arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

MUGEN:面向多学习任务的不可学习图示例生成框架

MUGEN: Generating Unlearnable Graph Examples for Multiple Learning Tasks

Ziyan Liu, Chengshuai Zhao, Huan Liu

arXiv 2609.00696首次发表:更新:

发表机构

Harrisburg University of Science and Technology; Arizona State University(哈里斯堡科技大学; 亚利桑那州立大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

MUGEN是首个面向多学习任务的不可学习图示例生成框架,通过TASO与TAP技术,生成可跨GNN骨干和任务迁移的防御性扰动图数据,在多基准实验中表现有效。

AI 中文摘要

不同领域的图数据会向未授权的表示学习暴露有价值的关系信息,因此亟需防御此类滥用。不可学习示例通过扰动训练发布数据实现数据级防御,使在该数据上训练的模型无法泛化到干净数据。现有方法仅为指定下游任务生成不可学习图示例,导致针对某一任务的防御发布数据,可能对节点分类、图分类、链接预测等数据所有者无法预判的其他合理用途仍具备可学习性。我们提出MUGEN,据我们所知,首个针对所有启用任务联合防御的不可学习图示例生成框架。从一个干净数据集出发,MUGEN生成单个经特征扰动的发布数据,通过共享GNN编码器与任务特定头,对所有启用任务实现防御。我们设计了任务对齐可分性目标(TASO),利用任务预测与类别可分性,增强不可学习性及其在GNN骨干与启用任务间的迁移性;还提出了类型自适应扰动(TAP),针对节点属性类型定制扰动优化:对离散节点属性,仅接受提升损失的可行硬翻转直接搜索;对连续节点特征,采用定制的基于梯度的更新,从而在两种设置下均实现强不可学习性。在五个基准、四个骨干、三种学习范式上的实验表明,MUGEN生成的不可学习图示例可在GNN骨干与所有三个任务间迁移,且在对抗训练与数据增强下仍保持有效。

英文摘要

Graph data across diverse domains can expose valuable relational information to unauthorized representation learning, creating a pressing need for protection against such misuse. Unlearnable examples offer a data-level defense by perturbing a training release so that models trained on it fail to generalize to clean data. Existing methods generate unlearnable graph examples for only a specified downstream task. Consequently, a release protected against one task may remain learnable for other plausible uses, including node classification, graph classification, and link prediction, which the data owner cannot anticipate. We introduce MUGEN, to our knowledge the first framework for generating unlearnable graph examples that jointly protect all enabled tasks. From one clean dataset, MUGEN produces a single feature-perturbed release that protects every enabled task through a shared GNN encoder and task-specific heads. We devise a Task-Aligned Separability Objective (TASO), which leverages task prediction and classwise separability to strengthen unlearnability and its transfer across GNN backbones and enabled tasks. We further introduce Type-Adaptive Perturbation (TAP), which tailors perturbation optimization to node-attribute type, with direct search over feasible hard flips that accept only loss-improving updates for discrete node attributes and customized gradient-based updates for continuous node features, thereby enabling strong unlearnability across both settings. Experiments across five benchmarks, four backends and three learning paradigms demonstrate that MUGEN generates transferable unlearnable graph examples across GNN backbones and all three tasks, and remains effective under adversarial training and data augmentation.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑