Skip to main content
QUICK REVIEW

[논문 리뷰] Adversarial Diffusion Attacks on Graph-based Traffic Prediction Models

Lyuyi Zhu, Kairui Feng|arXiv (Cornell University)|2021. 04. 19.
Traffic Prediction and Management Techniques참고 문헌 42인용 수 6
한 줄 요약

이 논문은 실시간 교통 예측 모델을 대상으로 하는 새로운 적대적 확산 공격 기법을 제안한다. 이 기법은 Simultaneous Perturbation Stochastic Approximation (SPSA)를 통한 블랙박스 기반 기울기 근사와 훈련 기반 탐색 전략을 활용하며, 여러 GCN 기반 모델(St-GCN, T-GCN, A3t-GCN)에 대해 실세계 데이터셋 두 개에서 성능 저하를 유도한다. 특히 DropEdge 정규화 조건 하에서 최대 72.37%의 공격 성공률를 기록하여 스마트 이동 시스템의 심각한 취약성을 드러낸다.

ABSTRACT

Real-time traffic prediction models play a pivotal role in smart mobility systems and have been widely used in route guidance, emerging mobility services, and advanced traffic management systems. With the availability of massive traffic data, neural network-based deep learning methods, especially the graph convolutional networks (GCN) have demonstrated outstanding performance in mining spatio-temporal information and achieving high prediction accuracy. Recent studies reveal the vulnerability of GCN under adversarial attacks, while there is a lack of studies to understand the vulnerability issues of the GCN-based traffic prediction models. Given this, this paper proposes a new task -- diffusion attack, to study the robustness of GCN-based traffic prediction models. The diffusion attack aims to select and attack a small set of nodes to degrade the performance of the entire prediction model. To conduct the diffusion attack, we propose a novel attack algorithm, which consists of two major components: 1) approximating the gradient of the black-box prediction model with Simultaneous Perturbation Stochastic Approximation (SPSA); 2) adapting the knapsack greedy algorithm to select the attack nodes. The proposed algorithm is examined with three GCN-based traffic prediction models: St-Gcn, T-Gcn, and A3t-Gcn on two cities. The proposed algorithm demonstrates high efficiency in the adversarial attack tasks under various scenarios, and it can still generate adversarial samples under the drop regularization such as DropOut, DropNode, and DropEdge. The research outcomes could help to improve the robustness of the GCN-based traffic prediction models and better protect the smart mobility systems. Our code is available at https://github.com/LYZ98/Adversarial-Diffusion-Attacks-on-Graph-based-Traffic-Prediction-Models

연구 동기 및 목표

  • 그래프 컨volution 네트워크(GCN) 기반 교통 예측 모델이 적대적 공격에 얼마나 취약한지 조사한다.
  • 전반적인 모델 성능 저하를 유도하기 위해 소수의 노드를 대상으로 하는 새로운 공격 패러다임인 확산 공격을 개발한다.
  • DropEdge, DropNode, Dropout과 같은 다양한 방어 메커니즘 하에서 GCN 기반 모델의 강건성(로버스트니)을 평가한다.
  • 모델에 대한 전체 액세스 없이도 작동하는 효율적인 블랙박스 공격 알고리즘을 설계한다.

제안 방법

  • Simultaneous Perturbation Stochastic Approximation (SPSA)를 활용해 블랙박스 교통 예측 모델의 기울기를 근사함으로써 기울기 기반 공격 생성을 가능하게 한다.
  • 모델 성능에 미치는 영향을 기반으로 영향력이 큰 노드를 선별하기 위해 컨테이너 기반 그레디 알고리즘을 적용한다.
  • 이중 단계 공격 프레임워크를 활용한다: 첫 번째 단계에서는 SPSA를 통해 영향력이 큰 노드를 식별하고, 두 번째 단계에서는 이러한 노드에 변형을 가해 성능 저하를 극대화한다.
  • 실세계 교통 데이터셋 두 개(LA 및 HK)에서 세 종류의 GCN 기반 모델(St-GCN, T-GCN, A3t-GCN)에 대해 공격를 검증한다.
  • DropEdge, DropNode, Dropout과 같은 다양한 정규화 방어 메커니즘 하에서 공격 효과성을 평가한다.
  • 공격 프레임워크와 평가 코드를 GitHub에 오픈소스로 배포하여 재현성과 향후 연구를 지원한다.

실험 결과

연구 질문

  • RQ1제안된 확산 공격가 블랙박스 환경에서 GCN 기반 교통 예측 모델의 성능 저하에 얼마나 효과적인가?
  • RQ2DropEdge, DropNode, Dropout과 같은 표준 방어 메커니즘이 적용된 상황에서도 공격가 높은 성공률를 유지할 수 있는가?
  • RQ3기울기 근사 기법으로 SPSA를 사용한 공격 전략이 다른 공격 전략 대비 공격 성공률에서 어떤 차이를 보이는가?
  • RQ4노드 선별 전략(예: 컨테이너 기반 vs. 중심성 기반)이 공격 효과성에 어떤 영향을 미치는가?
  • RQ5국소적 변형에도 불구하고 전체 그래프에 걸쳐 성능 저하가 얼마나 광범위하게 퍼지는가?

주요 결과

  • 기본 조건 하에서 LA 데이터셋에서 St-GCN에 대해 평균 8.32%의 공격 성공률, T-GCN에 대해 7.76%, A3t-GCN에 대해 22.77%의 성공률 기록.
  • DropEdge 정규화 조건 하에서 LA의 St-GCN에 대해 13.88%의 성공률, HK의 St-GCN에 대해 46.36%의 성공률 기록하여 엣지 수준 방어에 강건함을 입증.
  • Dropout(11.36% 성공률, LA의 St-GCN), DropNode(38.11% 성공률, LA의 A3t-GCN) 조건 하에서도 높은 효과성 유지하여 노드 수준 정규화에 대한 강건성 입증.
  • Kg-Spsa는 Pagerank 및 Betweenness 기반의 반블랙박스 기반 공격보다 우수한 성능을 보이며, HK의 A3t-GCN에서 DropEdge 조건 하에 72.37%의 공격 성공률 기록.
  • 강력한 방어 조건 하에서도 공격가 효과를 유지함: HK의 A3t-GCN에서 DropEdge 조건 하에 230.85%의 공격 성공률 기록으로 심각한 취약성 드러냄.
  • 오픈소스 구현을 통해 재현성이 보장되며, 그래프 기반 교통 모델의 강건성 및 방어 기법 연구에 기여할 수 있음.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.