Revisiting Graph Adversarial Attack and Defense From a Data Distribution Perspective
Kuan Li, Yang Liu, Xiang Ao, Qing He
Abstract
Recent studies have shown that structural perturbations are significantly effective in degrading the accuracy of Graph Neural Networks (GNNs) in the semi-supervised node classification (SSNC) task. However, the reasons for the destructive nature of gradient-based methods have not been explored in-depth. In this work, we discover an interesting phenomenon: the adversarial edges are not uniformly distributed on the graph, and a majority of perturbations are generated around the training nodes in poisoning attacks. Combined with this phenomenon, we provide an explanation for the effectiveness of the gradient-based attack method from a data distribution perspective and revisit both poisoning attack and evasion attack in SSNC. From this new perspective, we empirically and theoretically discuss some other attack tendencies. Based on the analysis, we provide nine practical tips on both attack and defense and meanwhile leverage them to improve existing attack and defense methods. Moreover, we design a fast attack method and a self-training defense method, which outperform the state-of-the-art methods and can effectively scale to large graphs like ogbn-arxiv. We validate our claims through extensive experiments on four benchmark datasets. * Corresponding to Xiang Ao implementation details and the statistics of the datasets are provided in A.1. RELATED WORK Many efforts have been made to study various properties of the gradient-based attack algorithms. GCN-SVD Entezari et al. (2020) discovers that attacks exhibit a specific behavior in the spectrum 1 Our focus is to revisit both attack and defense sides from a new view. These two algorithms are natural byproducts of this work, so we put them in the appendix.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers17
- Demystifying Structural Disparity in Graph Neural Networks: Can One Size Fit All?Haitao Mao, Zhikai Chen, Wei Jin, Haoyu Han et al.NeurIPS 2023 · 58 citations
- FLOOD: A Flexible Invariant Learning Framework for Out-of-Distribution Generalization on GraphsYang Liu, Xiang Ao, Fuli Feng, Yunshan Ma et al.KDD 2023 · 40 citations
- Boosting the Adversarial Robustness of Graph Neural Networks: An OOD PerspectiveKuan Li, Yiwen Chen, Yang Liu, Jin Wang et al.ICLR 2024 · 13 citations
- SPEAR: A Structure-Preserving Manipulation Method for Graph Backdoor AttacksYuanhao Ding, Yang Liu, Yugang Ji, Weigao Wen et al.WWW 2025 · 12 citations
- Can Large Language Models Improve the Adversarial Robustness of Graph Neural Networks?Zhongjian Zhang, Xiao Wang, Huichi Zhou, Yue Yu et al.KDD 2025 · 11 citations
Builds on17
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang et al.KDD 2020 · 604 citations
- Pick and Choose: A GNN-based Imbalanced Learning Approach for Fraud DetectionYang Liu, Xiang Ao, Zidi Qin, Jianfeng Chi et al.WWW 2021 · 527 citations
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 416 citations
- A Fine-Grained Analysis on Distribution ShiftOlivia Wiles, Sven Gowal, Florian Stimberg, Sylvestre-Alvise Rebuffi et al.ICLR 2022 · 258 citations
Related papers
- Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary PerturbationsJiate Li, Meng Pang, Yun Dong, Binghui WangCVPR 2025
- Turning Strengths into Weaknesses: A Certified Robustness Inspired Attack Framework against Graph Neural NetworksBinghui Wang, Meng Pang, Yun DongCVPR 2023
- Graph BackdoorZhaohan Xi, Ren Pang, Shouling Ji, Ting WangUSENIX Security 2021 · 12 citations
- Graph Structural Attack by Perturbing Spectral DistanceLu Lin, Ethan Blaser, Hongning WangKDD 2022 · 28 citations
- Rethinking Label Poisoning for GNNs: Pitfalls and AttacksVijay Lingam, Mohammad Sadegh Akhondzadeh, Aleksandar BojchevskiICLR 2024 · 8 citations
