

<!DOCTYPE html>
<html class="writer-html5" lang="en" >
<head>
  <meta charset="utf-8">
  
  <meta name="viewport" content="width=device-width, initial-scale=1.0">
  
  <title>deeprobust.graph.global_attack.mettack &mdash; DeepRobust 0.1.1 documentation</title>
  

  
  <link rel="stylesheet" href="../../../../_static/css/theme.css" type="text/css" />
  <link rel="stylesheet" href="../../../../_static/pygments.css" type="text/css" />

  
  
  
  

  
  <!--[if lt IE 9]>
    <script src="../../../../_static/js/html5shiv.min.js"></script>
  <![endif]-->
  
    
      <script type="text/javascript" id="documentation_options" data-url_root="../../../../" src="../../../../_static/documentation_options.js"></script>
        <script type="text/javascript" src="../../../../_static/jquery.js"></script>
        <script type="text/javascript" src="../../../../_static/underscore.js"></script>
        <script type="text/javascript" src="../../../../_static/doctools.js"></script>
        <script type="text/javascript" src="../../../../_static/language_data.js"></script>
        <script async="async" type="text/javascript" src="https://cdnjs.cloudflare.com/ajax/libs/mathjax/2.7.5/latest.js?config=TeX-AMS-MML_HTMLorMML"></script>
    
    <script type="text/javascript" src="../../../../_static/js/theme.js"></script>

    
    <link rel="index" title="Index" href="../../../../genindex.html" />
    <link rel="search" title="Search" href="../../../../search.html" /> 
</head>

<body class="wy-body-for-nav">

   
  <div class="wy-grid-for-nav">
    
    <nav data-toggle="wy-nav-shift" class="wy-nav-side">
      <div class="wy-side-scroll">
        <div class="wy-side-nav-search" >
          

          
            <a href="../../../../index.html" class="icon icon-home" alt="Documentation Home"> DeepRobust
          

          
          </a>

          
            
            
          

          
<div role="search">
  <form id="rtd-search-form" class="wy-form" action="../../../../search.html" method="get">
    <input type="text" name="q" placeholder="Search docs" />
    <input type="hidden" name="check_keywords" value="yes" />
    <input type="hidden" name="area" value="default" />
  </form>
</div>

          
        </div>

        
        <div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="main navigation">
          
            
            
              
            
            
              <p class="caption"><span class="caption-text">Installation</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../../../notes/installation.html">Installation</a></li>
</ul>
<p class="caption"><span class="caption-text">Graph Package</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../../../graph/data.html">Graph Dataset</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../graph/attack.html">Introduction to Graph Attack with Examples</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../graph/defense.html">Introduction to Graph Defense with Examples</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../graph/pyg.html">Using PyTorch Geometric in DeepRobust</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../graph/node_embedding.html">Node Embedding Attack and Defense</a></li>
</ul>
<p class="caption"><span class="caption-text">Image Package</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../../../image/example.html">Image Attack and Defense</a></li>
</ul>
<p class="caption"><span class="caption-text">Image Package</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.image.attack.html">deeprobust.image.attack package</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.image.defense.html">deeprobust.image.defense package</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.image.netmodels.html">deeprobust.image.netmodels package</a></li>
</ul>
<p class="caption"><span class="caption-text">Graph Package</span></p>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.graph.global_attack.html">deeprobust.graph.global_attack package</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.graph.targeted_attack.html">deeprobust.graph.targeted_attack package</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.graph.defense.html">deeprobust.graph.defense package</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../../../source/deeprobust.graph.data.html">deeprobust.graph.data package</a></li>
</ul>

            
          
        </div>
        
      </div>
    </nav>

    <section data-toggle="wy-nav-shift" class="wy-nav-content-wrap">

      
      <nav class="wy-nav-top" aria-label="top navigation">
        
          <i data-toggle="wy-nav-top" class="fa fa-bars"></i>
          <a href="../../../../index.html">DeepRobust</a>
        
      </nav>


      <div class="wy-nav-content">
        
        <div class="rst-content">
        
          















<div role="navigation" aria-label="breadcrumbs navigation">

  <ul class="wy-breadcrumbs">
    
      <li><a href="../../../../index.html" class="icon icon-home"></a> &raquo;</li>
        
          <li><a href="../../../index.html">Module code</a> &raquo;</li>
        
      <li>deeprobust.graph.global_attack.mettack</li>
    
    
      <li class="wy-breadcrumbs-aside">
        
      </li>
    
  </ul>

  
  <hr/>
</div>
          <div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article">
           <div itemprop="articleBody">
            
  <h1>Source code for deeprobust.graph.global_attack.mettack</h1><div class="highlight"><pre>
<span></span><span class="sd">&quot;&quot;&quot;</span>
<span class="sd">    Adversarial Attacks on Graph Neural Networks via Meta Learning. ICLR 2019</span>
<span class="sd">        https://openreview.net/pdf?id=Bylnx209YX</span>
<span class="sd">    Author Tensorflow implementation:</span>
<span class="sd">        https://github.com/danielzuegner/gnn-meta-attack</span>
<span class="sd">&quot;&quot;&quot;</span>

<span class="kn">import</span> <span class="nn">math</span>
<span class="kn">import</span> <span class="nn">numpy</span> <span class="k">as</span> <span class="nn">np</span>
<span class="kn">import</span> <span class="nn">scipy.sparse</span> <span class="k">as</span> <span class="nn">sp</span>
<span class="kn">import</span> <span class="nn">torch</span>
<span class="kn">from</span> <span class="nn">torch</span> <span class="kn">import</span> <span class="n">optim</span>
<span class="kn">from</span> <span class="nn">torch.nn</span> <span class="kn">import</span> <span class="n">functional</span> <span class="k">as</span> <span class="n">F</span>
<span class="kn">from</span> <span class="nn">torch.nn.parameter</span> <span class="kn">import</span> <span class="n">Parameter</span>
<span class="kn">from</span> <span class="nn">tqdm</span> <span class="kn">import</span> <span class="n">tqdm</span>
<span class="kn">from</span> <span class="nn">deeprobust.graph</span> <span class="kn">import</span> <span class="n">utils</span>
<span class="kn">from</span> <span class="nn">deeprobust.graph.global_attack</span> <span class="kn">import</span> <span class="n">BaseAttack</span>


<div class="viewcode-block" id="BaseMeta"><a class="viewcode-back" href="../../../../source/deeprobust.graph.global_attack.html#deeprobust.graph.global_attack.mettack.BaseMeta">[docs]</a><span class="k">class</span> <span class="nc">BaseMeta</span><span class="p">(</span><span class="n">BaseAttack</span><span class="p">):</span>
    <span class="sd">&quot;&quot;&quot;Abstract base class for meta attack. Adversarial Attacks on Graph Neural</span>
<span class="sd">    Networks via Meta Learning, ICLR 2019,</span>
<span class="sd">    https://openreview.net/pdf?id=Bylnx209YX</span>

<span class="sd">    Parameters</span>
<span class="sd">    ----------</span>
<span class="sd">    model :</span>
<span class="sd">        model to attack. Default `None`.</span>
<span class="sd">    nnodes : int</span>
<span class="sd">        number of nodes in the input graph</span>
<span class="sd">    lambda_ : float</span>
<span class="sd">        lambda_ is used to weight the two objectives in Eq. (10) in the paper.</span>
<span class="sd">    feature_shape : tuple</span>
<span class="sd">        shape of the input node features</span>
<span class="sd">    attack_structure : bool</span>
<span class="sd">        whether to attack graph structure</span>
<span class="sd">    attack_features : bool</span>
<span class="sd">        whether to attack node features</span>
<span class="sd">    device: str</span>
<span class="sd">        &#39;cpu&#39; or &#39;cuda&#39;</span>

<span class="sd">    &quot;&quot;&quot;</span>

    <span class="k">def</span> <span class="fm">__init__</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">model</span><span class="o">=</span><span class="kc">None</span><span class="p">,</span> <span class="n">nnodes</span><span class="o">=</span><span class="kc">None</span><span class="p">,</span> <span class="n">feature_shape</span><span class="o">=</span><span class="kc">None</span><span class="p">,</span> <span class="n">lambda_</span><span class="o">=</span><span class="mf">0.5</span><span class="p">,</span> <span class="n">attack_structure</span><span class="o">=</span><span class="kc">True</span><span class="p">,</span> <span class="n">attack_features</span><span class="o">=</span><span class="kc">False</span><span class="p">,</span> <span class="n">device</span><span class="o">=</span><span class="s1">&#39;cpu&#39;</span><span class="p">):</span>

        <span class="nb">super</span><span class="p">(</span><span class="n">BaseMeta</span><span class="p">,</span> <span class="bp">self</span><span class="p">)</span><span class="o">.</span><span class="fm">__init__</span><span class="p">(</span><span class="n">model</span><span class="p">,</span> <span class="n">nnodes</span><span class="p">,</span> <span class="n">attack_structure</span><span class="p">,</span> <span class="n">attack_features</span><span class="p">,</span> <span class="n">device</span><span class="p">)</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">lambda_</span> <span class="o">=</span> <span class="n">lambda_</span>

        <span class="k">assert</span> <span class="n">attack_features</span> <span class="ow">or</span> <span class="n">attack_structure</span><span class="p">,</span> <span class="s1">&#39;attack_features or attack_structure cannot be both False&#39;</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">modified_adj</span> <span class="o">=</span> <span class="kc">None</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">modified_features</span> <span class="o">=</span> <span class="kc">None</span>

        <span class="k">if</span> <span class="n">attack_structure</span><span class="p">:</span>
            <span class="k">assert</span> <span class="n">nnodes</span> <span class="ow">is</span> <span class="ow">not</span> <span class="kc">None</span><span class="p">,</span> <span class="s1">&#39;Please give nnodes=&#39;</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span> <span class="o">=</span> <span class="n">Parameter</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">FloatTensor</span><span class="p">(</span><span class="n">nnodes</span><span class="p">,</span> <span class="n">nnodes</span><span class="p">))</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span><span class="o">.</span><span class="n">data</span><span class="o">.</span><span class="n">fill_</span><span class="p">(</span><span class="mi">0</span><span class="p">)</span>

        <span class="k">if</span> <span class="n">attack_features</span><span class="p">:</span>
            <span class="k">assert</span> <span class="n">feature_shape</span> <span class="ow">is</span> <span class="ow">not</span> <span class="kc">None</span><span class="p">,</span> <span class="s1">&#39;Please give feature_shape=&#39;</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">feature_changes</span> <span class="o">=</span> <span class="n">Parameter</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">FloatTensor</span><span class="p">(</span><span class="n">feature_shape</span><span class="p">))</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">feature_changes</span><span class="o">.</span><span class="n">data</span><span class="o">.</span><span class="n">fill_</span><span class="p">(</span><span class="mi">0</span><span class="p">)</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">with_relu</span> <span class="o">=</span> <span class="n">model</span><span class="o">.</span><span class="n">with_relu</span>

<div class="viewcode-block" id="BaseMeta.attack"><a class="viewcode-back" href="../../../../source/deeprobust.graph.global_attack.html#deeprobust.graph.global_attack.mettack.BaseMeta.attack">[docs]</a>    <span class="k">def</span> <span class="nf">attack</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">adj</span><span class="p">,</span> <span class="n">labels</span><span class="p">,</span> <span class="n">n_perturbations</span><span class="p">):</span>
        <span class="k">pass</span></div>

    <span class="k">def</span> <span class="nf">get_modified_adj</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">ori_adj</span><span class="p">):</span>
        <span class="n">adj_changes_square</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span> <span class="o">-</span> <span class="n">torch</span><span class="o">.</span><span class="n">diag</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">diag</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span><span class="p">,</span> <span class="mi">0</span><span class="p">))</span>
        <span class="n">ind</span> <span class="o">=</span> <span class="n">np</span><span class="o">.</span><span class="n">diag_indices</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span><span class="o">.</span><span class="n">shape</span><span class="p">[</span><span class="mi">0</span><span class="p">])</span>
        <span class="n">adj_changes_symm</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">clamp</span><span class="p">(</span><span class="n">adj_changes_square</span> <span class="o">+</span> <span class="n">torch</span><span class="o">.</span><span class="n">transpose</span><span class="p">(</span><span class="n">adj_changes_square</span><span class="p">,</span> <span class="mi">1</span><span class="p">,</span> <span class="mi">0</span><span class="p">),</span> <span class="o">-</span><span class="mi">1</span><span class="p">,</span> <span class="mi">1</span><span class="p">)</span>
        <span class="n">modified_adj</span> <span class="o">=</span> <span class="n">adj_changes_symm</span> <span class="o">+</span> <span class="n">ori_adj</span>
        <span class="k">return</span> <span class="n">modified_adj</span>

    <span class="k">def</span> <span class="nf">get_modified_features</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">ori_features</span><span class="p">):</span>
        <span class="k">return</span> <span class="n">ori_features</span> <span class="o">+</span> <span class="bp">self</span><span class="o">.</span><span class="n">feature_changes</span>

<div class="viewcode-block" id="BaseMeta.filter_potential_singletons"><a class="viewcode-back" href="../../../../source/deeprobust.graph.global_attack.html#deeprobust.graph.global_attack.mettack.BaseMeta.filter_potential_singletons">[docs]</a>    <span class="k">def</span> <span class="nf">filter_potential_singletons</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">modified_adj</span><span class="p">):</span>
        <span class="sd">&quot;&quot;&quot;</span>
<span class="sd">        Computes a mask for entries potentially leading to singleton nodes, i.e. one of the two nodes corresponding to</span>
<span class="sd">        the entry have degree 1 and there is an edge between the two nodes.</span>
<span class="sd">        &quot;&quot;&quot;</span>

        <span class="n">degrees</span> <span class="o">=</span> <span class="n">modified_adj</span><span class="o">.</span><span class="n">sum</span><span class="p">(</span><span class="mi">0</span><span class="p">)</span>
        <span class="n">degree_one</span> <span class="o">=</span> <span class="p">(</span><span class="n">degrees</span> <span class="o">==</span> <span class="mi">1</span><span class="p">)</span>
        <span class="n">resh</span> <span class="o">=</span> <span class="n">degree_one</span><span class="o">.</span><span class="n">repeat</span><span class="p">(</span><span class="n">modified_adj</span><span class="o">.</span><span class="n">shape</span><span class="p">[</span><span class="mi">0</span><span class="p">],</span> <span class="mi">1</span><span class="p">)</span><span class="o">.</span><span class="n">float</span><span class="p">()</span>
        <span class="n">l_and</span> <span class="o">=</span> <span class="n">resh</span> <span class="o">*</span> <span class="n">modified_adj</span>
        <span class="n">logical_and_symmetric</span> <span class="o">=</span> <span class="n">l_and</span> <span class="o">+</span> <span class="n">l_and</span><span class="o">.</span><span class="n">t</span><span class="p">()</span>
        <span class="n">flat_mask</span> <span class="o">=</span> <span class="mi">1</span> <span class="o">-</span> <span class="n">logical_and_symmetric</span>
        <span class="k">return</span> <span class="n">flat_mask</span></div>

    <span class="k">def</span> <span class="nf">self_training_label</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">labels</span><span class="p">,</span> <span class="n">idx_train</span><span class="p">):</span>
        <span class="c1"># Predict the labels of the unlabeled nodes to use them for self-training.</span>
        <span class="n">output</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">surrogate</span><span class="o">.</span><span class="n">output</span>
        <span class="n">labels_self_training</span> <span class="o">=</span> <span class="n">output</span><span class="o">.</span><span class="n">argmax</span><span class="p">(</span><span class="mi">1</span><span class="p">)</span>
        <span class="n">labels_self_training</span><span class="p">[</span><span class="n">idx_train</span><span class="p">]</span> <span class="o">=</span> <span class="n">labels</span><span class="p">[</span><span class="n">idx_train</span><span class="p">]</span>
        <span class="k">return</span> <span class="n">labels_self_training</span>


<div class="viewcode-block" id="BaseMeta.log_likelihood_constraint"><a class="viewcode-back" href="../../../../source/deeprobust.graph.global_attack.html#deeprobust.graph.global_attack.mettack.BaseMeta.log_likelihood_constraint">[docs]</a>    <span class="k">def</span> <span class="nf">log_likelihood_constraint</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">modified_adj</span><span class="p">,</span> <span class="n">ori_adj</span><span class="p">,</span> <span class="n">ll_cutoff</span><span class="p">):</span>
        <span class="sd">&quot;&quot;&quot;</span>
<span class="sd">        Computes a mask for entries that, if the edge corresponding to the entry is added/removed, would lead to the</span>
<span class="sd">        log likelihood constraint to be violated.</span>

<span class="sd">        Note that different data type (float, double) can effect the final results.</span>
<span class="sd">        &quot;&quot;&quot;</span>
        <span class="n">t_d_min</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">tensor</span><span class="p">(</span><span class="mf">2.0</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>
        <span class="n">t_possible_edges</span> <span class="o">=</span> <span class="n">np</span><span class="o">.</span><span class="n">array</span><span class="p">(</span><span class="n">np</span><span class="o">.</span><span class="n">triu</span><span class="p">(</span><span class="n">np</span><span class="o">.</span><span class="n">ones</span><span class="p">((</span><span class="bp">self</span><span class="o">.</span><span class="n">nnodes</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">nnodes</span><span class="p">)),</span> <span class="n">k</span><span class="o">=</span><span class="mi">1</span><span class="p">)</span><span class="o">.</span><span class="n">nonzero</span><span class="p">())</span><span class="o">.</span><span class="n">T</span>
        <span class="n">allowed_mask</span><span class="p">,</span> <span class="n">current_ratio</span> <span class="o">=</span> <span class="n">utils</span><span class="o">.</span><span class="n">likelihood_ratio_filter</span><span class="p">(</span><span class="n">t_possible_edges</span><span class="p">,</span>
                                                                    <span class="n">modified_adj</span><span class="p">,</span>
                                                                    <span class="n">ori_adj</span><span class="p">,</span> <span class="n">t_d_min</span><span class="p">,</span>
                                                                    <span class="n">ll_cutoff</span><span class="p">)</span>
        <span class="k">return</span> <span class="n">allowed_mask</span><span class="p">,</span> <span class="n">current_ratio</span></div>

    <span class="k">def</span> <span class="nf">get_adj_score</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">adj_grad</span><span class="p">,</span> <span class="n">modified_adj</span><span class="p">,</span> <span class="n">ori_adj</span><span class="p">,</span> <span class="n">ll_constraint</span><span class="p">,</span> <span class="n">ll_cutoff</span><span class="p">):</span>
        <span class="n">adj_meta_grad</span> <span class="o">=</span> <span class="n">adj_grad</span> <span class="o">*</span> <span class="p">(</span><span class="o">-</span><span class="mi">2</span> <span class="o">*</span> <span class="n">modified_adj</span> <span class="o">+</span> <span class="mi">1</span><span class="p">)</span>
        <span class="c1"># Make sure that the minimum entry is 0.</span>
        <span class="n">adj_meta_grad</span> <span class="o">-=</span> <span class="n">adj_meta_grad</span><span class="o">.</span><span class="n">min</span><span class="p">()</span>
        <span class="c1"># Filter self-loops</span>
        <span class="n">adj_meta_grad</span> <span class="o">-=</span> <span class="n">torch</span><span class="o">.</span><span class="n">diag</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">diag</span><span class="p">(</span><span class="n">adj_meta_grad</span><span class="p">,</span> <span class="mi">0</span><span class="p">))</span>
        <span class="c1"># # Set entries to 0 that could lead to singleton nodes.</span>
        <span class="n">singleton_mask</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">filter_potential_singletons</span><span class="p">(</span><span class="n">modified_adj</span><span class="p">)</span>
        <span class="n">adj_meta_grad</span> <span class="o">=</span> <span class="n">adj_meta_grad</span> <span class="o">*</span>  <span class="n">singleton_mask</span>

        <span class="k">if</span> <span class="n">ll_constraint</span><span class="p">:</span>
            <span class="n">allowed_mask</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">ll_ratio</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">log_likelihood_constraint</span><span class="p">(</span><span class="n">modified_adj</span><span class="p">,</span> <span class="n">ori_adj</span><span class="p">,</span> <span class="n">ll_cutoff</span><span class="p">)</span>
            <span class="n">allowed_mask</span> <span class="o">=</span> <span class="n">allowed_mask</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>
            <span class="n">adj_meta_grad</span> <span class="o">=</span> <span class="n">adj_meta_grad</span> <span class="o">*</span> <span class="n">allowed_mask</span>
        <span class="k">return</span> <span class="n">adj_meta_grad</span>

    <span class="k">def</span> <span class="nf">get_feature_score</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">feature_grad</span><span class="p">,</span> <span class="n">modified_features</span><span class="p">):</span>
        <span class="n">feature_meta_grad</span> <span class="o">=</span> <span class="n">feature_grad</span> <span class="o">*</span> <span class="p">(</span><span class="o">-</span><span class="mi">2</span> <span class="o">*</span> <span class="n">modified_features</span> <span class="o">+</span> <span class="mi">1</span><span class="p">)</span>
        <span class="n">feature_meta_grad</span> <span class="o">-=</span> <span class="n">feature_meta_grad</span><span class="o">.</span><span class="n">min</span><span class="p">()</span>
        <span class="k">return</span> <span class="n">feature_meta_grad</span></div>


<div class="viewcode-block" id="Metattack"><a class="viewcode-back" href="../../../../source/deeprobust.graph.global_attack.html#deeprobust.graph.global_attack.mettack.Metattack">[docs]</a><span class="k">class</span> <span class="nc">Metattack</span><span class="p">(</span><span class="n">BaseMeta</span><span class="p">):</span>
    <span class="sd">&quot;&quot;&quot;Meta attack. Adversarial Attacks on Graph Neural Networks</span>
<span class="sd">    via Meta Learning, ICLR 2019.</span>

<span class="sd">    Examples</span>
<span class="sd">    --------</span>

<span class="sd">    &gt;&gt;&gt; import numpy as np</span>
<span class="sd">    &gt;&gt;&gt; from deeprobust.graph.data import Dataset</span>
<span class="sd">    &gt;&gt;&gt; from deeprobust.graph.defense import GCN</span>
<span class="sd">    &gt;&gt;&gt; from deeprobust.graph.global_attack import Metattack</span>
<span class="sd">    &gt;&gt;&gt; data = Dataset(root=&#39;/tmp/&#39;, name=&#39;cora&#39;)</span>
<span class="sd">    &gt;&gt;&gt; adj, features, labels = data.adj, data.features, data.labels</span>
<span class="sd">    &gt;&gt;&gt; idx_train, idx_val, idx_test = data.idx_train, data.idx_val, data.idx_test</span>
<span class="sd">    &gt;&gt;&gt; idx_unlabeled = np.union1d(idx_val, idx_test)</span>
<span class="sd">    &gt;&gt;&gt; idx_unlabeled = np.union1d(idx_val, idx_test)</span>
<span class="sd">    &gt;&gt;&gt; # Setup Surrogate model</span>
<span class="sd">    &gt;&gt;&gt; surrogate = GCN(nfeat=features.shape[1], nclass=labels.max().item()+1,</span>
<span class="sd">                    nhid=16, dropout=0, with_relu=False, with_bias=False, device=&#39;cpu&#39;).to(&#39;cpu&#39;)</span>
<span class="sd">    &gt;&gt;&gt; surrogate.fit(features, adj, labels, idx_train, idx_val, patience=30)</span>
<span class="sd">    &gt;&gt;&gt; # Setup Attack Model</span>
<span class="sd">    &gt;&gt;&gt; model = Metattack(surrogate, nnodes=adj.shape[0], feature_shape=features.shape,</span>
<span class="sd">            attack_structure=True, attack_features=False, device=&#39;cpu&#39;, lambda_=0).to(&#39;cpu&#39;)</span>
<span class="sd">    &gt;&gt;&gt; # Attack</span>
<span class="sd">    &gt;&gt;&gt; model.attack(features, adj, labels, idx_train, idx_unlabeled, n_perturbations=10, ll_constraint=False)</span>
<span class="sd">    &gt;&gt;&gt; modified_adj = model.modified_adj</span>

<span class="sd">    &quot;&quot;&quot;</span>

    <span class="k">def</span> <span class="fm">__init__</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">model</span><span class="p">,</span> <span class="n">nnodes</span><span class="p">,</span> <span class="n">feature_shape</span><span class="o">=</span><span class="kc">None</span><span class="p">,</span> <span class="n">attack_structure</span><span class="o">=</span><span class="kc">True</span><span class="p">,</span> <span class="n">attack_features</span><span class="o">=</span><span class="kc">False</span><span class="p">,</span> <span class="n">device</span><span class="o">=</span><span class="s1">&#39;cpu&#39;</span><span class="p">,</span> <span class="n">with_bias</span><span class="o">=</span><span class="kc">False</span><span class="p">,</span> <span class="n">lambda_</span><span class="o">=</span><span class="mf">0.5</span><span class="p">,</span> <span class="n">train_iters</span><span class="o">=</span><span class="mi">100</span><span class="p">,</span> <span class="n">lr</span><span class="o">=</span><span class="mf">0.1</span><span class="p">,</span> <span class="n">momentum</span><span class="o">=</span><span class="mf">0.9</span><span class="p">):</span>

        <span class="nb">super</span><span class="p">(</span><span class="n">Metattack</span><span class="p">,</span> <span class="bp">self</span><span class="p">)</span><span class="o">.</span><span class="fm">__init__</span><span class="p">(</span><span class="n">model</span><span class="p">,</span> <span class="n">nnodes</span><span class="p">,</span> <span class="n">feature_shape</span><span class="p">,</span> <span class="n">lambda_</span><span class="p">,</span> <span class="n">attack_structure</span><span class="p">,</span> <span class="n">attack_features</span><span class="p">,</span> <span class="n">device</span><span class="p">)</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">momentum</span> <span class="o">=</span> <span class="n">momentum</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">lr</span> <span class="o">=</span> <span class="n">lr</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">train_iters</span> <span class="o">=</span> <span class="n">train_iters</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">with_bias</span> <span class="o">=</span> <span class="n">with_bias</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">weights</span> <span class="o">=</span> <span class="p">[]</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">biases</span> <span class="o">=</span> <span class="p">[]</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">w_velocities</span> <span class="o">=</span> <span class="p">[]</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">b_velocities</span> <span class="o">=</span> <span class="p">[]</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">hidden_sizes</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">surrogate</span><span class="o">.</span><span class="n">hidden_sizes</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">nfeat</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">surrogate</span><span class="o">.</span><span class="n">nfeat</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">nclass</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">surrogate</span><span class="o">.</span><span class="n">nclass</span>

        <span class="n">previous_size</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">nfeat</span>
        <span class="k">for</span> <span class="n">ix</span><span class="p">,</span> <span class="n">nhid</span> <span class="ow">in</span> <span class="nb">enumerate</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">hidden_sizes</span><span class="p">):</span>
            <span class="n">weight</span> <span class="o">=</span> <span class="n">Parameter</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">FloatTensor</span><span class="p">(</span><span class="n">previous_size</span><span class="p">,</span> <span class="n">nhid</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">))</span>
            <span class="n">w_velocity</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">zeros</span><span class="p">(</span><span class="n">weight</span><span class="o">.</span><span class="n">shape</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">)</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">weight</span><span class="p">)</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">w_velocities</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">w_velocity</span><span class="p">)</span>

            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_bias</span><span class="p">:</span>
                <span class="n">bias</span> <span class="o">=</span> <span class="n">Parameter</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">FloatTensor</span><span class="p">(</span><span class="n">nhid</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">))</span>
                <span class="n">b_velocity</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">zeros</span><span class="p">(</span><span class="n">bias</span><span class="o">.</span><span class="n">shape</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">)</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">bias</span><span class="p">)</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">b_velocities</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">b_velocity</span><span class="p">)</span>

            <span class="n">previous_size</span> <span class="o">=</span> <span class="n">nhid</span>

        <span class="n">output_weight</span> <span class="o">=</span> <span class="n">Parameter</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">FloatTensor</span><span class="p">(</span><span class="n">previous_size</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">nclass</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">))</span>
        <span class="n">output_w_velocity</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">zeros</span><span class="p">(</span><span class="n">output_weight</span><span class="o">.</span><span class="n">shape</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">)</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">output_weight</span><span class="p">)</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">w_velocities</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">output_w_velocity</span><span class="p">)</span>

        <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_bias</span><span class="p">:</span>
            <span class="n">output_bias</span> <span class="o">=</span> <span class="n">Parameter</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">FloatTensor</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">nclass</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">))</span>
            <span class="n">output_b_velocity</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">zeros</span><span class="p">(</span><span class="n">output_bias</span><span class="o">.</span><span class="n">shape</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">)</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">output_bias</span><span class="p">)</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">b_velocities</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">output_b_velocity</span><span class="p">)</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">_initialize</span><span class="p">()</span>

    <span class="k">def</span> <span class="nf">_initialize</span><span class="p">(</span><span class="bp">self</span><span class="p">):</span>
        <span class="k">for</span> <span class="n">w</span><span class="p">,</span> <span class="n">v</span> <span class="ow">in</span> <span class="nb">zip</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">w_velocities</span><span class="p">):</span>
            <span class="n">stdv</span> <span class="o">=</span> <span class="mf">1.</span> <span class="o">/</span> <span class="n">math</span><span class="o">.</span><span class="n">sqrt</span><span class="p">(</span><span class="n">w</span><span class="o">.</span><span class="n">size</span><span class="p">(</span><span class="mi">1</span><span class="p">))</span>
            <span class="n">w</span><span class="o">.</span><span class="n">data</span><span class="o">.</span><span class="n">uniform_</span><span class="p">(</span><span class="o">-</span><span class="n">stdv</span><span class="p">,</span> <span class="n">stdv</span><span class="p">)</span>
            <span class="n">v</span><span class="o">.</span><span class="n">data</span><span class="o">.</span><span class="n">fill_</span><span class="p">(</span><span class="mi">0</span><span class="p">)</span>

        <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_bias</span><span class="p">:</span>
            <span class="k">for</span> <span class="n">b</span><span class="p">,</span> <span class="n">v</span> <span class="ow">in</span> <span class="nb">zip</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">b_velocities</span><span class="p">):</span>
                <span class="n">stdv</span> <span class="o">=</span> <span class="mf">1.</span> <span class="o">/</span> <span class="n">math</span><span class="o">.</span><span class="n">sqrt</span><span class="p">(</span><span class="n">w</span><span class="o">.</span><span class="n">size</span><span class="p">(</span><span class="mi">1</span><span class="p">))</span>
                <span class="n">b</span><span class="o">.</span><span class="n">data</span><span class="o">.</span><span class="n">uniform_</span><span class="p">(</span><span class="o">-</span><span class="n">stdv</span><span class="p">,</span> <span class="n">stdv</span><span class="p">)</span>
                <span class="n">v</span><span class="o">.</span><span class="n">data</span><span class="o">.</span><span class="n">fill_</span><span class="p">(</span><span class="mi">0</span><span class="p">)</span>

    <span class="k">def</span> <span class="nf">inner_train</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">features</span><span class="p">,</span> <span class="n">adj_norm</span><span class="p">,</span> <span class="n">idx_train</span><span class="p">,</span> <span class="n">idx_unlabeled</span><span class="p">,</span> <span class="n">labels</span><span class="p">):</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">_initialize</span><span class="p">()</span>

        <span class="k">for</span> <span class="n">ix</span> <span class="ow">in</span> <span class="nb">range</span><span class="p">(</span><span class="nb">len</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">hidden_sizes</span><span class="p">)</span> <span class="o">+</span> <span class="mi">1</span><span class="p">):</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span><span class="o">.</span><span class="n">requires_grad</span> <span class="o">=</span> <span class="kc">True</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">w_velocities</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">w_velocities</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">w_velocities</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span><span class="o">.</span><span class="n">requires_grad</span> <span class="o">=</span> <span class="kc">True</span>

            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_bias</span><span class="p">:</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span><span class="o">.</span><span class="n">requires_grad</span> <span class="o">=</span> <span class="kc">True</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">b_velocities</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">b_velocities</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">b_velocities</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span><span class="o">.</span><span class="n">requires_grad</span> <span class="o">=</span> <span class="kc">True</span>

        <span class="k">for</span> <span class="n">j</span> <span class="ow">in</span> <span class="nb">range</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">train_iters</span><span class="p">):</span>
            <span class="n">hidden</span> <span class="o">=</span> <span class="n">features</span>
            <span class="k">for</span> <span class="n">ix</span><span class="p">,</span> <span class="n">w</span> <span class="ow">in</span> <span class="nb">enumerate</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">):</span>
                <span class="n">b</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span> <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_bias</span> <span class="k">else</span> <span class="mi">0</span>
                <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">sparse_features</span><span class="p">:</span>
                    <span class="n">hidden</span> <span class="o">=</span> <span class="n">adj_norm</span> <span class="o">@</span> <span class="n">torch</span><span class="o">.</span><span class="n">spmm</span><span class="p">(</span><span class="n">hidden</span><span class="p">,</span> <span class="n">w</span><span class="p">)</span> <span class="o">+</span> <span class="n">b</span>
                <span class="k">else</span><span class="p">:</span>
                    <span class="n">hidden</span> <span class="o">=</span> <span class="n">adj_norm</span> <span class="o">@</span> <span class="n">hidden</span> <span class="o">@</span> <span class="n">w</span> <span class="o">+</span> <span class="n">b</span>

                <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_relu</span> <span class="ow">and</span> <span class="n">ix</span> <span class="o">!=</span> <span class="nb">len</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">)</span> <span class="o">-</span> <span class="mi">1</span><span class="p">:</span>
                    <span class="n">hidden</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">relu</span><span class="p">(</span><span class="n">hidden</span><span class="p">)</span>

            <span class="n">output</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">log_softmax</span><span class="p">(</span><span class="n">hidden</span><span class="p">,</span> <span class="n">dim</span><span class="o">=</span><span class="mi">1</span><span class="p">)</span>
            <span class="n">loss_labeled</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">nll_loss</span><span class="p">(</span><span class="n">output</span><span class="p">[</span><span class="n">idx_train</span><span class="p">],</span> <span class="n">labels</span><span class="p">[</span><span class="n">idx_train</span><span class="p">])</span>

            <span class="n">weight_grads</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">autograd</span><span class="o">.</span><span class="n">grad</span><span class="p">(</span><span class="n">loss_labeled</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">,</span> <span class="n">create_graph</span><span class="o">=</span><span class="kc">True</span><span class="p">)</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">w_velocities</span> <span class="o">=</span> <span class="p">[</span><span class="bp">self</span><span class="o">.</span><span class="n">momentum</span> <span class="o">*</span> <span class="n">v</span> <span class="o">+</span> <span class="n">g</span> <span class="k">for</span> <span class="n">v</span><span class="p">,</span> <span class="n">g</span> <span class="ow">in</span> <span class="nb">zip</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">w_velocities</span><span class="p">,</span> <span class="n">weight_grads</span><span class="p">)]</span>
            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_bias</span><span class="p">:</span>
                <span class="n">bias_grads</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">autograd</span><span class="o">.</span><span class="n">grad</span><span class="p">(</span><span class="n">loss_labeled</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">,</span> <span class="n">create_graph</span><span class="o">=</span><span class="kc">True</span><span class="p">)</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">b_velocities</span> <span class="o">=</span> <span class="p">[</span><span class="bp">self</span><span class="o">.</span><span class="n">momentum</span> <span class="o">*</span> <span class="n">v</span> <span class="o">+</span> <span class="n">g</span> <span class="k">for</span> <span class="n">v</span><span class="p">,</span> <span class="n">g</span> <span class="ow">in</span> <span class="nb">zip</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">b_velocities</span><span class="p">,</span> <span class="n">bias_grads</span><span class="p">)]</span>

            <span class="bp">self</span><span class="o">.</span><span class="n">weights</span> <span class="o">=</span> <span class="p">[</span><span class="n">w</span> <span class="o">-</span> <span class="bp">self</span><span class="o">.</span><span class="n">lr</span> <span class="o">*</span> <span class="n">v</span> <span class="k">for</span> <span class="n">w</span><span class="p">,</span> <span class="n">v</span> <span class="ow">in</span> <span class="nb">zip</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">w_velocities</span><span class="p">)]</span>
            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_bias</span><span class="p">:</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">biases</span> <span class="o">=</span> <span class="p">[</span><span class="n">b</span> <span class="o">-</span> <span class="bp">self</span><span class="o">.</span><span class="n">lr</span> <span class="o">*</span> <span class="n">v</span> <span class="k">for</span> <span class="n">b</span><span class="p">,</span> <span class="n">v</span> <span class="ow">in</span> <span class="nb">zip</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">b_velocities</span><span class="p">)]</span>

    <span class="k">def</span> <span class="nf">get_meta_grad</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">features</span><span class="p">,</span> <span class="n">adj_norm</span><span class="p">,</span> <span class="n">idx_train</span><span class="p">,</span> <span class="n">idx_unlabeled</span><span class="p">,</span> <span class="n">labels</span><span class="p">,</span> <span class="n">labels_self_training</span><span class="p">):</span>

        <span class="n">hidden</span> <span class="o">=</span> <span class="n">features</span>
        <span class="k">for</span> <span class="n">ix</span><span class="p">,</span> <span class="n">w</span> <span class="ow">in</span> <span class="nb">enumerate</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">):</span>
            <span class="n">b</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span> <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_bias</span> <span class="k">else</span> <span class="mi">0</span>
            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">sparse_features</span><span class="p">:</span>
                <span class="n">hidden</span> <span class="o">=</span> <span class="n">adj_norm</span> <span class="o">@</span> <span class="n">torch</span><span class="o">.</span><span class="n">spmm</span><span class="p">(</span><span class="n">hidden</span><span class="p">,</span> <span class="n">w</span><span class="p">)</span> <span class="o">+</span> <span class="n">b</span>
            <span class="k">else</span><span class="p">:</span>
                <span class="n">hidden</span> <span class="o">=</span> <span class="n">adj_norm</span> <span class="o">@</span> <span class="n">hidden</span> <span class="o">@</span> <span class="n">w</span> <span class="o">+</span> <span class="n">b</span>
            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_relu</span> <span class="ow">and</span> <span class="n">ix</span> <span class="o">!=</span> <span class="nb">len</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">)</span> <span class="o">-</span> <span class="mi">1</span><span class="p">:</span>
                <span class="n">hidden</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">relu</span><span class="p">(</span><span class="n">hidden</span><span class="p">)</span>

        <span class="n">output</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">log_softmax</span><span class="p">(</span><span class="n">hidden</span><span class="p">,</span> <span class="n">dim</span><span class="o">=</span><span class="mi">1</span><span class="p">)</span>

        <span class="n">loss_labeled</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">nll_loss</span><span class="p">(</span><span class="n">output</span><span class="p">[</span><span class="n">idx_train</span><span class="p">],</span> <span class="n">labels</span><span class="p">[</span><span class="n">idx_train</span><span class="p">])</span>
        <span class="n">loss_unlabeled</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">nll_loss</span><span class="p">(</span><span class="n">output</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">],</span> <span class="n">labels_self_training</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">])</span>
        <span class="n">loss_test_val</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">nll_loss</span><span class="p">(</span><span class="n">output</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">],</span> <span class="n">labels</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">])</span>

        <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">lambda_</span> <span class="o">==</span> <span class="mi">1</span><span class="p">:</span>
            <span class="n">attack_loss</span> <span class="o">=</span> <span class="n">loss_labeled</span>
        <span class="k">elif</span> <span class="bp">self</span><span class="o">.</span><span class="n">lambda_</span> <span class="o">==</span> <span class="mi">0</span><span class="p">:</span>
            <span class="n">attack_loss</span> <span class="o">=</span> <span class="n">loss_unlabeled</span>
        <span class="k">else</span><span class="p">:</span>
            <span class="n">attack_loss</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">lambda_</span> <span class="o">*</span> <span class="n">loss_labeled</span> <span class="o">+</span> <span class="p">(</span><span class="mi">1</span> <span class="o">-</span> <span class="bp">self</span><span class="o">.</span><span class="n">lambda_</span><span class="p">)</span> <span class="o">*</span> <span class="n">loss_unlabeled</span>

        <span class="nb">print</span><span class="p">(</span><span class="s1">&#39;GCN loss on unlabled data: </span><span class="si">{}</span><span class="s1">&#39;</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">loss_test_val</span><span class="o">.</span><span class="n">item</span><span class="p">()))</span>
        <span class="nb">print</span><span class="p">(</span><span class="s1">&#39;GCN acc on unlabled data: </span><span class="si">{}</span><span class="s1">&#39;</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">utils</span><span class="o">.</span><span class="n">accuracy</span><span class="p">(</span><span class="n">output</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">],</span> <span class="n">labels</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">])</span><span class="o">.</span><span class="n">item</span><span class="p">()))</span>
        <span class="nb">print</span><span class="p">(</span><span class="s1">&#39;attack loss: </span><span class="si">{}</span><span class="s1">&#39;</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">attack_loss</span><span class="o">.</span><span class="n">item</span><span class="p">()))</span>

        <span class="n">adj_grad</span><span class="p">,</span> <span class="n">feature_grad</span> <span class="o">=</span> <span class="kc">None</span><span class="p">,</span> <span class="kc">None</span>
        <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_structure</span><span class="p">:</span>
            <span class="n">adj_grad</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">autograd</span><span class="o">.</span><span class="n">grad</span><span class="p">(</span><span class="n">attack_loss</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span><span class="p">,</span> <span class="n">retain_graph</span><span class="o">=</span><span class="kc">True</span><span class="p">)[</span><span class="mi">0</span><span class="p">]</span>
        <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_features</span><span class="p">:</span>
            <span class="n">feature_grad</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">autograd</span><span class="o">.</span><span class="n">grad</span><span class="p">(</span><span class="n">attack_loss</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">feature_changes</span><span class="p">,</span> <span class="n">retain_graph</span><span class="o">=</span><span class="kc">True</span><span class="p">)[</span><span class="mi">0</span><span class="p">]</span>
        <span class="k">return</span> <span class="n">adj_grad</span><span class="p">,</span> <span class="n">feature_grad</span>

<div class="viewcode-block" id="Metattack.attack"><a class="viewcode-back" href="../../../../source/deeprobust.graph.global_attack.html#deeprobust.graph.global_attack.mettack.Metattack.attack">[docs]</a>    <span class="k">def</span> <span class="nf">attack</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">ori_features</span><span class="p">,</span> <span class="n">ori_adj</span><span class="p">,</span> <span class="n">labels</span><span class="p">,</span> <span class="n">idx_train</span><span class="p">,</span> <span class="n">idx_unlabeled</span><span class="p">,</span> <span class="n">n_perturbations</span><span class="p">,</span> <span class="n">ll_constraint</span><span class="o">=</span><span class="kc">True</span><span class="p">,</span> <span class="n">ll_cutoff</span><span class="o">=</span><span class="mf">0.004</span><span class="p">):</span>
        <span class="sd">&quot;&quot;&quot;Generate n_perturbations on the input graph.</span>

<span class="sd">        Parameters</span>
<span class="sd">        ----------</span>
<span class="sd">        ori_features :</span>
<span class="sd">            Original (unperturbed) node feature matrix</span>
<span class="sd">        ori_adj :</span>
<span class="sd">            Original (unperturbed) adjacency matrix</span>
<span class="sd">        labels :</span>
<span class="sd">            node labels</span>
<span class="sd">        idx_train :</span>
<span class="sd">            node training indices</span>
<span class="sd">        idx_unlabeled:</span>
<span class="sd">            unlabeled nodes indices</span>
<span class="sd">        n_perturbations : int</span>
<span class="sd">            Number of perturbations on the input graph. Perturbations could</span>
<span class="sd">            be edge removals/additions or feature removals/additions.</span>
<span class="sd">        ll_constraint: bool</span>
<span class="sd">            whether to exert the likelihood ratio test constraint</span>
<span class="sd">        ll_cutoff : float</span>
<span class="sd">            The critical value for the likelihood ratio test of the power law distributions.</span>
<span class="sd">            See the Chi square distribution with one degree of freedom. Default value 0.004</span>
<span class="sd">            corresponds to a p-value of roughly 0.95. It would be ignored if `ll_constraint`</span>
<span class="sd">            is False.</span>

<span class="sd">        &quot;&quot;&quot;</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">sparse_features</span> <span class="o">=</span> <span class="n">sp</span><span class="o">.</span><span class="n">issparse</span><span class="p">(</span><span class="n">ori_features</span><span class="p">)</span>
        <span class="n">ori_adj</span><span class="p">,</span> <span class="n">ori_features</span><span class="p">,</span> <span class="n">labels</span> <span class="o">=</span> <span class="n">utils</span><span class="o">.</span><span class="n">to_tensor</span><span class="p">(</span><span class="n">ori_adj</span><span class="p">,</span> <span class="n">ori_features</span><span class="p">,</span> <span class="n">labels</span><span class="p">,</span> <span class="n">device</span><span class="o">=</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>
        <span class="n">labels_self_training</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">self_training_label</span><span class="p">(</span><span class="n">labels</span><span class="p">,</span> <span class="n">idx_train</span><span class="p">)</span>
        <span class="n">modified_adj</span> <span class="o">=</span> <span class="n">ori_adj</span>
        <span class="n">modified_features</span> <span class="o">=</span> <span class="n">ori_features</span>

        <span class="k">for</span> <span class="n">i</span> <span class="ow">in</span> <span class="n">tqdm</span><span class="p">(</span><span class="nb">range</span><span class="p">(</span><span class="n">n_perturbations</span><span class="p">),</span> <span class="n">desc</span><span class="o">=</span><span class="s2">&quot;Perturbing graph&quot;</span><span class="p">):</span>
            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_structure</span><span class="p">:</span>
                <span class="n">modified_adj</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">get_modified_adj</span><span class="p">(</span><span class="n">ori_adj</span><span class="p">)</span>

            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_features</span><span class="p">:</span>
                <span class="n">modified_features</span> <span class="o">=</span> <span class="n">ori_features</span> <span class="o">+</span> <span class="bp">self</span><span class="o">.</span><span class="n">feature_changes</span>

            <span class="n">adj_norm</span> <span class="o">=</span> <span class="n">utils</span><span class="o">.</span><span class="n">normalize_adj_tensor</span><span class="p">(</span><span class="n">modified_adj</span><span class="p">)</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">inner_train</span><span class="p">(</span><span class="n">modified_features</span><span class="p">,</span> <span class="n">adj_norm</span><span class="p">,</span> <span class="n">idx_train</span><span class="p">,</span> <span class="n">idx_unlabeled</span><span class="p">,</span> <span class="n">labels</span><span class="p">)</span>

            <span class="n">adj_grad</span><span class="p">,</span> <span class="n">feature_grad</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">get_meta_grad</span><span class="p">(</span><span class="n">modified_features</span><span class="p">,</span> <span class="n">adj_norm</span><span class="p">,</span> <span class="n">idx_train</span><span class="p">,</span> <span class="n">idx_unlabeled</span><span class="p">,</span> <span class="n">labels</span><span class="p">,</span> <span class="n">labels_self_training</span><span class="p">)</span>

            <span class="n">adj_meta_score</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">tensor</span><span class="p">(</span><span class="mf">0.0</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>
            <span class="n">feature_meta_score</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">tensor</span><span class="p">(</span><span class="mf">0.0</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>
            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_structure</span><span class="p">:</span>
                <span class="n">adj_meta_score</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">get_adj_score</span><span class="p">(</span><span class="n">adj_grad</span><span class="p">,</span> <span class="n">modified_adj</span><span class="p">,</span> <span class="n">ori_adj</span><span class="p">,</span> <span class="n">ll_constraint</span><span class="p">,</span> <span class="n">ll_cutoff</span><span class="p">)</span>
            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_features</span><span class="p">:</span>
                <span class="n">feature_meta_score</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">get_feature_score</span><span class="p">(</span><span class="n">feature_grad</span><span class="p">,</span> <span class="n">modified_features</span><span class="p">)</span>

            <span class="k">if</span> <span class="n">adj_meta_score</span><span class="o">.</span><span class="n">max</span><span class="p">()</span> <span class="o">&gt;=</span> <span class="n">feature_meta_score</span><span class="o">.</span><span class="n">max</span><span class="p">():</span>
                <span class="n">adj_meta_argmax</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">argmax</span><span class="p">(</span><span class="n">adj_meta_score</span><span class="p">)</span>
                <span class="n">row_idx</span><span class="p">,</span> <span class="n">col_idx</span> <span class="o">=</span> <span class="n">utils</span><span class="o">.</span><span class="n">unravel_index</span><span class="p">(</span><span class="n">adj_meta_argmax</span><span class="p">,</span> <span class="n">ori_adj</span><span class="o">.</span><span class="n">shape</span><span class="p">)</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span><span class="o">.</span><span class="n">data</span><span class="p">[</span><span class="n">row_idx</span><span class="p">][</span><span class="n">col_idx</span><span class="p">]</span> <span class="o">+=</span> <span class="p">(</span><span class="o">-</span><span class="mi">2</span> <span class="o">*</span> <span class="n">modified_adj</span><span class="p">[</span><span class="n">row_idx</span><span class="p">][</span><span class="n">col_idx</span><span class="p">]</span> <span class="o">+</span> <span class="mi">1</span><span class="p">)</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span><span class="o">.</span><span class="n">data</span><span class="p">[</span><span class="n">col_idx</span><span class="p">][</span><span class="n">row_idx</span><span class="p">]</span> <span class="o">+=</span> <span class="p">(</span><span class="o">-</span><span class="mi">2</span> <span class="o">*</span> <span class="n">modified_adj</span><span class="p">[</span><span class="n">row_idx</span><span class="p">][</span><span class="n">col_idx</span><span class="p">]</span> <span class="o">+</span> <span class="mi">1</span><span class="p">)</span>
            <span class="k">else</span><span class="p">:</span>
                <span class="n">feature_meta_argmax</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">argmax</span><span class="p">(</span><span class="n">feature_meta_score</span><span class="p">)</span>
                <span class="n">row_idx</span><span class="p">,</span> <span class="n">col_idx</span> <span class="o">=</span> <span class="n">utils</span><span class="o">.</span><span class="n">unravel_index</span><span class="p">(</span><span class="n">feature_meta_argmax</span><span class="p">,</span> <span class="n">ori_features</span><span class="o">.</span><span class="n">shape</span><span class="p">)</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">feature_changes</span><span class="o">.</span><span class="n">data</span><span class="p">[</span><span class="n">row_idx</span><span class="p">][</span><span class="n">col_idx</span><span class="p">]</span> <span class="o">+=</span> <span class="p">(</span><span class="o">-</span><span class="mi">2</span> <span class="o">*</span> <span class="n">modified_features</span><span class="p">[</span><span class="n">row_idx</span><span class="p">][</span><span class="n">col_idx</span><span class="p">]</span> <span class="o">+</span> <span class="mi">1</span><span class="p">)</span>

        <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_structure</span><span class="p">:</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">modified_adj</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">get_modified_adj</span><span class="p">(</span><span class="n">ori_adj</span><span class="p">)</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span>
        <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_features</span><span class="p">:</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">modified_features</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">get_modified_features</span><span class="p">(</span><span class="n">ori_features</span><span class="p">)</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span></div></div>


<div class="viewcode-block" id="MetaApprox"><a class="viewcode-back" href="../../../../source/deeprobust.graph.global_attack.html#deeprobust.graph.global_attack.mettack.MetaApprox">[docs]</a><span class="k">class</span> <span class="nc">MetaApprox</span><span class="p">(</span><span class="n">BaseMeta</span><span class="p">):</span>
    <span class="sd">&quot;&quot;&quot;Approximated version of Meta Attack. Adversarial Attacks on</span>
<span class="sd">    Graph Neural Networks via Meta Learning, ICLR 2019.</span>

<span class="sd">    Examples</span>
<span class="sd">    --------</span>

<span class="sd">    &gt;&gt;&gt; import numpy as np</span>
<span class="sd">    &gt;&gt;&gt; from deeprobust.graph.data import Dataset</span>
<span class="sd">    &gt;&gt;&gt; from deeprobust.graph.defense import GCN</span>
<span class="sd">    &gt;&gt;&gt; from deeprobust.graph.global_attack import MetaApprox</span>
<span class="sd">    &gt;&gt;&gt; from deeprobust.graph.utils import preprocess</span>
<span class="sd">    &gt;&gt;&gt; data = Dataset(root=&#39;/tmp/&#39;, name=&#39;cora&#39;)</span>
<span class="sd">    &gt;&gt;&gt; adj, features, labels = data.adj, data.features, data.labels</span>
<span class="sd">    &gt;&gt;&gt; adj, features, labels = preprocess(adj, features, labels, preprocess_adj=False) # conver to tensor</span>
<span class="sd">    &gt;&gt;&gt; idx_train, idx_val, idx_test = data.idx_train, data.idx_val, data.idx_test</span>
<span class="sd">    &gt;&gt;&gt; idx_unlabeled = np.union1d(idx_val, idx_test)</span>
<span class="sd">    &gt;&gt;&gt; # Setup Surrogate model</span>
<span class="sd">    &gt;&gt;&gt; surrogate = GCN(nfeat=features.shape[1], nclass=labels.max().item()+1,</span>
<span class="sd">                    nhid=16, dropout=0, with_relu=False, with_bias=False, device=&#39;cpu&#39;).to(&#39;cpu&#39;)</span>
<span class="sd">    &gt;&gt;&gt; surrogate.fit(features, adj, labels, idx_train, idx_val, patience=30)</span>
<span class="sd">    &gt;&gt;&gt; # Setup Attack Model</span>
<span class="sd">    &gt;&gt;&gt; model = MetaApprox(surrogate, nnodes=adj.shape[0], feature_shape=features.shape,</span>
<span class="sd">            attack_structure=True, attack_features=False, device=&#39;cpu&#39;, lambda_=0).to(&#39;cpu&#39;)</span>
<span class="sd">    &gt;&gt;&gt; # Attack</span>
<span class="sd">    &gt;&gt;&gt; model.attack(features, adj, labels, idx_train, idx_unlabeled, n_perturbations=10, ll_constraint=True)</span>
<span class="sd">    &gt;&gt;&gt; modified_adj = model.modified_adj</span>

<span class="sd">    &quot;&quot;&quot;</span>

    <span class="k">def</span> <span class="fm">__init__</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">model</span><span class="p">,</span> <span class="n">nnodes</span><span class="p">,</span> <span class="n">feature_shape</span><span class="o">=</span><span class="kc">None</span><span class="p">,</span> <span class="n">attack_structure</span><span class="o">=</span><span class="kc">True</span><span class="p">,</span> <span class="n">attack_features</span><span class="o">=</span><span class="kc">False</span><span class="p">,</span> <span class="n">device</span><span class="o">=</span><span class="s1">&#39;cpu&#39;</span><span class="p">,</span> <span class="n">with_bias</span><span class="o">=</span><span class="kc">False</span><span class="p">,</span> <span class="n">lambda_</span><span class="o">=</span><span class="mf">0.5</span><span class="p">,</span> <span class="n">train_iters</span><span class="o">=</span><span class="mi">100</span><span class="p">,</span> <span class="n">lr</span><span class="o">=</span><span class="mf">0.01</span><span class="p">):</span>

        <span class="nb">super</span><span class="p">(</span><span class="n">MetaApprox</span><span class="p">,</span> <span class="bp">self</span><span class="p">)</span><span class="o">.</span><span class="fm">__init__</span><span class="p">(</span><span class="n">model</span><span class="p">,</span> <span class="n">nnodes</span><span class="p">,</span> <span class="n">feature_shape</span><span class="p">,</span> <span class="n">lambda_</span><span class="p">,</span> <span class="n">attack_structure</span><span class="p">,</span> <span class="n">attack_features</span><span class="p">,</span> <span class="n">device</span><span class="p">)</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">lr</span> <span class="o">=</span> <span class="n">lr</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">train_iters</span> <span class="o">=</span> <span class="n">train_iters</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">adj_meta_grad</span> <span class="o">=</span> <span class="kc">None</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">features_meta_grad</span> <span class="o">=</span> <span class="kc">None</span>
        <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_structure</span><span class="p">:</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">adj_grad_sum</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">zeros</span><span class="p">(</span><span class="n">nnodes</span><span class="p">,</span> <span class="n">nnodes</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">)</span>
        <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_features</span><span class="p">:</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">feature_grad_sum</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">zeros</span><span class="p">(</span><span class="n">feature_shape</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">)</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">with_bias</span> <span class="o">=</span> <span class="n">with_bias</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">weights</span> <span class="o">=</span> <span class="p">[]</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">biases</span> <span class="o">=</span> <span class="p">[]</span>

        <span class="n">previous_size</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">nfeat</span>
        <span class="k">for</span> <span class="n">ix</span><span class="p">,</span> <span class="n">nhid</span> <span class="ow">in</span> <span class="nb">enumerate</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">hidden_sizes</span><span class="p">):</span>
            <span class="n">weight</span> <span class="o">=</span> <span class="n">Parameter</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">FloatTensor</span><span class="p">(</span><span class="n">previous_size</span><span class="p">,</span> <span class="n">nhid</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">))</span>
            <span class="n">bias</span> <span class="o">=</span> <span class="n">Parameter</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">FloatTensor</span><span class="p">(</span><span class="n">nhid</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">))</span>
            <span class="n">previous_size</span> <span class="o">=</span> <span class="n">nhid</span>

            <span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">weight</span><span class="p">)</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">bias</span><span class="p">)</span>

        <span class="n">output_weight</span> <span class="o">=</span> <span class="n">Parameter</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">FloatTensor</span><span class="p">(</span><span class="n">previous_size</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">nclass</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">))</span>
        <span class="n">output_bias</span> <span class="o">=</span> <span class="n">Parameter</span><span class="p">(</span><span class="n">torch</span><span class="o">.</span><span class="n">FloatTensor</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">nclass</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="n">device</span><span class="p">))</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">output_weight</span><span class="p">)</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="o">.</span><span class="n">append</span><span class="p">(</span><span class="n">output_bias</span><span class="p">)</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">optimizer</span> <span class="o">=</span> <span class="n">optim</span><span class="o">.</span><span class="n">Adam</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">weights</span> <span class="o">+</span> <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">,</span> <span class="n">lr</span><span class="o">=</span><span class="n">lr</span><span class="p">)</span> <span class="c1"># , weight_decay=5e-4)</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">_initialize</span><span class="p">()</span>

    <span class="k">def</span> <span class="nf">_initialize</span><span class="p">(</span><span class="bp">self</span><span class="p">):</span>
        <span class="k">for</span> <span class="n">w</span><span class="p">,</span> <span class="n">b</span> <span class="ow">in</span> <span class="nb">zip</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">):</span>
            <span class="c1"># w.data.fill_(1)</span>
            <span class="c1"># b.data.fill_(1)</span>
            <span class="n">stdv</span> <span class="o">=</span> <span class="mf">1.</span> <span class="o">/</span> <span class="n">math</span><span class="o">.</span><span class="n">sqrt</span><span class="p">(</span><span class="n">w</span><span class="o">.</span><span class="n">size</span><span class="p">(</span><span class="mi">1</span><span class="p">))</span>
            <span class="n">w</span><span class="o">.</span><span class="n">data</span><span class="o">.</span><span class="n">uniform_</span><span class="p">(</span><span class="o">-</span><span class="n">stdv</span><span class="p">,</span> <span class="n">stdv</span><span class="p">)</span>
            <span class="n">b</span><span class="o">.</span><span class="n">data</span><span class="o">.</span><span class="n">uniform_</span><span class="p">(</span><span class="o">-</span><span class="n">stdv</span><span class="p">,</span> <span class="n">stdv</span><span class="p">)</span>

        <span class="bp">self</span><span class="o">.</span><span class="n">optimizer</span> <span class="o">=</span> <span class="n">optim</span><span class="o">.</span><span class="n">Adam</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">weights</span> <span class="o">+</span> <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">,</span> <span class="n">lr</span><span class="o">=</span><span class="bp">self</span><span class="o">.</span><span class="n">lr</span><span class="p">)</span>

    <span class="k">def</span> <span class="nf">inner_train</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">features</span><span class="p">,</span> <span class="n">modified_adj</span><span class="p">,</span> <span class="n">idx_train</span><span class="p">,</span> <span class="n">idx_unlabeled</span><span class="p">,</span> <span class="n">labels</span><span class="p">,</span> <span class="n">labels_self_training</span><span class="p">):</span>
        <span class="n">adj_norm</span> <span class="o">=</span> <span class="n">utils</span><span class="o">.</span><span class="n">normalize_adj_tensor</span><span class="p">(</span><span class="n">modified_adj</span><span class="p">)</span>
        <span class="k">for</span> <span class="n">j</span> <span class="ow">in</span> <span class="nb">range</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">train_iters</span><span class="p">):</span>
            <span class="c1"># hidden = features</span>
            <span class="c1"># for w, b in zip(self.weights, self.biases):</span>
            <span class="c1">#     if self.sparse_features:</span>
            <span class="c1">#         hidden = adj_norm @ torch.spmm(hidden, w) + b</span>
            <span class="c1">#     else:</span>
            <span class="c1">#         hidden = adj_norm @ hidden @ w + b</span>
            <span class="c1">#     if self.with_relu:</span>
            <span class="c1">#         hidden = F.relu(hidden)</span>

            <span class="n">hidden</span> <span class="o">=</span> <span class="n">features</span>
            <span class="k">for</span> <span class="n">ix</span><span class="p">,</span> <span class="n">w</span> <span class="ow">in</span> <span class="nb">enumerate</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">weights</span><span class="p">):</span>
                <span class="n">b</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">biases</span><span class="p">[</span><span class="n">ix</span><span class="p">]</span> <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_bias</span> <span class="k">else</span> <span class="mi">0</span>
                <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">sparse_features</span><span class="p">:</span>
                    <span class="n">hidden</span> <span class="o">=</span> <span class="n">adj_norm</span> <span class="o">@</span> <span class="n">torch</span><span class="o">.</span><span class="n">spmm</span><span class="p">(</span><span class="n">hidden</span><span class="p">,</span> <span class="n">w</span><span class="p">)</span> <span class="o">+</span> <span class="n">b</span>
                <span class="k">else</span><span class="p">:</span>
                    <span class="n">hidden</span> <span class="o">=</span> <span class="n">adj_norm</span> <span class="o">@</span> <span class="n">hidden</span> <span class="o">@</span> <span class="n">w</span> <span class="o">+</span> <span class="n">b</span>
                <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">with_relu</span><span class="p">:</span>
                    <span class="n">hidden</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">relu</span><span class="p">(</span><span class="n">hidden</span><span class="p">)</span>

            <span class="n">output</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">log_softmax</span><span class="p">(</span><span class="n">hidden</span><span class="p">,</span> <span class="n">dim</span><span class="o">=</span><span class="mi">1</span><span class="p">)</span>
            <span class="n">loss_labeled</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">nll_loss</span><span class="p">(</span><span class="n">output</span><span class="p">[</span><span class="n">idx_train</span><span class="p">],</span> <span class="n">labels</span><span class="p">[</span><span class="n">idx_train</span><span class="p">])</span>
            <span class="n">loss_unlabeled</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">nll_loss</span><span class="p">(</span><span class="n">output</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">],</span> <span class="n">labels_self_training</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">])</span>

            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">lambda_</span> <span class="o">==</span> <span class="mi">1</span><span class="p">:</span>
                <span class="n">attack_loss</span> <span class="o">=</span> <span class="n">loss_labeled</span>
            <span class="k">elif</span> <span class="bp">self</span><span class="o">.</span><span class="n">lambda_</span> <span class="o">==</span> <span class="mi">0</span><span class="p">:</span>
                <span class="n">attack_loss</span> <span class="o">=</span> <span class="n">loss_unlabeled</span>
            <span class="k">else</span><span class="p">:</span>
                <span class="n">attack_loss</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">lambda_</span> <span class="o">*</span> <span class="n">loss_labeled</span> <span class="o">+</span> <span class="p">(</span><span class="mi">1</span> <span class="o">-</span> <span class="bp">self</span><span class="o">.</span><span class="n">lambda_</span><span class="p">)</span> <span class="o">*</span> <span class="n">loss_unlabeled</span>

            <span class="bp">self</span><span class="o">.</span><span class="n">optimizer</span><span class="o">.</span><span class="n">zero_grad</span><span class="p">()</span>
            <span class="n">loss_labeled</span><span class="o">.</span><span class="n">backward</span><span class="p">(</span><span class="n">retain_graph</span><span class="o">=</span><span class="kc">True</span><span class="p">)</span>

            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_structure</span><span class="p">:</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span><span class="o">.</span><span class="n">grad</span><span class="o">.</span><span class="n">zero_</span><span class="p">()</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">adj_grad_sum</span> <span class="o">+=</span> <span class="n">torch</span><span class="o">.</span><span class="n">autograd</span><span class="o">.</span><span class="n">grad</span><span class="p">(</span><span class="n">attack_loss</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span><span class="p">,</span> <span class="n">retain_graph</span><span class="o">=</span><span class="kc">True</span><span class="p">)[</span><span class="mi">0</span><span class="p">]</span>
            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_features</span><span class="p">:</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">feature_changes</span><span class="o">.</span><span class="n">grad</span><span class="o">.</span><span class="n">zero_</span><span class="p">()</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">feature_grad_sum</span> <span class="o">+=</span> <span class="n">torch</span><span class="o">.</span><span class="n">autograd</span><span class="o">.</span><span class="n">grad</span><span class="p">(</span><span class="n">attack_loss</span><span class="p">,</span> <span class="bp">self</span><span class="o">.</span><span class="n">feature_changes</span><span class="p">,</span> <span class="n">retain_graph</span><span class="o">=</span><span class="kc">True</span><span class="p">)[</span><span class="mi">0</span><span class="p">]</span>

            <span class="bp">self</span><span class="o">.</span><span class="n">optimizer</span><span class="o">.</span><span class="n">step</span><span class="p">()</span>


        <span class="n">loss_test_val</span> <span class="o">=</span> <span class="n">F</span><span class="o">.</span><span class="n">nll_loss</span><span class="p">(</span><span class="n">output</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">],</span> <span class="n">labels</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">])</span>
        <span class="nb">print</span><span class="p">(</span><span class="s1">&#39;GCN loss on unlabled data: </span><span class="si">{}</span><span class="s1">&#39;</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">loss_test_val</span><span class="o">.</span><span class="n">item</span><span class="p">()))</span>
        <span class="nb">print</span><span class="p">(</span><span class="s1">&#39;GCN acc on unlabled data: </span><span class="si">{}</span><span class="s1">&#39;</span><span class="o">.</span><span class="n">format</span><span class="p">(</span><span class="n">utils</span><span class="o">.</span><span class="n">accuracy</span><span class="p">(</span><span class="n">output</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">],</span> <span class="n">labels</span><span class="p">[</span><span class="n">idx_unlabeled</span><span class="p">])</span><span class="o">.</span><span class="n">item</span><span class="p">()))</span>


<div class="viewcode-block" id="MetaApprox.attack"><a class="viewcode-back" href="../../../../source/deeprobust.graph.global_attack.html#deeprobust.graph.global_attack.mettack.MetaApprox.attack">[docs]</a>    <span class="k">def</span> <span class="nf">attack</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">ori_features</span><span class="p">,</span> <span class="n">ori_adj</span><span class="p">,</span> <span class="n">labels</span><span class="p">,</span> <span class="n">idx_train</span><span class="p">,</span> <span class="n">idx_unlabeled</span><span class="p">,</span> <span class="n">n_perturbations</span><span class="p">,</span> <span class="n">ll_constraint</span><span class="o">=</span><span class="kc">True</span><span class="p">,</span> <span class="n">ll_cutoff</span><span class="o">=</span><span class="mf">0.004</span><span class="p">):</span>
        <span class="sd">&quot;&quot;&quot;Generate n_perturbations on the input graph.</span>

<span class="sd">        Parameters</span>
<span class="sd">        ----------</span>
<span class="sd">        ori_features :</span>
<span class="sd">            Original (unperturbed) node feature matrix</span>
<span class="sd">        ori_adj :</span>
<span class="sd">            Original (unperturbed) adjacency matrix</span>
<span class="sd">        labels :</span>
<span class="sd">            node labels</span>
<span class="sd">        idx_train :</span>
<span class="sd">            node training indices</span>
<span class="sd">        idx_unlabeled:</span>
<span class="sd">            unlabeled nodes indices</span>
<span class="sd">        n_perturbations : int</span>
<span class="sd">            Number of perturbations on the input graph. Perturbations could</span>
<span class="sd">            be edge removals/additions or feature removals/additions.</span>
<span class="sd">        ll_constraint: bool</span>
<span class="sd">            whether to exert the likelihood ratio test constraint</span>
<span class="sd">        ll_cutoff : float</span>
<span class="sd">            The critical value for the likelihood ratio test of the power law distributions.</span>
<span class="sd">            See the Chi square distribution with one degree of freedom. Default value 0.004</span>
<span class="sd">            corresponds to a p-value of roughly 0.95. It would be ignored if `ll_constraint`</span>
<span class="sd">            is False.</span>

<span class="sd">        &quot;&quot;&quot;</span>
        <span class="n">ori_adj</span><span class="p">,</span> <span class="n">ori_features</span><span class="p">,</span> <span class="n">labels</span> <span class="o">=</span> <span class="n">utils</span><span class="o">.</span><span class="n">to_tensor</span><span class="p">(</span><span class="n">ori_adj</span><span class="p">,</span> <span class="n">ori_features</span><span class="p">,</span> <span class="n">labels</span><span class="p">,</span> <span class="n">device</span><span class="o">=</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>
        <span class="n">labels_self_training</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">self_training_label</span><span class="p">(</span><span class="n">labels</span><span class="p">,</span> <span class="n">idx_train</span><span class="p">)</span>
        <span class="bp">self</span><span class="o">.</span><span class="n">sparse_features</span> <span class="o">=</span> <span class="n">sp</span><span class="o">.</span><span class="n">issparse</span><span class="p">(</span><span class="n">ori_features</span><span class="p">)</span>
        <span class="n">modified_adj</span> <span class="o">=</span> <span class="n">ori_adj</span>
        <span class="n">modified_features</span> <span class="o">=</span> <span class="n">ori_features</span>

        <span class="k">for</span> <span class="n">i</span> <span class="ow">in</span> <span class="n">tqdm</span><span class="p">(</span><span class="nb">range</span><span class="p">(</span><span class="n">n_perturbations</span><span class="p">),</span> <span class="n">desc</span><span class="o">=</span><span class="s2">&quot;Perturbing graph&quot;</span><span class="p">):</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">_initialize</span><span class="p">()</span>

            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_structure</span><span class="p">:</span>
                <span class="n">modified_adj</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">get_modified_adj</span><span class="p">(</span><span class="n">ori_adj</span><span class="p">)</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">adj_grad_sum</span><span class="o">.</span><span class="n">data</span><span class="o">.</span><span class="n">fill_</span><span class="p">(</span><span class="mi">0</span><span class="p">)</span>
            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_features</span><span class="p">:</span>
                <span class="n">modified_features</span> <span class="o">=</span> <span class="n">ori_features</span> <span class="o">+</span> <span class="bp">self</span><span class="o">.</span><span class="n">feature_changes</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">feature_grad_sum</span><span class="o">.</span><span class="n">data</span><span class="o">.</span><span class="n">fill_</span><span class="p">(</span><span class="mi">0</span><span class="p">)</span>

            <span class="bp">self</span><span class="o">.</span><span class="n">inner_train</span><span class="p">(</span><span class="n">modified_features</span><span class="p">,</span> <span class="n">modified_adj</span><span class="p">,</span> <span class="n">idx_train</span><span class="p">,</span> <span class="n">idx_unlabeled</span><span class="p">,</span> <span class="n">labels</span><span class="p">,</span> <span class="n">labels_self_training</span><span class="p">)</span>

            <span class="n">adj_meta_score</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">tensor</span><span class="p">(</span><span class="mf">0.0</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>
            <span class="n">feature_meta_score</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">tensor</span><span class="p">(</span><span class="mf">0.0</span><span class="p">)</span><span class="o">.</span><span class="n">to</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">device</span><span class="p">)</span>

            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_structure</span><span class="p">:</span>
                <span class="n">adj_meta_score</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">get_adj_score</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">adj_grad_sum</span><span class="p">,</span> <span class="n">modified_adj</span><span class="p">,</span> <span class="n">ori_adj</span><span class="p">,</span> <span class="n">ll_constraint</span><span class="p">,</span> <span class="n">ll_cutoff</span><span class="p">)</span>
            <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_features</span><span class="p">:</span>
                <span class="n">feature_meta_score</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">get_feature_score</span><span class="p">(</span><span class="bp">self</span><span class="o">.</span><span class="n">feature_grad_sum</span><span class="p">,</span> <span class="n">modified_features</span><span class="p">)</span>

            <span class="k">if</span> <span class="n">adj_meta_score</span><span class="o">.</span><span class="n">max</span><span class="p">()</span> <span class="o">&gt;=</span> <span class="n">feature_meta_score</span><span class="o">.</span><span class="n">max</span><span class="p">():</span>
                <span class="n">adj_meta_argmax</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">argmax</span><span class="p">(</span><span class="n">adj_meta_score</span><span class="p">)</span>
                <span class="n">row_idx</span><span class="p">,</span> <span class="n">col_idx</span> <span class="o">=</span> <span class="n">utils</span><span class="o">.</span><span class="n">unravel_index</span><span class="p">(</span><span class="n">adj_meta_argmax</span><span class="p">,</span> <span class="n">ori_adj</span><span class="o">.</span><span class="n">shape</span><span class="p">)</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span><span class="o">.</span><span class="n">data</span><span class="p">[</span><span class="n">row_idx</span><span class="p">][</span><span class="n">col_idx</span><span class="p">]</span> <span class="o">+=</span> <span class="p">(</span><span class="o">-</span><span class="mi">2</span> <span class="o">*</span> <span class="n">modified_adj</span><span class="p">[</span><span class="n">row_idx</span><span class="p">][</span><span class="n">col_idx</span><span class="p">]</span> <span class="o">+</span> <span class="mi">1</span><span class="p">)</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">adj_changes</span><span class="o">.</span><span class="n">data</span><span class="p">[</span><span class="n">col_idx</span><span class="p">][</span><span class="n">row_idx</span><span class="p">]</span> <span class="o">+=</span> <span class="p">(</span><span class="o">-</span><span class="mi">2</span> <span class="o">*</span> <span class="n">modified_adj</span><span class="p">[</span><span class="n">row_idx</span><span class="p">][</span><span class="n">col_idx</span><span class="p">]</span> <span class="o">+</span> <span class="mi">1</span><span class="p">)</span>
            <span class="k">else</span><span class="p">:</span>
                <span class="n">feature_meta_argmax</span> <span class="o">=</span> <span class="n">torch</span><span class="o">.</span><span class="n">argmax</span><span class="p">(</span><span class="n">feature_meta_score</span><span class="p">)</span>
                <span class="n">row_idx</span><span class="p">,</span> <span class="n">col_idx</span> <span class="o">=</span> <span class="n">utils</span><span class="o">.</span><span class="n">unravel_index</span><span class="p">(</span><span class="n">feature_meta_argmax</span><span class="p">,</span> <span class="n">ori_features</span><span class="o">.</span><span class="n">shape</span><span class="p">)</span>
                <span class="bp">self</span><span class="o">.</span><span class="n">feature_changes</span><span class="o">.</span><span class="n">data</span><span class="p">[</span><span class="n">row_idx</span><span class="p">][</span><span class="n">col_idx</span><span class="p">]</span> <span class="o">+=</span> <span class="p">(</span><span class="o">-</span><span class="mi">2</span> <span class="o">*</span> <span class="n">modified_features</span><span class="p">[</span><span class="n">row_idx</span><span class="p">][</span><span class="n">col_idx</span><span class="p">]</span> <span class="o">+</span> <span class="mi">1</span><span class="p">)</span>

        <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_structure</span><span class="p">:</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">modified_adj</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">get_modified_adj</span><span class="p">(</span><span class="n">ori_adj</span><span class="p">)</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span>
        <span class="k">if</span> <span class="bp">self</span><span class="o">.</span><span class="n">attack_features</span><span class="p">:</span>
            <span class="bp">self</span><span class="o">.</span><span class="n">modified_features</span> <span class="o">=</span> <span class="bp">self</span><span class="o">.</span><span class="n">get_modified_features</span><span class="p">(</span><span class="n">ori_features</span><span class="p">)</span><span class="o">.</span><span class="n">detach</span><span class="p">()</span></div></div>
</pre></div>

           </div>
           
          </div>
          <footer>
  

  <hr/>

  <div role="contentinfo">
    <p>
        
        &copy; Copyright 

    </p>
  </div>
    
    
    
    Built with <a href="http://sphinx-doc.org/">Sphinx</a> using a
    
    <a href="https://github.com/rtfd/sphinx_rtd_theme">theme</a>
    
    provided by <a href="https://readthedocs.org">Read the Docs</a>. 

</footer>

        </div>
      </div>

    </section>

  </div>
  

  <script type="text/javascript">
      jQuery(function () {
          SphinxRtdTheme.Navigation.enable(true);
      });
  </script>

  
  
    
   

</body>
</html>