发表机构
Southeast University; Nanyang Technological University(东南大学; 南洋理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对现有图对抗净化方法领域受限的缺陷,提出ProGAP方案,通过漏洞感知图提示学习实现可迁移图净化,性能提升1%-9%且时间消耗最多减少2.2倍。
AI 中文摘要
图神经网络(GNNs)已成为在各类多媒体任务中表示复杂关系依赖的核心技术,尤其在跨平台用户兴趣建模和跨模态语义对齐领域应用广泛。在现实场景中,亟需一种能抵御图对抗扰动的实用防御方案。然而,我们发现主流的对抗净化方法本质上是领域受限的防御,存在以下缺陷:(1)单域数据无法提供足够的结构和语义多样性来学习鲁棒的净化准则;(2)从头训练特定领域的防御策略会消耗大量计算成本。为解决上述局限,我们提出一种名为ProGAP的可迁移图净化方案,通过漏洞感知图提示学习桥接对抗防御知识。首先,为捕捉通用对抗模式,我们在数据丰富的图上预训练了一个扰动捕获边检测器,联合建模拓扑和语义信息;随后,为实现更具鲁棒性的知识迁移,我们设计了漏洞感知提示,将针对性的净化指导注入有偏差的节点,在此过程中,预训练的检测器无需进行大量参数更新即可适配下游图的分布偏移。实验结果表明,与当前最优基线相比,我们的ProGAP实现了1%-9%的性能提升,且时间消耗最多减少2.2倍。ProGAP的代码可在该httpsURL获取。
英文摘要
Graph Neural Networks (GNNs) have emerged as a cornerstone for representing complex relational dependencies in diverse multimedia tasks, particularly in cross-platform user interest modeling and cross-modal semantic alignment. In the real world, a practical defense against graph adversarial perturbations is needed. However, we observe that the prevailing adversarial purification methods are essentially domain-restricted defenses, which leads to the following shortcomings: (1) single-domain data provides insufficient structural and semantic diversity for learning robust purification criteria; (2) training of domain-specific defense strategies from scratch consumes substantial computational cost. To address the above limitations, we propose a transferable graph purification scheme, named ProGAP, to bridge adversarial defense knowledge via vulnerability-aware graph prompt learning. Firstly, to capture universal adversarial patterns, a perturbation-capture edge detector is pretrained on data-rich graphs by jointly modeling topological and semantic information. Subsequently, to achieve more knowledge transfer w.r.t. robustness, vulnerability-aware prompts are designed that inject targeted purification guidance into biased nodes, during which the pretrained detector adapts to distribution shifts in downstream graphs without parameter-laborious updates. Experimental results demonstrate that compared with state-of-the-art baselines, our ProGAP achieves 1%-9% improvement, and reduces the time consumption by up to 2.2x. The code for ProGAP is available at https://github.com/Lieyoufffff/ProGAP.
CommentsTo appear in the Proceedings of the 34th ACM International Conference on Multimedia (MM '26). 10 pages, 7 figures, and 4 tables. Shuomin Xue and Jingyuan Li contributed equally to this work