimizing the prediction confidence of the target node: Among them, v is the target node, is the predicted label of the target node, α, β, and γ are hyperparameters used to balance the influence of different terms.
11. The method for countering attacks on heterogeneous graph neural networks based on graph entropy according to claim 1, characterized in that: The performance evaluation of the attack method is to calculate the average change in the classification performance of all nodes before and after the attack to obtain the overall performance of the attack method. "Average accuracy drop" or "average F1 score drop" is used as the performance evaluation indicator. "Average accuracy drop" can be expressed as: Where N is the number of nodes in the test set.