Dynamic multi-step adversarial attack method based on minimum disturbance budget of graph neural network
By constructing a multi-step attack loss function in a graph neural network, using a binary search algorithm and a dynamic perturbation propagation mechanism of a graph convolutional network, and combining the optimal attack path search strategy, the existing multi-step adversarial attack method is solved, and efficient damage to the target system is achieved at the minimum perturbation cost.
Patent Information
- Application Number
- CN202510276520.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-27
AI Technical Summary
The existing multi-step adversarial attack methods are difficult to take into account both efficiency, concealment and cost control in complex network environments. Especially in graph neural networks, due to the high dependence on graph structure and node characteristics, the control of the disturbance budget becomes uncontrollable.
A dynamic multi-step adversarial attack algorithm based on the minimum perturbation budget of graph neural network is proposed. By constructing a multi-step attack loss function, introducing a binary search algorithm, and utilizing the dynamic perturbation propagation mechanism of graph convolutional networks and the optimal attack path search strategy, the perturbation path and dynamically allocate the perturbation budget are precisely controlled to achieve efficient and hidden damage to the target system.
By accurately controlling the disturbance path and dynamically allocating the disturbance budget, efficient damage to the target system is achieved at the minimum disturbance cost, significantly improving the success rate and efficiency of the attack and reducing the disturbance cost.
Smart Images

Figure CN120218119A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical fields of multi-step attacks and information security, and particularly relates to a dynamic multi-step adversarial attack algorithm based on the minimum perturbation budget of graph neural networks. Background Art
[0002] In the fields of graph data analysis and information security, adversarial attacks have always been a research direction that has received much attention. Single-step attacks usually impose a large perturbation on the target system in a single centralized operation. Although it may bring obvious effects, there are also several significant defects: First, in the case of a single large-scale modification, the attack behavior is often obvious and is more likely to be captured and traced by existing detection mechanisms; Second, the high perturbation cost is not conducive to implementing efficient attacks in resource-constrained situations. Therefore, in view of the limitations of traditional single-step attacks in terms of concealment and cost, researchers have begun to explore more flexible and cumulative multi-step adversarial attacks.
[0003] Different from single-step attacks, multi-step adversarial attacks disperse the total perturbation budget into multiple steps, so that only minor modifications need to be applied in each step, thus effectively avoiding the high-risk exposure caused by large-scale modifications. During this process, the attacker can dynamically evaluate the optimal operation for the next step according to the real-time network state, and make full use of the cumulative perturbation effect to gradually undermine the stability of the target system. Compared with the "one-time" strong intervention, this small-step and fast-run strategy can not only flexibly bypass security detection and defense mechanisms, but also maintain a high attack success rate under the condition of limited budget. Thus, multi-step adversarial attacks are more feasible and threatening in complex scenarios such as social networks, the Internet of Things, and online recommendation systems.
[0004] In recent years, graph neural networks (GNNs) have shown excellent performance in processing complex network data (such as node classification, link prediction, graph embedding, etc.). However, due to the high dependence of GNNs on network structures and node features, once the attacker gradually manipulates this information in a multi-step attack scenario, the interference range can be continuously expanded, causing the model prediction to deviate. In fact, the deeper the information aggregation process of GNNs, the more easily the influence of the perturbation of a small number of nodes or edges cascades and spreads, resulting in multi-step adversarial attacks that are more difficult to detect and defend. Therefore, how to face complex networks, use the least budget, and flexibly adjust the attack decision in step-by-step perturbations has become a key issue in current multi-step attack research.
[0005] Early research mainly focused on single-step adversarial attacks and gradient-based methods. Wu et al. were the first to propose using the gradient information of the model to attack the adjacency matrix in the article "Adversarial Examples on Graph Data: Deep Insights into Attack and Defense". They selected the edges that were most sensitive to the model for addition or deletion, inducing misclassification of target nodes. This work laid the foundation for graph adversarial attacks, but did not consider the cumulative effect of multi-step perturbations, so its efficiency was limited in the context of dynamic defense. Subsequently, Zügner et al. extended this idea to the optimal perturbation scenario in the article "Adversarial Attacks on Neural Networks for Graph Data". By analyzing the gradient direction of target nodes, they modified node features or edge connections specifically, thus achieving a more targeted attack in a single modification. However, in large or complex networks, it is difficult for a single perturbation to completely mislead the classification of target nodes, and the attack behavior is relatively easy to detect. Multi-step adversarial attacks use small perturbations at each step to attack the model in a concealed and continuous manner, achieving more efficient target interference. Wang et al. proposed a method of gradually modifying the graph structure and node features, gradually guiding the model prediction to deviate in the wrong direction, achieving preliminary results in improving concealment, but lacking optimization in the global planning of the perturbation path, resulting in a still relatively high actual attack cost. Xu et al. based on the gradient search framework, gradually perturbed the target nodes and their neighborhoods, and adjusted the attack path according to the gradient information in each round to achieve more accurate multi-step attacks. However, due to the complex graph structure and high node dependence, the practical application on large graphs still faces the balance challenge between budget allocation and concealment. To improve the flexibility and adaptability of multi-step attacks, subsequent work began to explore dynamic multi-step strategies. For example, Wang et al. dynamically adjusted the attack path to cover key nodes by analyzing the influence of second-order neighborhoods. However, this method lacks systematic control over the cumulative perturbation effect and cannot maintain a stable attack success rate in high-concealment scenarios.
[0006] Meanwhile, GNN defense strategies are also evolving continuously. Alzaidy et al. introduced the concept of adversarial training into graph models, enhancing the robustness of the model by adding adversarial perturbations during the training phase. However, the effect of such methods is not ideal in multi-step attack scenarios and requires high computational resources. Zhang et al. proposed a strategy based on graph structure repair. First, they detected suspicious perturbations and repaired them in subsequent steps, but it relies heavily on the accuracy of the detection module and is difficult to achieve effective defense against more concealed multi-step attacks.
[0007] In the field of graph data analysis and information security, existing adversarial attack techniques are mainly divided into two categories: single-step attacks and multi-step attacks. Single-step attacks usually perturb the target system on a large scale at one time. Although they can quickly produce significant effects, they have the following significant defects: First, the large-scale modification makes the attack behavior easy to be discovered and tracked by the existing security detection mechanism, thereby reducing the concealment of the attack; second, the high perturbation cost limits the efficiency and feasibility of the attack under resource-constrained conditions. In addition, although the existing multi-step attack method reduces the visibility of each step by dispersing the perturbation budget into multiple steps, in graph neural networks (GNNs), the control of the perturbation budget becomes uncontrollable due to the high dependence on graph structure and node features. This budget uncertainty may lead to unstable attack effects, or require higher perturbation costs to achieve the expected attack effects, further weakening the practicality and concealment of multi-step attacks. Therefore, the current multi-step adversarial attack method is difficult to simultaneously take into account efficiency, concealment and cost control in complex network environments, and new technical means are urgently needed to improve it. Summary of the invention
[0008] In view of the shortcomings of existing technologies in terms of concealment, cost control and disturbance budget management, this paper proposes a dynamic multi-step adversarial attack algorithm based on graph neural network minimum disturbance budget. The algorithm aims to achieve efficient and covert destruction of the target system with minimal disturbance cost by accurately controlling the disturbance path and dynamically allocating the disturbance budget.
[0009] Specifically, the present invention includes three main parts: Multi-step perturbation budget determination: By constructing a multi-step attack loss function based on maximizing the classification error of the target node, accurate control of the perturbation path is achieved. A binary search algorithm is introduced to quickly locate the perturbation scheme that has the greatest impact on the target classification result, thereby achieving effective misleading of the target node with minimal intervention. Dynamic perturbation propagation of graph convolutional networks: Using a dynamic search strategy, the most vulnerable nodes are preferentially selected in each step and the perturbation budget is reasonably allocated, and the persistence and concealment of the attack are improved by gradually diffusing the perturbation. Combined with multiple perturbation constraints of the adjacency matrix and node characteristics, the attack process is optimized from the two dimensions of perturbation intensity and balance to ensure that the perturbation of each step is both effective and hidden. Optimal attack path search strategy: By adaptively evaluating the global influence of nodes and edges, key nodes (i.e., nodes that are in important topological positions or easily misclassified in the network) and key edges are preferentially selected to carry out attacks, amplifying the cascading effect of multi-step perturbations and improving overall efficiency.
[0010] To achieve the above purpose, the technical solution adopted by the present invention is:
[0011] A dynamic multi-step adversarial attack method based on minimum perturbation budget of graph neural network includes the following steps:
[0012] Step S1: First, during the training process of the graph neural network, minimize the classification loss on the training nodes, and by defining a new multi-step adversarial attack loss function, clarify the optimal target for each step of perturbation. On this basis, adopt a binary search-based strategy to dynamically allocate the minimum perturbation budget for each round of attack, and use the minimum perturbation budget to mislead the classification of the target node;
[0013] Step S2: After determining the available perturbation budget for each step, utilize the hierarchical propagation mechanism of the graph convolutional network to gradually spread the perturbation to more nodes, forming an accumulated attack effect. Specifically, by modifying the adjacency matrix and node features, and cooperating with the regularization or random noise terms in each layer of graph convolution, amplify the influence on the target node layer by layer, so as to achieve a highly concealed multi-step attack;
[0014] Step S3: After each round of perturbation is completed and the attack effect is observed, dynamically evaluate the nodes in the current network that have not been misled, select the next priority attack node and perturbation path; and combine the aforementioned perturbation budget allocation and dynamic propagation strategy to continuously expand the influence scope of the entire network. This step can pursue the maximum attack effect with the minimum budget, and improve the efficiency and concealment of the attack by flexibly selecting paths.
[0015] A further improvement of the technical solution of the present invention lies in: minimizing the classification loss on the training nodes in Step S1, as shown in formula (2), which is used to guide the attack path and optimize the perturbation operation for each step. The GNN parameter W is learned by minimizing the classification loss on the training nodes
[0016]
[0017] where σ is the softmax activation function, which is used to calculate the classification probability of the target node; represents the set of training nodes, represents the sum of the absolute values of the perturbed edges that have been executed in the adjacency matrix, where P A is the actual perturbation set; represents the sum of the absolute values of the perturbed features that have been executed in the node feature matrix X, where P X is the actual feature perturbation set;
[0018] The two regularization constraints in the formula respectively control the perturbation degree of the graph structure and node features, ensuring that the perturbation for each step minimizes the cost while maintaining the attack effectiveness. By restricting the number and amplitude of the perturbed edges, this regularization term optimizes the attack path while controlling the modification range of the graph structure, making the perturbation enhance the influence on the target node while maintaining concealment.
[0019] A further improvement of the technical solution of the present invention lies in that the adversarial attack loss is as shown in formula (3).
[0020]
[0021] Wherein, is the predicted score of node v for the true class y v from the output of the GNN, represents the predicted score of node v for another class, aiming to maximize the loss function of the adversarial attack so as to make the prediction of the model incorrect, partially measures the effect of the attack by comparing the difference between the true class score and the non-true class score; κ is a constant and is a parameter for controlling the boundary.
[0022] A further improvement of the technical solution of the present invention lies in that in step S1, the minimum effective perturbation budget B(v) is determined by a perturbation budget allocation algorithm based on binary search. This algorithm dynamically sets the upper and lower limits of the perturbation budget at each step, calculates the sorted gradient once and performs an equal division search on these gradients to find the minimum perturbation set required to transform v, thereby quickly determining the minimum effective perturbation budget. The specific steps are as follows:
[0023] S1.1. Initialize the boundary: The algorithm first sets the initial boundary for the budget. The initial lower limit L of the perturbation budget is zero, and the upper limit U = deg(v) (deg(v) is the degree of v) is determined by doubling step by step until a budget value U that can successfully perturb the target node v is reached, so as to determine the upper bound U (i.e., v is correctly classified by the top-U perturbations in );
[0024] S1.2. Perform binary search in a loop: In each loop, the budget is bisected, the intermediate value C is calculated, and then it is checked whether v can be correctly classified by the top-C perturbations in ;
[0025] S1.3. Determine node classification: Use the current budget C to check whether the target node v is correctly classified. If v is correctly classified, the algorithm adjusts the lower bound L, that is, updates it to C. If the classification is incorrect, the upper bound U is updated to C;
[0026] S1.4. End condition: The algorithm stops until the difference U - L between the upper and lower bounds of the budget is less than or equal to 1;
[0027] S1.5. Return the result: The finally returned U is the minimum budget required to misclassify the target node v.
[0028] It represents the ordered set of perturbations obtained after gradient aggregation and sorting for all candidate perturbations (including modifications to edge and node features). The top-U perturbations in represent the top U perturbations with the highest scores taken from the sorted set of perturbations. These perturbations are the modification operations that are most likely to cause a classification change in the target node v under the current budget U. The top-C perturbations of : When testing at the intermediate budget C of the binary search, these C optimal perturbations (according to the gradient sorting priority) are used to check whether the target node v has been successfully attacked (i.e., whether a classification change has occurred).
[0029] Finally, a minimum perturbation budget that can achieve the attack is determined, and this budget is used to modify the nodes and edges.
[0030] A further improvement of the technical solution of the present invention lies in: the hierarchical propagation method of the graph convolutional network in step S2, which gradually spreads the perturbation to more nodes to form an accumulative attack effect. The graph convolution formula is shown in formula (4):
[0031]
[0032] where is the normalized adjacency matrix, and H (l) represents the hidden representation of the l-th layer, and W (l) is the weight of the l-th layer, αR (l) is the attack perturbation regularization term, and R (l) represents the random perturbation noise based on the feature or adjacency matrix. In the scenario of multi-step attacks, the design of αR (l) is used to simulate and enhance the propagation effect of the perturbation. By gradually transmitting the cumulative influence layer by layer, the stealth and effectiveness of the attack are further improved.
[0033] A further improvement of the technical solution of the present invention lies in: the specific process of dynamic multi-step perturbation propagation:
[0034] A Application of the initial perturbation: According to the set perturbation budget, the adjacency relationship and feature matrix of the target node and its neighborhood are initially modified, and the perturbed graph is input into the GCN to extract the new node embedding representation;
[0035] B Multi-step propagation accumulation: In each step, the new node embedding is calculated through the GCN to capture the propagation effect of the perturbation in the network. As the perturbation gradually expands, its influence range gradually spreads from the target node to more key nodes, achieving an accumulative attack effect;
[0036] The introduction of the C perturbation regularization term ensures that each step of the perturbation is both effective and concealed. An adversarial regularization term is added during each layer's propagation, and diverse perturbation paths are simulated through random noise, maximizing the amplification of the perturbation effect during the propagation process.
[0037] A further improvement of the technical solution of the present invention lies in: the dynamic multi-step adversarial search strategy in step S3 is as follows:
[0038] Step S3.1, Initialize the attack parameters and set the budget:
[0039] Input parameters: The inputs of this algorithm include the graph structure G = (A, X), the attacker set S, the target node set T, the target node set C to be transformed, the initial value of the perturbation budget, the threshold α, etc.
[0040] Initialize the budget: Initially, the attack budget is set to zero. The goal of the attack is to gradually transform the nodes in the target node set T from the normal state to the misclassified state and complete the transformation with the minimum budget.
[0041] Step S3.2, Calculate the perturbation budget for each target node:
[0042] Multi-step perturbation calculation: For each target node v ∈ T, calculate the ordered perturbation set used to transform v, and call the binary search algorithm mentioned above to calculate the minimum perturbation budget B(v) for this node. This process is carried out independently for each node to evaluate the impact of the perturbation on this node and lay the foundation for subsequent selection of the perturbation path.
[0043] Step S3.3, Dynamically adjust the attack path and the perturbation budget:
[0044] Select the nodes with the minimum budget: By calculating the perturbation budget of each node, select the node set M that requires the least budget. These nodes are the most likely targets to be successfully transformed in the current attack path. For each node v ∈ M, calculate its forward-looking influence I(v, k), that is, evaluate the potential impact of future perturbations on the entire network. This influence value is used to determine which nodes to attack first.
[0045] Step S3.4, Selection of the attack path and node perturbation:
[0046] Select the node with the greatest influence: According to the forward-looking influence, select the node t ∈ M with the greatest influence (the most likely to bring subsequent impacts) for perturbation. Apply the perturbation to the network, update the state of the target node to develop it towards the misclassified direction, and at the same time increase the consumed attack budget.
[0047] Budget update: When the perturbation of node t meets the condition (for example, I(t) > α, indicating that the impact of this node on the network has increased significantly), a large perturbation is performed and the corresponding budget is updated.
[0048] Step S3.5, Adjust the attack target and update the test set:
[0049] During the attack process, as the target nodes are transformed, the test set is recalculated and updated. So as to further evaluate and expand the attack effect.
[0050] Step S3.6, Loop until all target nodes are transformed:
[0051] The above steps will be dynamically executed in each attack round until all target nodes C are successfully transformed into misclassified nodes. Each time it is executed, the current most effective attack path and nodes are continuously evaluated to ensure the concealment, persistence, and maximum effect of the attack.
[0052] Step S3.7, End condition and output:
[0053] When all the predetermined target nodes C are transformed, the algorithm ends and returns the required total attack budget, indicating the minimum budget required to complete the multi-step adversarial attack.
[0054] A further improvement of the technical solution of the present invention is: From the set of target nodes, select those nodes that are most sensitive to the model prediction as the priority targets for the current attack. By calculating the classification margin value of the nodes, select the nodes with the smallest margin value for attack to ensure the success rate of the attack. In each step, evaluate the potential impact of the perturbation on the entire network, select the attack path that can maximize the influence, and determine the nodes and edges with the greatest influence within the budget range as the attack objects through the global analysis of the graph structure. After each step of the attack, the algorithm dynamically adjusts the path according to the actual effect of the attack, selects new target nodes and edges to ensure that the attack can achieve the optimal effect at the minimum cost.
[0055] Due to the adoption of the above technical solution, the technical progress achieved by the present invention is:
[0056] The present invention is a dynamic multi-step adversarial attack algorithm based on the minimum perturbation budget. This algorithm combines the methods of binary search and first-order gradient sorting, solves the problem of uncontrollable perturbation budget in existing multi-step attacks, and makes the allocation of the attack budget more accurate and efficient.
[0057] The present invention combines the multi-step perturbation budget determination mechanism with the dynamic perturbation propagation strategy. By gradually selecting the most vulnerable nodes and reasonably allocating the perturbation budget, it significantly improves the persistence and concealment of the attack.
[0058] The present invention is based on the dynamic perturbation propagation of graph convolutional networks. This method first constructs a multi-step attack loss function based on the classification error of target nodes, and then selects key nodes through a dynamic search strategy. The method of the present invention considers the global influence of nodes and edges, so as to efficiently attack key nodes and edges, and amplify the cascading effect of perturbations.
[0059] The present invention is based on an optimization strategy with multiple perturbation constraints. First, the perturbation intensity of the adjacency matrix is controlled, and at the same time, the perturbation balance of node features is achieved. Then, the overall attack process is optimized through an optimal attack path search strategy to ensure that the perturbation is both effective and concealed.
[0060] Through the above solutions, the present invention not only overcomes the limitations of traditional single-step and multi-step attack methods, but also significantly improves the success rate and efficiency of attacks, and reduces the perturbation cost. Experimental results show that the algorithm achieves higher attack success rates and lower perturbation costs on multiple standard datasets, verifying the effectiveness and superiority of the method of the present invention. Description of the Drawings
[0061] Figure 1 is the flowchart of the method of this application;
[0062] Figure 2 is the number of node conversions at different hop counts for different datasets (Cora, Citeseer, CoauthorCS, Polblogs, and SBM);
[0063] Figure 3 is the convergence characteristic and time evolution analysis of DMAA, where (a) is the functional relationship between the budget and the number of converted nodes, and (b) is the functional relationship between the number of converted nodes and the time step;
[0064] Figure 4 is the analysis of the number of attackers and the budget. Detailed Embodiment
[0065] The following further describes the present invention in detail with reference to embodiments:
[0066] In order to achieve an efficient attack on target nodes with the minimum perturbation cost in a complex network environment, the present invention proposes a dynamic multi-step adversarial attack algorithm based on the minimum perturbation budget of graph neural networks, which is generally divided into three main parts: multi-step perturbation budget determination, dynamic perturbation propagation of graph convolutional networks, and optimal attack path search strategy. Its core idea is to select the most attack-worthy nodes or edges according to the current network state in each round of iteration, and gradually expand the influence range on the target group under the premise of a controllable budget. The overall flowchart is as Figure 1 shown.
[0067] From the perspective of multi-step attacks, the attack process can be regarded as gradually establishing adversarial edges between the attacker group and the target group and moderately intervening in node attributes to achieve the conversion of node states. As the attack iterates, the converted nodes can continue to affect their surrounding neighbors, forming a cascading effect. Among them, the solid edges represent the original natural connections in the network, and the dashed edges represent the newly added adversarial connections in the current attack stage. Through this gradually cumulative strategy, the attacker's control ability over the target nodes will continuously increase and eventually extend to the entire target group, achieving a continuous upgrade of the adversarial attack effect.
[0068] 1. Determination of multi-step perturbation budget
[0069] Set a graph G=(A, X), where A∈{0,1} n×n represents the adjacency matrix of the graph, and X∈{0,1} n×d represents the attribute matrix associated with the nodes. The label of each node is represented by Y∈{0,1} n The set of nodes in the graph is defined as and further divided into a training set, a validation set, and a test set, that is For any node v, its feature can be represented as x v ∈{0,1} d , and its corresponding label is y v ∈{0,1}. For the link connectivity between node sets S and T, use A S,T to represent the submatrix of the adjacency matrix A, and use X S to represent the submatrix of node set S in the feature matrix X. In addition, a vector of length m with all elements being 1 is denoted as 1 m .
[0070] The present invention uses a GNN model to construct a hierarchical hidden representation of nodes and outputs the logit scores of the classifier, and the specific formula is shown in Equation (1).
[0071] O = GNN(A, X, W) (1)
[0072] where W is the learnable parameter of GNN, and the predicted label for each node is given by the category with the highest logit score.
[0073] In an adversarial attack scenario, the main goal of the attacker is to impose fine-grained perturbations on the adjacency matrix A and the node feature matrix X to gradually achieve misclassification of the target node v. This goal is usually achieved by maximizing the cumulative loss function of multi-step attacks, thereby enhancing the attack effect and maintaining the attack's concealment. The present invention proposes a multi-step adversarial attack loss function for complex networks, as shown in formula (2), which is used to guide the attack path and optimize the perturbation operation at each step. The GNN parameters W are learned by minimizing the classification loss on the training nodes.
[0074]
[0075] Among them, σ is the softmax activation function, which is used to calculate the classification probability of the target node. represents the set of training nodes. The two regularization constraints in the formula control the degree of perturbation of the graph structure and node features respectively, so as to ensure that the perturbation at each step minimizes the cost while maintaining the attack's effectiveness. represents the sum of the absolute values of the perturbed edges that have been executed in the adjacency matrix, where P A is the actual perturbation set. By restricting the number and magnitude of the perturbed edges, this regularization term optimizes the attack path while controlling the scope of modification to the graph structure, making the perturbation enhance the impact on the target node while maintaining concealment. Similarly, represents the sum of the absolute values of the perturbed features that have been executed in the node feature matrix X, where P X is the actual feature perturbation set. By restricting the magnitude of feature modification, this regularization term effectively reduces unnecessary modification operations, thereby improving the pertinence of the perturbation and the attack efficiency.
[0076] By adjusting the regularization coefficients λ and μ, the attacker can flexibly control the perturbation magnitude according to the requirements of the attack scenario. For example, a larger λ value helps to maintain the original properties of the graph structure, while a smaller value tends to modify the edge relationships more significantly to achieve a stronger attack effect. Similarly, the adjustment of μ can balance the relationship between feature integrity and attack effect, thereby achieving precise misguidance of the target node. To further optimize the execution efficiency of multi-step attacks, the present invention proposes a perturbation budget allocation algorithm based on binary search. This algorithm dynamically sets the upper and lower limits of the perturbation budget at each step, combines the first-order gradient sorting to calculate the priority of possible perturbations, and thus quickly determines the minimum effective perturbation budget B(v). In each step of the operation, the attacker selects the perturbation path with the smallest budget but the greatest impact to gradually accumulate the influence range and achieve the final deviation of the target node classification. Compared with traditional single-step attack methods, the multi-step adversarial attack algorithm proposed by the present invention can make full use of the cumulative effect of perturbations to significantly interfere with complex networks with higher concealment and lower cost.
[0077] This algorithm (Algorithm 1: Binary Search to Find the Minimum Budget) aims to calculate the minimum budget required to misclassify the target node v through binary search. The specific steps are as follows:
[0078] 1. Initialize the boundaries: The algorithm first sets the initial boundaries for the budget. Here, U is set to the degree of node v (i.e., the number of neighbors of this node), and L is set to 0. Here, U is the upper bound of the budget, representing the maximum possible number of perturbations.
[0079] 2. Perform binary search in a loop: In each loop, the budget is bisected to calculate the middle value C, and then it is checked whether the target node v is correctly classified under the current budget.
[0080] 3. Determine the node classification: Use the current budget U to check whether the target node v is correctly classified. If v is correctly classified, the algorithm adjusts the lower bound L, that is, updates it to C. If the classification is incorrect, the upper bound U is updated to C.
[0081] 4. End condition: The algorithm stops until the difference U - L between the upper and lower bounds of the budget is less than or equal to 1.
[0082] 5. Return the result: The finally returned U is the minimum budget required to misclassify the target node v.
[0083] This algorithm gradually narrows the budget range through binary search to find the minimum perturbation budget that changes the classification result of the target node, thus achieving precise control of the minimum value of the perturbation.
[0084] Specifically as follows:
[0085]
[0086]
[0087] The lower limit (L) of the initial perturbation budget is zero, and the upper limit (U = deg(v), where deg(v) is the degree of v) is determined by gradually doubling until a budget value that can successfully perturb the target node is reached. After determining the upper and lower limits, the algorithm gradually approaches the minimum perturbation budget through binary search, ensuring that the budget required for each attack is minimized to save the attack cost. Finally, a minimum perturbation budget that can achieve the attack is determined, and this budget is used to modify the nodes and edges. Through this process, the algorithm can find the minimum perturbation budget required to attack the target node, ensuring the effectiveness of the attack while minimizing the number of perturbations and costs. The training objective provides an optimized starting point, enabling the search for the perturbation budget to be carried out on a more targeted model, reducing unnecessary search calculations, and directly achieving the optimal allocation of the perturbation budget by combining binary search.
[0088] 2. Dynamic Perturbation Propagation of Graph Convolutional Networks
[0089] In adversarial attacks, the attacker's goal is to misclassify the target node. Drawing on the idea of the Carlini-Wagner (CW) attack, adversarial perturbations are carried out by maximizing the gap between classification results. The present invention defines a new adversarial attack loss as shown in formula (3).
[0090]
[0091] Among them, is the predicted score of node v for the true class y v , which comes from the output of the GNN. A high score means that the model has a high confidence in this class. represents the predicted score of node v for another class. The aim is to maximize the adversarial attack loss function so as to make the model's prediction incorrect. Part measures the effect of the attack by comparing the difference between the true class score and the non-true class score. If the score of the true class is much lower than that of the wrong class, the attack loss is zero, which means the attack is successful. This can avoid unnecessary optimization when the attack has already succeeded and save computing resources. κ is a constant and a parameter for controlling the boundary. If κ>0 is set, then the attacker hopes that the score of the wrong class is not only higher than that of the true class, but also this difference should reach at least κ, which can make the attack more stable and more effective in the face of defense mechanisms.
[0092] With this attack target by directly operating on the class scores, the attacker can more precisely control the behavior of the model, making the attack more targeted. Especially when the model has a low classification confidence in a certain sample, the attacker can more easily push the model to make a wrong classification by finely controlling the class scores (logits). This attack method is more effective than directly using the cross-entropy loss because the cross-entropy loss focuses on the global error, while the adversarial attack can precisely manipulate the boundary of the model and perform more targeted perturbations on weakly confident samples. And the κ parameter can control the attack intensity, keeping the amplitude of each attack within a reasonable range. This is very important for attacks with high concealment requirements because smaller perturbations are less likely to be detected. At the same time, the adjustment of k also enables the attack to be dynamically adjusted according to the difficulty of the target node, improving the flexibility and effectiveness of the adversarial attack.
[0093] The present invention proposes a dynamic multi-step adversarial attack propagation method based on the Graph Convolutional Network (GCN), aiming to effectively attack the target node by gradually expanding the influence range of the perturbation. The graph convolution operation is designed as the core propagation mechanism of the attack, which is used to gradually amplify the cumulative effect of the perturbation on the entire network. The specifically designed graph convolution formula is shown in formula (4):
[0094]
[0095] where is the normalized adjacency matrix, and H (l) represents the hidden representation of the l-th layer, and W (l) is the weight of the l-th layer. αR (l) is the attack perturbation regularization term, and R (l) represents the random perturbation noise based on the feature or adjacency matrix. In the scenario of multi-step attacks, the design of αR (l) is used to simulate and enhance the propagation effect of the perturbation. By transmitting and accumulating the influence layer by layer, the concealment and effectiveness of the attack are further improved.
[0096] Specific process of dynamic multi-step perturbation propagation: First is the application of the initial perturbation. According to the set perturbation budget, the adjacency relationship and feature matrix of the target node and its neighborhood are initially modified. The perturbed graph is input into the GCN to extract the new node embedding representation. Then is the multi-step propagation and accumulation. In each step, the new node embedding is calculated through the GCN to capture the propagation effect of the perturbation in the network. As the perturbation gradually expands, its influence range gradually spreads from the target node to more key nodes, thereby achieving the cumulative attack effect. Finally is the introduction of the perturbation regularization term. To ensure that the perturbation in each step is both effective and concealed, the present invention adds an adversarial regularization term in each layer of propagation. By simulating diverse perturbation paths with random noise, the perturbation effect is maximally amplified during the propagation process.
[0097] The key to this process lies in the precise design of the attack target. Specifically, the attack target guides the direction of the explicit perturbation and instructs how to adjust the adjacency matrix and node features to gradually maximize the classification error of the target node. The dynamic propagation strategy analyzes the influence range of the perturbation in each step and dynamically adjusts the propagation path and perturbation amplitude to ensure that the perturbation has a continuous effect on the target node and its neighborhood. In the propagation process of the regularization strategy, the regularization term is not only used to constrain the amplitude of the perturbation, but also avoids the detection of the attack path by introducing randomness, thereby enhancing the concealment of the attack.
[0098] Compared with traditional static attack methods, the dynamic perturbation propagation method of the present invention can gradually amplify the attack influence of perturbations in each layer of the network. By integrating the attack target, dynamic propagation strategy, and adversarial regularization, the algorithm proposed by the present invention achieves the following two core advantages. First is the cumulative attack effect, where multi-step perturbations continuously expand the influence range through layer-by-layer propagation, thus more efficiently achieving the attack target. Second is the balance between stealth and efficiency, which ensures the minimization of the cost of each step of the attack while hiding the perturbation traces by dynamically adjusting the perturbation path and budget allocation.
[0099] 3. Optimal Search Strategy for Attack Paths
[0100] In multi-step adversarial attacks, choosing the appropriate attack path is crucial. The present invention proposes an attack path selection strategy based on maximizing influence and minimizing perturbation cost, aiming to ensure that each step of the attack can maximize the impact on the target graph structure. The entire process of the dynamic multi-step adversarial search strategy is shown in Algorithm 2.
[0101] Overview of the Process of the Dynamic Multi-step Adversarial Search Algorithm:
[0102] (1) Initialize the budget B = 0.
[0103] (2) Iterative process:
[0104] For each target node v ∈ T, calculate the ordered perturbation set used to perturb node v and use Algorithm 1 to calculate the required minimum budget B(v).
[0105] After the calculation, find the node set M with the minimum budget.
[0106] For each node in the set M, calculate its "forward-looking influence" I(v, k), that is, the influence range of the current perturbation.
[0107] Select the node t with the maximum forward-looking influence in M and perturb the network to change the classification of this node, and update the budget B ← B + B(v).
[0108] If the influence I(t) of node t exceeds the threshold α, then perform k perturbations at node t and update the target node set T to those nodes that have successfully been converted to the specified class.
[0109] (3) Repeat the above steps until all target nodes C are successfully converted.
[0110] Finally, the algorithm returns the calculated minimum budget B, that is, the minimum perturbation budget required to convert the target node set to the category desired by the attacker during the multi-step perturbation process.
[0111] This algorithm gradually reduces the perturbation cost and improves the attack effect by dynamically adjusting the perturbation path, selecting perturbation nodes, and considering the forward-looking impact of each node.
[0112] The details are as follows:
[0113]
[0114]
[0115] From the set of target nodes, select those nodes that are most sensitive to the model prediction as the priority targets for the current attack. By calculating the classification margin value of the nodes, select the node with the smallest margin value for attack to ensure the success rate of the attack. In each step, evaluate the potential impact of the perturbation on the entire network and select the attack path that can maximize the influence. Through the global analysis of the graph structure, determine the nodes and edges with the greatest influence within the budget as the attack objects. After each step of the attack, the algorithm dynamically adjusts the path according to the actual effect of the attack, selects new target nodes and edges to ensure that the attack can achieve the optimal effect at the minimum cost.
[0116] Through this optimal search strategy for the attack path, the multi-step adversarial attack algorithm of the present invention can make full use of the perturbation budget in each step of operation, gradually expand the attack range, and finally achieve a continuous attack on the entire target network. This strategy not only ensures the concealment of the attack but also improves the overall efficiency of the attack by dynamically adjusting the path selection.
[0117] 4. Experimental Environment and Datasets
[0118] To evaluate the DMAA algorithm proposed in the present invention, we selected datasets of real-world networks and synthetic networks for experimental analysis. The statistical data of all benchmark tests are shown in Table 1.
[0119] Cora and Citeseer are two-population subgraphs extracted from multi-population citation networks, which contain sparse bag-of-words feature vectors as the attributes of nodes. CoAuthorCS is a two-population subgraph of a multi-population cooperation network, and its node feature vectors are in binary form, indicating the presence of keywords. Polblogs is a real-world political blog network dataset, and the labels represent the political tendencies of the blogs, including two classifications: liberal and conservative. SBM is a commonly used random graph model for generating network data with community structure. For Polblogs and SBM, we use the one-hot encoding of the node labels as the feature vectors.
[0120] Table 1. Overall Dataset Statistics
[0121]
[0122] To verify the effectiveness of the proposed DMAA algorithm of the present invention, it was compared with the following attack baseline methods. NETTACK generates subtle perturbations on edges and features by attacking a linearized two-layer GCN proxy, and the perturbations are sorted through fast scoring. FGA generates link perturbations by calculating the first-order gradient of the attack loss and recalculates the gradient after each perturbation. For these two single-step attack methods, the present invention finds the minimum perturbation budget of the target node through binary search and aggregates the total budget of all node-level perturbations.
[0123] In addition, to systematically evaluate the performance of the DMAA algorithm and analyze the contributions of key modules, the following 4 groups of experiments were designed under the same experimental environment. MAC-Fixed and DMAA-Fixed represent perturbation strategies that fix the potential attack effect, analyzing the effect of maintaining a constant influence during the dynamic attack process. MAC and DMAA represent the expected attack effects of dynamically adjusting the perturbation path and target nodes.
[0124] Finally, for the GNN model baseline, the present invention selected the following popular GNN backbone architectures for comparison. GCN is a first-order approximation model of a spectral GNN, used as a low-pass filter, and the node aggregation function is where is the symmetric normalized graph Laplacian matrix. GraphSAGE is a general GNN architecture that can be extended to large-scale graphs. The average aggregation strategy is adopted in the present invention. It should be noted that the degree of the source node has an important influence on the aggregation process of GCN, while it has less influence on GraphSAGE.
[0125] All experimental models were trained and attacked on an NVIDIA RTX3060 GPU with 32GB of RAM. Through the above experiments, the performance superiority of the dynamic multi-step adversarial attack algorithm of the present invention on various datasets was verified, and the performance of multi-step adversarial attacks in different GNN architectures was further analyzed.
[0126] The present invention has conducted experiments, and the multi-step adversarial attack effect is very ideal, which is consistent with the design expectation.
[0127] The experimental comparison results of the proposed DMAA algorithm with single-step and multi-step attacks on 5 benchmark datasets of the GCN and SAGE core models are shown in Table 2, which shows the perturbation budgets consumed by different algorithms during the attack process. The budget represents the number of modifications to the edges and node features of the graph during the attack process, and its amount is a core indicator for measuring the efficiency, cost, and attack success rate of the attack algorithm. A smaller budget means a more efficient attack. The results of the GCN and SAGE two graph neural network structures on multiple datasets were compared to verify the performance of the algorithm under different network structures.
[0128] The experimental results show that DMAA is superior to single-step and multi-step attacks. Single-step attacks do not take into account the cascading effect of perturbations, so they are either unsuccessful (with an infinite budget) or require a high budget. In addition, due to the limitation of non-obvious perturbations, NETTACK generates a high budget, while FGA does not consider feature perturbations. Multi-step dynamic adversarial attacks are more effective because they can discover effective multi-hop attack paths through the transformed targets. However, during the experiment, it was found that when only link perturbations or only feature perturbations are used in each step of the attack, the results will not converge on Cora, Citeseer, and CoauthorCS, that is, the transformed targets switch back and forth because the perturbations in the subsequent steps may cause them to move across the classifier boundary again, which emphasizes that both link and feature perturbations are necessary for strong multi-step attacks.
[0129] In addition, the cumulative effect of feature perturbations in the network gradually increases in multiple attack steps. By comparing DMAA-Fixed and DMAA, MAC-Fixed and MAC, we are able to analyze the effectiveness differences between the fixed perturbation strategy and the strategy of dynamically adjusting paths and target nodes. The results show that in almost all cases, the dynamic adjustment strategy can effectively reduce budget consumption. The DMAA model maximizes the attack effect with less budget by strategically applying critical perturbations to target nodes at each step and further spreading the influence to other nodes. The experimental results verify the superiority of the DMAA model on multiple datasets. Compared with existing models, DMAA shows significant performance improvement in implementing dynamic multi-step adversarial attacks. Especially in terms of node conversion rate and perturbation budget, DMAA not only achieves higher efficiency but also reduces resource waste. In addition, DMAA can capture complex node relationships and dynamic features, and this ability significantly improves the stealth and success rate of the attack. Through these innovations, the method proposed in the present invention provides an efficient and stealthy implementation approach for multi-step adversarial attacks in complex networks, demonstrating its potential in practical applications.
[0130] Table 2. Experimental results of comprehensive evaluation
[0131]
[0132] The main advantage of the dynamic multi-step adversarial attack proposed in the present invention compared to single-step attacks is that it can discover multi-hop paths of the attack. Figure 2For Cora, Citeseer, CoauthorCS, Polblogs, and SBM, the number of converted nodes of DMAA decreases rapidly as the hop distance increases, indicating that nodes at close range are more vulnerable to attacks, while nodes at long range require more budget. This shows that the DMAA model has an obvious cascading effect. Nodes at close range are more easily attacked and converted into target nodes, while with the increase of hop count, remote nodes require more perturbation budget to be converted. Although the number of converted nodes decreases as the hop count increases, there are still many target nodes that are converted through multi-hop paths. The target nodes converted by DMAA in the initial stage then become the preferred attackers. DMAA can even discover attack paths of length 7, indicating the dynamics of the attack. Therefore, DMAA attacks tend to cascade conversion, similar to a dynamic infection propagation model. However, the minimum budget DMAA should be regarded as a targeted infection that spreads to more vulnerable target nodes rather than being random.
[0133] A converted node refers to a target node whose predicted class successfully changes by perturbing the adjacency matrix and node features during the dynamic multi-step adversarial attack. If the number of converted nodes is large, it indicates that the attack algorithm can effectively utilize the limited perturbation budget to misclassify the target nodes. This is a direct reflection of the attack success rate. In the DMAA model, the attack will preferentially select nodes that are more easily perturbed, that is, those nodes that have a greater influence on the overall network or are more vulnerable. This selection can convert more nodes with less budget, indicating that the model is efficient. When DMAA discovers longer multi-hop paths, it shows that the scope of the attack is larger and can indirectly attack remote nodes through the cascading effect. This dynamic multi-hop path attack demonstrates the diffusion ability of the algorithm. Nodes closer to the attack source are more easily attacked successfully due to the direct influence of the perturbation, so the number of conversions is larger. As the hop count increases, it takes more perturbation budget to spread to remote nodes, and it is also restricted by the network structure and node features, so the number of converted nodes decreases.
[0134] To understand how DMAA unfolds over time, the present invention plots the budget of the converted nodes and the time function of the converted nodes of DMAA and DMAA-Fixed in Figure 3 (a) and Figure 3 (b) respectively. The converted nodes represent the number of nodes that are successfully attacked and converted into the target class, and the budget represents the number of modifications to the edges and node features of the graph consumed during the attack process. Figure 3 (a) shows the budget expenditure as a function of the increasing number of converted targets, Figure 3(b) is the target number converted for the budget expenditure as a function of the time step. The dashed and solid lines represent DMAA-Fixed and DMAA respectively. The experimental results show that DMAA and DMAA-Fixed have similar number of iteration steps (Time steps) required to complete the conversion of the same number of nodes, but DMAA uses less budget and shows higher efficiency. It can be seen that for DMAA-Fixed, the budget grows linearly as a function of the conversion nodes, and the conversion nodes also grow linearly as a function of the number of steps. Therefore, DMAA-Fixed is a conservative attack because it applies influential perturbations at each conversion node regardless of its impact, so it has a fast convergence speed and a high budget. In contrast, for DMAA, both the budget and the converted nodes grow sub-linearly. Therefore, although it takes longer to converge than DMAA-Fixed, it creates influential perturbations more strategically than DMAA-Fixed, thus spending less budget.
[0135] Figure 4 is for the budget as a function of the increase in the number of attackers in the source set. As the number of attackers increases, the budget almost monotonically decreases because the more attackers there are, the larger the range of easily attackable targets. This reflects that the DMAA algorithm proposed by the present invention can efficiently utilize attack resources in a distributed network environment, especially in the scenario of multi-attacker collaborative operation, and its optimization strategy has stronger adaptability. This not only improves the practical application ability of the algorithm in complex network topologies, but also provides theoretical support and technical guarantee for dealing with distributed attacks in reality.
Claims
1. A dynamic multi-step adversarial attack method based on minimum perturbation budget of graph neural network, characterized by The following steps are involved: Step S1: During the training of the graph neural network, the classification loss on the training nodes is minimized, and the optimal target of each perturbation step is clarified by defining a new multi-step adversarial attack loss function. On this basis, a binary search-based strategy is adopted to dynamically allocate the minimum perturbation budget for each round of attack, and the minimum perturbation budget is used to achieve misleading of the target node classification; Step S2: After determining the available perturbation budget for each step, the layered propagation mechanism of the graph convolutional network is used to gradually spread the perturbation to more nodes to form a cumulative attack effect. By modifying the adjacency matrix and node features, and coordinating the regularization or random noise terms in each layer of graph convolution, the impact on the target node is amplified layer by layer, thereby achieving a highly concealed multi-step attack. Step S3: After completing a round of disturbance and observing the attack effect, dynamically evaluate the nodes in the current network that have not been misled, select the priority attack nodes and disturbance paths for the next step; and combine the aforementioned disturbance budget allocation and dynamic propagation strategy to continuously expand the scope of influence on the entire network.
2. According to claim 1, a dynamic multi-step adversarial attack method based on minimum perturbation budget of graph neural network is characterized in that: The classification loss on the training nodes in step S1 is minimized, as shown in formula (2), which is used to guide the attack path and optimize the perturbation operation at each step. The GNN parameter W is learned by minimizing the classification loss on the training nodes. Among them, σ is the softmax activation function, which is used to calculate the classification probability of the target node; represents the set of training nodes, represents the sum of the absolute values of the perturbations performed in the adjacency matrix, where P A is the actual disturbance set; represents the absolute value sum of the perturbation features executed in the node feature matrix X, where P X is the actual feature perturbation set; The two regularization constraints in the formula control the degree of disturbance of the graph structure and node features respectively, ensuring that the disturbance at each step minimizes the cost while maintaining the effectiveness of the attack. By limiting the number and amplitude of the perturbed edges, this regularization term optimizes the attack path while controlling the scope of modification to the graph structure, allowing the disturbance to maintain concealment while enhancing the impact on the target node.
3. The dynamic multi-step adversarial attack method based on minimum perturbation budget of graph neural network according to claim 1, characterized in that: The multi-step adversarial attack loss function in step S1 is shown in formula (3): in, is the node v for the true category y v The prediction score comes from the output of GNN. It represents the predicted score of node v for another category, with the goal of maximizing the loss function of the adversarial attack. This causes the model’s predictions to be wrong. The effectiveness of the attack is measured in part by comparing the difference between the true class score and the non-true class score; κ is a constant and a parameter that controls the boundary.
4. The dynamic multi-step adversarial attack method based on graph neural network minimum perturbation budget according to claim 1, characterized in that: In step S1, the minimum effective perturbation budget B(v) is determined by a perturbation budget allocation algorithm based on binary search. The algorithm calculates a sorting gradient by dynamically setting the upper and lower limits of the perturbation budget for each step. These gradients are then searched equally to find the minimum set of perturbations required to transform v, thereby quickly determining the minimum effective perturbation budget.
5. A dynamic multi-step adversarial attack method based on graph neural network minimum perturbation budget according to claim 4, characterized in that The specific steps of the perturbation budget allocation algorithm based on binary search are as follows: S1.1, Initialization Boundary: The algorithm first sets the initial boundary for the budget. The lower limit L of the initial perturbation budget is zero, and the upper limit U = deg(v) is determined by gradually doubling it, where deg(v) is the degree of v, until a budget value U is reached that can successfully perturb the target node v, thereby determining the upper bound U; S1.2, loop to perform binary search: In each loop, the budget is divided into two parts, the middle value C is calculated, and then it is checked whether the current budget can be used. ’s top-C perturbation, whether v can be correctly classified; S1.3, determine node classification: use the current budget C to check whether the target node v is correctly classified. If v is correctly classified, the algorithm will adjust the lower bound L, that is, update it to C. If the classification is incorrect, the upper bound U is updated to C. S1.4, End condition: The algorithm stops until the difference UL between the upper and lower bounds of the budget is less than or equal to 1; S1.
5. Return result: The final returned value U is the minimum budget required to make the target node v misclassified; in, Represents the ordered perturbation set obtained after gradient merging and sorting of all candidate perturbations, including modifications of edge and node features; The top-U perturbations in represent taking the top U perturbations with the highest scores from the sorted perturbation set. Top-C perturbations: When testing at the intermediate budget C of the binary search, these C optimal perturbations are used to check whether the target node v has been successfully attacked; Finally, a minimum perturbation budget that can realize the attack is determined, and the budget is used to modify the nodes and edges.
6. The dynamic multi-step adversarial attack method based on graph neural network minimum perturbation budget according to claim 1, characterized in that: The layered propagation method of the graph convolutional network in step S2 gradually spreads the disturbance to more nodes, forming a cumulative attack effect. The graph convolution formula is shown in formula (4): in, is the normalized adjacency matrix, H (l) represents the hidden representation of the lth layer, W (l) is the weight of the lth layer, αR (l) is the attack perturbation regularization term, R (l) represents random perturbation noise based on features or adjacency matrix. In the multi-step attack scenario, αR (l) The design is used to simulate and enhance the propagation effect of disturbances, and the cumulative impact is transmitted layer by layer, so that the concealment and effectiveness of the attack are further improved.
7. The dynamic multi-step adversarial attack method based on minimum perturbation budget of graph neural network according to claim 6, characterized in that: In step S2, the layered propagation mechanism of the graph convolutional network is used to gradually spread the disturbance to more nodes, forming a cumulative attack effect, that is, the specific process of dynamic multi-step disturbance propagation: A. The application of initial perturbation, based on the set perturbation budget, initially modifies the adjacency relationship and feature matrix of the target node and its neighborhood. The perturbed graph is input into GCN to extract a new node embedding representation; B. Multi-step propagation accumulation. In each step, new node embedding is calculated through GCN to capture the propagation effect of the disturbance in the network. As the disturbance gradually expands, its influence range gradually spreads from the target node to more key nodes, achieving a cumulative attack effect. The introduction of the C perturbation regularization term, in order to ensure that the perturbation at each step is both effective and hidden, adds an adversarial regularization term in each layer of propagation, and simulates diversified perturbation paths through random noise, so that the perturbation effect is maximized during the propagation process.
8. The dynamic multi-step adversarial attack method based on graph neural network minimum perturbation budget according to claim 1, characterized in that: Step S3: After completing a round of disturbance and observing the attack effect, dynamically evaluate the nodes in the current network that have not been misled, and select the priority attack nodes and disturbance paths for the next step. The process of the dynamic multi-step adversarial search strategy is as follows: Step S3.1, Initialize attack parameters and budget settings: Input parameters: The input of the algorithm includes the graph structure G = (A, X), the attacker set S, the target node set T, the target node set C to be converted, the initial value of the perturbation budget, and the threshold α; Initialization budget: Initially, the attack budget is set to zero, and the goal of the attack is to gradually convert the nodes in the target node T from the normal state to the misclassified state and complete the conversion under the minimum budget. Step S3.2, calculate the disturbance budget of each target node: Multi-step perturbation computation: For each target node v∈T, compute an ordered set of perturbations for transforming v And call the previous binary search algorithm to calculate the minimum perturbation budget B(v) of the node; Step S3.3: Dynamically adjust the attack path and disturbance budget: Select the minimum budget node: By calculating the perturbation budget of each node, select the node set M that requires the least budget. For each node v∈M, calculate its forward-looking influence I(v,k), that is, evaluate the potential impact of future perturbations on the entire network; this influence value is used to decide which nodes to attack first; Step S3.4, attack path selection and node perturbation: Select the most influential node: Based on the forward-looking influence, select the most influential node t∈M for perturbation, apply the perturbation to the network, update the state of the target node, make it move towards the direction of misclassification, and increase the consumed attack budget; Budget update: When the disturbance of node t meets the conditions (for example, I(t)>α, indicating that the influence of the node on the network has increased significantly), a large disturbance is performed and the corresponding budget is updated; Step S3.5: Adjust the attack target and update the test set: During the attack, as the target node is transformed, the test set is recalculated and updated. In order to further evaluate and expand the attack effect; Step S3.6, loop execution until all target nodes are converted: The above steps are dynamically executed in each attack round until all target nodes C are successfully converted into misclassified nodes. Each time the attack is executed, the most effective attack path and nodes are continuously evaluated to ensure the concealment, continuity and maximum effect of the attack. Step S3.7, end condition and output: When all the predetermined target nodes C are converted, the algorithm ends and returns the required total attack budget, which represents the minimum budget required to complete the multi-step adversarial attack.
9. The method of claim 8 for dynamic multi-step adversarial attack based on minimum perturbation budget of graph neural network, characterized in that: From the target node set, select those nodes that are most sensitive to the model prediction as the priority targets of the current attack. By calculating the classified edge values of the nodes, select the nodes with the smallest edge values for attack to ensure the success rate of the attack. In each step, evaluate the potential impact of the disturbance on the entire network, and select the attack path that can maximize the impact. Through a global analysis of the graph structure, determine the nodes and edges with the greatest impact within the budget as the attack targets. After each attack step, the algorithm dynamically adjusts the path according to the actual effect of the attack and selects new target nodes and edges to ensure that the attack can achieve the best effect at the lowest cost.
Citation Information
Cited By
Unmanned aerial vehicle confrontation scheduling method with low-tuning measurement
CN121277228A
A low-scheduling metric drone counter-scheduling method
CN121277228B
Node injection attack method based on adaptive target selection
CN121485896A
A Citation Classification Method and System Based on Dual Robust Adaptive Graph Neural Network
CN122570724A