Graph neural network model inversion attack method of variational graph auto-encoder
By introducing a variational graph autoencoder module in the graph neural network model inversion attack, the adjacency matrix is optimized and reconstructed, the problem of insufficient graph structure modeling capabilities in the existing technology is solved, and the attack performance and model expression capabilities are improved.
Patent Information
- Application Number
- CN202510224697.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-13
AI Technical Summary
Existing model inversion attack methods for graph neural networks are difficult to effectively capture the uncertainty of embedded representations and the complex relationship between embedded vectors, resulting in insufficient graph structure modeling capabilities.
A graph neural network model inversion attack method for variational graph autoencoder is proposed. By constructing a target classification model, an initial objective function, a final objective function, a projection gradient descent module with graph structure loss, and a variational graph autoencoder module with personalized PageRank, we generate and optimize the reconstruction of the adjacency matrix to improve attack performance and model expression capabilities.
The initial reconstruction adjacency matrix is post-processed through the personalized PageRank's variational graph autoencoder module to generate adversarial samples closer to the original samples, improving the attack performance and graph structure modeling capabilities of the model.
Smart Images

Figure CN120145228A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of privacy attacks for graph neural networks, and particularly to a method for attacking a graph neural network model of a variational graph autoencoder by model inversion. Background Art
[0002] Existing model inversion attacks for GNNS can be classified into two types: white-box attacks and black-box attacks according to the degree of access of the attacker to the target model. Under the condition of a white-box attack, the attacker has full access to the target model, including the model architecture and all parameters. In addition, the attacker may also access additional auxiliary knowledge such as node labels and features. Under the condition of a black-box attack, the attacker can only use the input graph to query the target model and obtain the corresponding predicted labels.
[0003] Although the existing model inversion attacks for GNNS have achieved success to some extent, there are still the following two challenges: First, in order to further improve the attack performance, one of the challenges is how to make the generated adversarial samples (i.e., the reconstructed adjacency matrix) closer to the original samples (i.e., the original adjacency matrix). Second, whether the information such as the graph structure, node features, and parameters of the target classification model is fully utilized directly affects the model's ability to model the graph structure.
[0004] Existing methods are difficult to effectively capture the uncertainty of the embedded representation and the complex relationship between the embedded vectors, which leads to defects in the model's ability to model the graph structure.
[0005] Currently, the existing model inversion attacks mainly focus on grid domain data such as images, and there is less research on model inversion attacks for graph-structured data. Summary of the Invention
[0006] In view of the above problems, the present invention is proposed to provide a method for attacking a graph neural network model of a variational graph autoencoder that overcomes the above problems or at least partially solves the above problems.
[0007] According to one aspect of the present invention, there is provided a method for attacking a graph neural network model of a variational graph autoencoder, the model inversion attack method comprising:
[0008] Constructing a target classification model, an initial objective function, a final objective function, a projected gradient descent module with a graph structure loss, and a variational graph autoencoder module with personalized PageRank;
[0009] The target classification model defines the model to be attacked;
[0010] The initial objective function defines the attack objective of the attacker;
[0011] The final objective function enhances the similarity between the reconstructed adjacency matrix and the original adjacency matrix;
[0012] The projection gradient descent module with graph structure loss generates an initial reconstructed adjacency matrix;
[0013] The variational graph autoencoder module with personalized PageRank post - processes the initial reconstructed adjacency matrix to obtain the final reconstructed adjacency matrix.
[0014] Optionally, the target classification model includes a graph convolutional neural network and a graph attention network.
[0015] Optionally, the initial objective function defines the attack objectives of the attacker, specifically including:
[0016] The graph neural network model inversion attack method based on the variational graph autoencoder with personalized PageRank infers the connection relationships between nodes in the input graph data;
[0017] Under the setting of white - box attack, the attacker has access to and acquisition rights for the target model f θ , and with the help of a series of auxiliary knowledge and the pre - trained target classification model, reconstructs the adjacency matrix and makes the reconstructed adjacency matrix as similar as possible to the original adjacency matrix;
[0018] Uses minimizing the cross - entropy loss between the true label and the predicted label as the objective function;
[0019] If the node prediction labels in the reconstructed adjacency matrix are closer to the true label distribution, it is inferred that the similarity between the reconstructed adjacency matrix and the original adjacency matrix is higher.
[0020] Optionally, the definition of the initial objective function:
[0021]
[0022] where A' represents the reconstructed adjacency matrix, n represents the number of nodes, represents the attack loss at node i, x i represents the feature of node i, c i represents the true label of node i, and C represent the attacker and the node label matrix respectively, and θ are the parameters of the pre - trained target classification model f θ .
[0023] Optionally, the final objective function is defined as:
[0024]
[0025]
[0026] Among them, is the cross-entropy loss between the true label and the predicted label, is the feature smoothness loss, ||A'|| F is the adjacency matrix F-norm regularization term, is the graph structure loss, α, β, and γ are hyperparameters, n is the number of nodes, A' i,j and (x i - x j ) 2 respectively represent the connection between node i and node j and the feature difference between node i and node j.
[0027] Optionally, the projection gradient descent module with graph structure loss generates the initial reconstructed adjacency matrix, which specifically includes:
[0028] Set the target classification model f θ , the node feature matrix X, and the node label matrix C. First, initialize an adjacency matrix A with a value of 0. Secondly, use the trained target classification model f θ and auxiliary knowledge such as the node feature matrix X and the node label matrix C to infer the connection relationship between nodes in the training graph, and reconstruct the adjacency matrix A';
[0029] Calculate the attack loss of the nodes in A' The attack loss includes the graph structure loss
[0030] Finally, according to the definition of the final objective function, use the projection gradient descent PGD technique to optimize A' so that the node prediction labels in the reconstructed adjacency matrix A' are closer to the true label distribution.
[0031] Optionally, the calculation formula for generating the initial reconstructed adjacency matrix is:
[0032]
[0033] Among them, P [0,1] represents the projection operation, t and η t respectively represent the number of iterations and the learning rate, represents the attacker.
[0034] Optionally, the personalized PageRank variational graph autoencoder module performs post-processing operations on the initial reconstructed adjacency matrix to obtain the final reconstructed adjacency matrix, which specifically includes:
[0035] Pass some parameters of the target classification model f θ to the VGAE encoder, use the feature matrix X and the reconstructed initial adjacency matrix A' as inputs, and obtain the initial vector representation H of the graph structure through the GCN of the VGAE encoder(0) ;
[0036] The Personalized PageRank algorithm of APPNP is adopted to capture deeper and more complex node features and graph topologies to obtain the final graph structure vector representation H (K+1) ;
[0037] Use the decoder to obtain the final reconstructed adjacency matrix A'.
[0038] Optionally, the calculation formula for using the decoder to obtain the final reconstructed adjacency matrix A' is:
[0039] A' = σ(mm T )
[0040] s.t. m = ReLU(H (K+1) )
[0041]
[0042] H (0) = H = μ + ε × σ
[0043] μ = GCN μ (A′, X)
[0044] σ = GCN σ (A', X)
[0045] where σ(·) represents the activation function, K represents the number of iterations during the aggregation operation, represents the teleportation probability, ε is a randomly generated variable, and μ and σ are the mean and variance obtained by GCN using the VGAE encoder, respectively.
[0046] A method for inverting and attacking a graph neural network model of a variational graph autoencoder provided by the present invention, the inversion attack method includes: constructing a target classification model, an initial objective function, a final objective function, a projected gradient descent module with a graph structure loss, and a variational graph autoencoder module with personalized PageRank; the target classification model defines the model to be attacked; the initial objective function defines the attack target of the attacker; the final objective function enhances the similarity between the reconstructed adjacency matrix and the original adjacency matrix; the projected gradient descent module with a graph structure loss generates an initial reconstructed adjacency matrix; the variational graph autoencoder module with personalized PageRank performs post-processing operations on the initial reconstructed adjacency matrix to obtain the final reconstructed adjacency matrix. Improve the attack performance, enhance the expression ability of the model, and at the same time further alleviate the problem of insufficient graph structure modeling ability of the model.
[0047] The above description is only an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention, it can be implemented according to the content of the specification. And in order to make the above and other objects, features and advantages of the present invention more obvious and understandable, the following specific embodiments of the present invention are given. Brief Description of the Drawings
[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0049] Figure 1 It is a flowchart of a method for inverting and attacking a graph neural network model of a variational graph autoencoder provided by an embodiment of the present invention.
[0050] Figure 2 It is a schematic diagram of a neural network model of a method for inverting and attacking a graph neural network model of a variational graph autoencoder provided by an embodiment of the present invention.
[0051] Figure 3 It is an example diagram of a specific motivation scenario provided by an embodiment of the present invention. Detailed Description of the Embodiments
[0052] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.
[0053] The terms "including" and "having" and any variations thereof in the embodiments of the specification, claims and drawings of the present invention are intended to cover non-exclusive inclusion. For example, including a series of steps or units.
[0054] The technical solutions of the present invention will be further described in detail below with reference to the drawings and embodiments.
[0055] The present invention proposes a method for inverting and attacking a graph neural network model of a variational graph autoencoder based on personalized PageRank, namely VGMIA, to infer the connection relationship in the training data.
[0056] Use the projection gradient descent module with graph structure loss to effectively narrow the gap between the reconstructed adjacency matrix and the original adjacency matrix, further improving the attack performance; design a variational graph autoencoder module with personalized PageRank, and capture the uncertainty of the embedded representation, the complex relationships between the embedded vectors, and the feature information of deeper neighbor nodes by leveraging the VGAE encoder and the Personalized PageRank algorithm of APPNP to optimize the reconstructed adjacency matrix.
[0057] Example 1
[0058] The present invention proposes a graph neural network model inversion attack method for variational graph autoencoders, including: a target classification model, an initial objective function, a final objective function, a projection gradient descent module with graph structure loss, and a variational graph autoencoder module with personalized PageRank.
[0059] The target classification model is used to define the model to be attacked;
[0060] The initial objective function is used to define the attack strategy of the attacker;
[0061] The final objective function is used to enhance the similarity between the reconstructed adjacency matrix and the original adjacency matrix;
[0062] The projection gradient descent module with graph structure loss is used to generate an initial reconstructed adjacency matrix;
[0063] The variational graph autoencoder module with personalized PageRank is used to perform post-processing operations on the initial reconstructed adjacency matrix to obtain the final reconstructed adjacency matrix.
[0064] The target classification model includes a Graph Convolution Network (GCN) and a Graph Attention Network (GAT).
[0065] In most parts of the present invention, the node classification of a two-layer GCN is mainly taken as an example.
[0066] The initial objective function is used to define the attack target of the attacker, specifically as follows:
[0067] The graph neural network model inversion attack method based on variational graph autoencoder with personalized PageRank aims to infer the connection relationships between nodes in the input graph data. Under the setting of white-box attack, the attacker has access to the target model f θThe access and acquisition rights, which reconstruct the adjacency matrix by means of a series of auxiliary knowledge and a trained target classification model, and strive to make the reconstructed adjacency matrix as similar as possible to the original adjacency matrix. To more accurately measure the similarity between the reconstructed adjacency matrix and the original adjacency matrix, the present invention initially uses minimizing the cross-entropy loss between the true label and the predicted label as the objective function (the cross-entropy loss here is the attack loss). If the node prediction labels in the reconstructed adjacency matrix are closer to the true label distribution, it is inferred that the similarity between the reconstructed adjacency matrix and the original adjacency matrix is higher.
[0068] The definition of the initial objective function of the present invention is as follows:
[0069]
[0070] Where A' represents the reconstructed adjacency matrix, n represents the number of nodes, represents the attack loss at node i, x i represents the feature of node i, c i represents the true label of node i, and C respectively represent the attacker and the node label matrix, and θ is the parameter of the trained target classification model f θ of.
[0071] The final objective function is used to enhance the similarity between the reconstructed adjacency matrix and the original adjacency matrix. The definition of the final objective function is as follows:
[0072]
[0073] Where, is the cross-entropy loss between the true label and the predicted label, is the feature smoothness loss, ||A'|| F is the adjacency matrix F-norm regularization term, is the graph structure loss, α, β, and γ are hyperparameters, n is the number of nodes, A' i,j and (x i -x j ) 2 respectively represent the connection between nodes i and j and the feature difference between nodes i and j.
[0074] The process of generating the initial reconstructed adjacency matrix by the projection gradient descent module with graph structure loss includes:
[0075] Set the target classification model f θ , the node feature matrix X and the node label matrix C. First, initialize an adjacency matrix A with a value of 0. Secondly, use the trained target classification model f θInfer the connection relationship between nodes in the training graph with the help of auxiliary knowledge such as the node feature matrix X and the node label matrix C, that is, reconstruct the adjacency matrix A'.
[0076] Calculate the attack loss of the nodes in A'. The loss includes the graph structure loss
[0077] According to the definition of the final objective function, use the Projected Gradient Descent (PGD) technique to optimize A' so that the predicted labels of the nodes in the reconstructed adjacency matrix A' are closer to the true label distribution.
[0078] When performing the Projected Gradient Descent (PGD) technique in the present invention, first convert the reconstructed adjacency matrix A' into a vector a' to more effectively process the graph data and make the gradient calculation and update operations more convenient.
[0079] The specific calculation formula for generating the initial reconstructed adjacency matrix is:[[]]
[0080]
[0081] where P [0,1] represents the projection operation, t and η t represent the number of iterations and the learning rate respectively, represents the attacker.
[0082] The variational graph autoencoder module of personalized PageRank is used to perform post-processing operations on the initial reconstructed adjacency matrix to obtain the final reconstructed adjacency matrix. The process includes:
[0083] First, pass some parameters of the target classification model f θ to the VGAE encoder, and then use the feature matrix X and the reconstructed initial adjacency matrix A' as inputs. After passing through the GCN of the VGAE encoder, obtain the initial vector representation H (0) of the graph structure,
[0084] Then, adopt the PersonalizedPageRank algorithm of APPNP to capture deeper and more complex node features and graph topologies to obtain the final graph structure vector representation H (K+1) .
[0085] Finally, use the decoder to obtain the final reconstructed adjacency matrix A'. The specific calculation formula is:
[0086] A' = σ(mm T )
[0087] s.t. m = ReLU(H (K+1) )
[0088]
[0089] H (0) = H = μ + ε × σ
[0090] μ = GCN μ (A′,X)
[0091] σ = GCN σ (A',X)
[0092] where σ(·) represents the activation function, K represents the number of iterations during the aggregation operation, represents the transmission probability, ε is a randomly generated variable, and μ and σ are the mean and variance obtained by GCN using the VGAE encoder, respectively.
[0093] The specific method includes:
[0094] S1: Initialize an adjacency matrix A with a value of 0;
[0095] S2: Reconstruct the adjacency matrix with the help of the trained target classification model f θ and auxiliary knowledge such as the node feature matrix X and the node label C;
[0096] S3: Calculate the attack loss function after adding the graph structure loss ;
[0097] S4: According to the definition of the final objective function, use the projected gradient descent technique to optimize the reconstructed adjacency matrix to obtain the initial reconstructed adjacency matrix;
[0098] S5: Use the variational graph autoencoder module of personalized PageRank to obtain the final reconstructed adjacency matrix.
[0099] As Figure 2 shown, the present invention proposes a graph neural network model inversion attack method based on the variational graph autoencoder of personalized PageRank, which mainly includes two modules: the projected gradient descent module with graph structure loss and the variational graph autoencoder module of personalized PageRank. The present invention first trains a target classification model, then uses the projected gradient descent module with graph structure loss to generate the initial reconstructed adjacency matrix, and finally uses the variational graph autoencoder module of personalized PageRank to perform post-processing operations on the above-mentioned reconstructed adjacency matrix to obtain the final reconstructed adjacency matrix. Combining Figure 1 , it specifically includes the following steps:
[0100] Step 1) Initialize an adjacency matrix A with a value of 0; go to Step 2).
[0101] Step 2) With the help of the trained target classification model f θRebuild the adjacency matrix with auxiliary knowledge such as the node feature matrix X and the node label C;
[0102] The present invention selects GCN and GAT as the target classification models. To train GCN and GAT, the present invention uses an early stopping strategy to train them for 200 epochs on a training set containing 10% of the nodes and a validation set containing 20% of the nodes.
[0103] Proceed to step 3).
[0104] Step 3) Calculate the attack loss function after adding the graph structure loss ; Proceed to step 4).
[0105] Step 4) According to the definition of the final objective function, use the projected gradient descent technique to optimize the reconstructed adjacency matrix to obtain the initial reconstructed adjacency matrix; Proceed to step 5).
[0106] Step 5) Use the variational graph autoencoder module of personalized PageRank to obtain the final reconstructed adjacency matrix.
[0107] Figure 3 It is an example diagram of the specific motivation scenario of the present invention. In a social network, users do not want their private friendships and sensitive privacy data to be leaked. Since usually, this network uses a trained graph neural network model to generate friend recommendations and other content, if an illegal attacker obtains this graph neural network model by some means and then combines the user's public information, they may perform a model inversion attack to infer some users' social circle information, including sensitive information such as private friendship relationships.
[0108] Embodiment 2
[0109] As Figure 2 shown, the present invention proposes a graph neural network model inversion attack method based on the variational graph autoencoder of personalized PageRank, which mainly includes two modules: the projected gradient descent module with graph structure loss and the variational graph autoencoder module of personalized PageRank. The present invention first trains a target classification model, then uses the projected gradient descent module with graph structure loss to generate the initial reconstructed adjacency matrix, and finally uses the variational graph autoencoder module of personalized PageRank to perform post-processing operations on the above reconstructed adjacency matrix to obtain the final reconstructed adjacency matrix. Combining Figure 1 , it specifically includes the following steps:
[0110] Step 1) Initialize an adjacency matrix A with a value of 0; Proceed to step 2).
[0111] Step 2) With the help of the trained target classification model f θReconstruct the adjacency matrix with auxiliary knowledge such as node feature matrix X and node label C;
[0112] The present invention selects GCN and GAT as target classification models. In order to train GCN and GAT, the present invention uses an early termination strategy on a training set containing 10% of nodes and a validation set containing 20% of nodes to train them for 200 epochs.
[0113] Go to step 3).
[0114] Step 3) Calculate the added graph structure loss The attack loss function after that; go to step 4).
[0115] Step 4) According to the definition of the final objective function, the projected gradient descent technique is used to optimize the reconstructed adjacency matrix to obtain the initial reconstructed adjacency matrix; proceed to step 5).
[0116] Step 5) Use the variational graph autoencoder module of personalized PageRank to obtain the final reconstructed adjacency matrix.
[0117] The data set of this embodiment is described in detail below:
[0118] In this embodiment, three public network datasets are used for experiments, including Cora (Citation Network), Citeseer (Citation Network), and USA (Air-Traffic Network). The Cora dataset consists of academic papers covering the field of machine learning. The nodes in the graph represent individual academic papers, and the edges represent the citation and citation relationship between papers; the Citeseer dataset brings together academic papers in the fields of information science and computer science, which are divided into six different categories; the USA dataset is a dataset built on the basis of flight records between airports. In this dataset, nodes represent airports and edges represent routes between airports. The description information of the three datasets is shown in Table 1:
[0119] Table 1 Dataset description information
[0120]
[0121] The present invention has two main objectives for the variational graph autoencoder with personalized PageRank. First, it captures the uncertainty of the embedded representation and the complex relationships between the embedded vectors, enhances the model's expressive ability, and improves the model's performance. Different from the deterministic embedding of GAE, VGAE uses the probability distribution of latent variables to represent graph data. It models the implicit embeddings of nodes and edges as probability distributions, which can effectively capture the complex dependencies and uncertainties between nodes in the graph, thus helping attackers to reconstruct the adjacency matrix more accurately. Second, it aggregates the feature information of deeper neighbor nodes to improve the model's performance. By combining the VGAE encoder with the Personalized PageRank algorithm of APPNP, the information propagation ability between neighbor nodes is enhanced, enabling the feature information of nodes to spread to more distant positions, thereby prompting attackers to obtain a better embedded representation of the graph structure.
[0122] Figure 3 It is an example diagram of the specific motivation scenario of the present invention. In a social network, users do not want their private friendships and sensitive privacy data to be leaked. Since usually, this network uses a trained graph neural network model to generate content such as friend recommendations, if an illegal attacker obtains this graph neural network model by some means and then combines the public information of users, they may carry out a model inversion attack to infer the social circle information of some users, including sensitive information such as private friendship relationships.
[0123] In summary, starting from the white-box attack scenario, the present invention studies the graph neural network model inversion attack VGMIA based on the variational graph autoencoder with personalized PageRank to infer the connection relationships between nodes in the training data. Specifically, VGMIA first makes the generated adversarial samples (the reconstructed initial adjacency matrix) closer to the original samples through a projection gradient descent module with a graph structure loss. Then, it uses the VGAE encoder and the Personalized PageRank algorithm of APPNP to capture the uncertainty of the embedded representation, the complex relationships between the embedded vectors, and the feature information of deeper neighbor nodes, so as to achieve better performance in the post-processing operation of graph optimization.
[0124] 1) In the white-box attack scenario, the present invention proposes a new model inversion attack method VGMIA for graph neural networks to better infer the sensitive information of the input data (i.e., the connection relationships between nodes).
[0125] 2) The variational graph autoencoder module with personalized PageRank designed by the present invention captures more complex node features and graph topologies by using the VGAE encoder and the Personalized PageRank algorithm of APPNP, and generates adversarial samples closer to the original samples.
[0126] Advantageous effects: 1) In the white-box attack scenario, the present invention proposes a new model inversion attack method VGMIA for graph neural networks to better infer sensitive information of input data (i.e., the connection relationship between nodes).
[0127] 2) The personalized PageRank variational graph autoencoder module designed in the present invention captures more complex node features and graph topologies by using the VGAE encoder and the Personalized PageRank algorithm of APPNP to generate adversarial samples closer to the original samples. Specifically, first, it captures the uncertainty of the embedded representation and the complex relationship between the embedding vectors, enhances the model's expressive ability, and improves the model's performance. Different from the deterministic embedding of GAE, VGAE uses the probability distribution of latent variables to represent graph data. Modeling the implicit embeddings of nodes and edges as probability distributions can effectively capture the complex dependencies and uncertainties between nodes in the graph, thereby helping the attacker to more accurately reconstruct the adjacency matrix. Second, it aggregates the feature information of deeper neighbor nodes to improve the model's performance. Combining the VGAE encoder with the PersonalizedPageRank algorithm of APPNP enhances the information propagation ability between neighbor nodes, enables the feature information of nodes to spread to farther positions, and prompts the attacker to obtain a better graph structure embedding representation.
[0128] The above specific implementation manners further elaborate on the purpose, technical solution, and advantageous effects of the present invention. It should be understood that the above are only the specific implementation manners of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A graph neural network model inversion attack method for a variational graph autoencoder, characterized in that: The reverse attack method comprises: Construct the target classification model, initial objective function, final objective function, projected gradient descent module with graph structure loss, and variational graph autoencoder module for personalized PageRank; The target classification model defines the model under attack; The initial objective function defines the attacker's attack target; The final objective function enhances the similarity between the reconstructed adjacency matrix and the original adjacency matrix; The projected gradient descent module with graph structure loss generates an initial reconstructed adjacency matrix; The variational graph autoencoder module of the personalized PageRank performs a post-processing operation on the initial reconstructed adjacency matrix to obtain a final reconstructed adjacency matrix.
2. According to claim 1, the graph neural network model inversion attack method of a variational graph autoencoder is characterized in that: The target classification model includes a graph convolutional neural network and a graph attention network.
3. According to claim 1, the graph neural network model reversal attack method of a variational graph autoencoder is characterized in that: The initial objective function defines the attacker's attack target, which specifically includes: The graph neural network model reversal attack method based on personalized PageRank variational graph autoencoder infers the connection relationship between nodes in the input graph data; In the white-box attack setting, the attacker has the target model f θ With the help of a series of auxiliary knowledge and the trained target classification model, the adjacency matrix is reconstructed and the reconstructed adjacency matrix is made as similar as possible to the original adjacency matrix. Use minimizing the cross entropy loss between the true label and the predicted label as the objective function; If the predicted labels of nodes in the reconstructed adjacency matrix are closer to the true label distribution, it is inferred that the similarity between the reconstructed adjacency matrix and the original adjacency matrix is higher.
4. According to claim 1, the graph neural network model inversion attack method of a variational graph autoencoder is characterized in that: The definition of the initial objective function is: Among them, A' represents the reconstructed adjacency matrix, n represents the number of nodes, represents the attack loss at node i, x i represents the characteristics of node i, c i represents the true label of node i, and C represent the attacker and node label matrices respectively, and θ is the trained target classification model f θ Parameters.
5. According to claim 1, the graph neural network model inversion attack method of a variational graph autoencoder is characterized in that: The final objective function is defined as: in, is the cross entropy loss between the true label and the predicted label, is the feature smoothness loss, ||A'|| F is the adjacency matrix F norm regularization term, is the graph structure loss, α, β and γ are hyperparameters, n is the number of nodes, A' i,j and (x i -x j ) 2 They represent the connection between node i and node j and the feature difference between node i and node j respectively.
6. According to claim 1, the graph neural network model inversion attack method of a variational graph autoencoder is characterized in that: The projected gradient descent module with graph structure loss generates the initial reconstructed adjacency matrix specifically including: Set the target classification model f θ , node feature matrix X and node label matrix C, first initialize an adjacency matrix A with a value of 0, and then use the trained target classification model f θ The node feature matrix X, node label matrix C and other auxiliary knowledge are used to infer the connection relationship between nodes in the training graph, and the adjacency matrix A' is reconstructed; Calculate the attack loss of nodes in A' The attack loss includes graph structure loss Finally, according to the definition of the final objective function, the projected gradient descent PGD technique is used to optimize A' so that the node prediction labels in the reconstructed adjacency matrix A' are closer to the actual label distribution.
7. The graph neural network model reversal attack method of a variational graph autoencoder according to claim 1 is characterized in that: The calculation formula for generating the initial reconstruction adjacency matrix is: Among them, P [0,1] represents the projection operation, t and η t denote the number of iterations and the learning rate respectively, Indicates attacker.
8. According to claim 1, the graph neural network model inversion attack method of a variational graph autoencoder is characterized in that: The variational graph autoencoder module of the personalized PageRank performs a post-processing operation on the initial reconstructed adjacency matrix to obtain the final reconstructed adjacency matrix, specifically comprising: The target classification model f θ The parameters of the VGAE encoder are passed to the VGAE encoder, and the feature matrix X and the reconstructed initial adjacency matrix A' are taken as input. The GCN of the VGAE encoder obtains the initial vector representation H of the graph structure. (0) ; The Personalized PageRank algorithm of APPNP is used to capture deeper and more complex node features and graph topology to obtain the final graph structure vector representation H (K+1) ; Use the decoder to get the final reconstructed adjacency matrix A'.
9. The graph neural network model reversal attack method of a variational graph autoencoder according to claim 8, characterized in that: The calculation formula for obtaining the final reconstructed adjacency matrix A' using the decoder is: A'=σ(mm T ) stm=ReLU(H (K+1) ) H (0) =H=μ+ε×σ μ=GCN μ (A′,X) σ=GCN σ (A',X) Among them, σ(·) represents the activation function, K represents the number of iterations during the aggregation operation, represents the transmission probability, ε is a randomly generated variable, μ and σ are the mean and variance obtained by GCN using the VGAE encoder, respectively.