Prompt as a Double-Edged Sword: A Dynamic Equilibrium Gradient-Assigned Attack against Graph Prompt Learning
Ju Jia, Jingxuan Yu, Di Wu, Cong Wu, Hengjie Zhu, Lina Wang
Abstract
Graph prompt learning (GPL) is designed to bridge the gap between graph pretraining models and downstream graph tasks, providing advantages in terms of graph knowledge transfer. However, GPL is vulnerable to poisoned graph attacks that induce abnormal training via adversarial malicious perturbations. We observe that the prevalent meta-gradient attacks, which heavily rely on the training of surrogate graph neural networks (GNNs), fail to account for the impact of perturbations on GPL where the pretrained GNN remains frozen and graph prompt tokens are tuned. Moreover, their gradient-assigned strategies tend to corrupt the topological semantics on a few influential labeled graphs, which in turn diminishes the trustworthiness of the surrogate training. To address this issue, we propose a dynamic equilibrium gradient-assigned attack against GPL, named MetaGpro. To guarantee the transferability of MetaGpro, the surrogate GPL is utilized in our simulation across various downstream tasks. To dynamically equilibrate the relationships between the reliability of surrogate models and instable structures, the over-robust contrastive learning is integrated into the surrogate training. In this way, the gradient bias caused by excessive perturbations of labeled nodes can be effectively mitigated. Subsequently, the topology perturbation generation is exploited to assign more gradient weights to nodes that are closer to the misclassification area. The experimental results reveal that the surrogate GPL outperforms the surrogate GNN in 96% of downstream evaluations, and our MetaGpro reduces the accuracy of GPL by 2%∼20% compared to the state-of-the-art (SOTA) works mostly. The code for our MetaGpro is available here.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers1
Ask how each one uses itRelated papers
- Are You Using Reliable Graph Prompts? Trojan Prompt Attacks on Graph Neural NetworksMinhua Lin, Zhiwei Zhang, Enyan Dai, Zongyu Wu et al.KDD 2025
- Cross-Context Backdoor Attacks against Graph Prompt LearningXiaoting Lyu, Yufei Han, Wei Wang, Hangwei Qian et al.KDD 2024 · 10 citations
- Attribute-guided Dynamic Prompt Learning for Graph Neural NetworksZhuomin Liang, Liang Bai, Xian YangAAAI 2026
- Unsupervised Heterogeneous Graph Rewriting Attack via Node ClusteringHaosen Wang, Can Xu, Chenglong Shi, Pengfei Zheng et al.KDD 2024 · 4 citations
- Similarity Preserving Adversarial Graph Contrastive LearningYeonjun In, Kanghoon Yoon, Chanyoung ParkKDD 2023 · 15 citations
