Intruding with Words: Towards Understanding Graph Injection Attacks at the Text Level
Runlin Lei, Yuwei Hu, Yuchen Ren, Zhewei Wei
Abstract
Graph Neural Networks (GNNs) excel across various applications but remain vulnerable to adversarial attacks, particularly Graph Injection Attacks (GIAs), which inject malicious nodes into the original graph and pose realistic threats. Text-attributed graphs (TAGs), where nodes are associated with textual features, are crucial due to their prevalence in real-world applications and are commonly used to evaluate these vulnerabilities. However, existing research only focuses on embedding-level GIAs, which inject node embeddings rather than actual textual content, limiting their applicability and simplifying detection. In this paper, we pioneer the exploration of GIAs at the text level, presenting three novel attack designs that inject textual content into the graph. Through theoretical and empirical analysis, we demonstrate that text interpretability, a factor previously overlooked at the embedding level, plays a crucial role in attack strength. Among the designs we investigate, the Word-frequency-based Text-level GIA (WTGIA) is particularly notable for its balance between performance and interpretability. Despite the success of WTGIA, we discover that defenders can easily enhance their defenses with customized text embedding methods or large language model (LLM)-based predictors. These insights underscore the necessity for further research into the potential and practical significance of text-level GIAs. The code is available at https://github.com/Leirunlin/Text-level-Graph-Attack .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 19881b34-e16b-4c7d-8195-a743bc28617eCited by top-tier papers5
- Robustness in Text-Attributed Graph Learning: Insights, Trade-offs, and New DefensesRunlin Lei, Lu Yi, Mingguo He, Pengyu Qiu et al.ICLR 2026 · 1 citation
- Towards Robust Text-Attributed Federated Graph Learning: Multimodal Threats and DefenseZitong Shi, Guancheng Wan, Wenke Huang, Yuxin Wu et al.AAAI 2026
- GraphTextack: A Realistic Black-Box Node Injection Attack on LLM-Enhanced GNNsJiaji Ma, Puja Trivedi, Danai KoutraAAAI 2026
- Unveiling the Vulnerability of Graph-LLMs: An Interpretable Multi-Dimensional Adversarial Attack on TAGsBowen Fan, Zhilin Guo, Xunkai Li, Yihan Zhou et al.WWW 2026
- Can LLMs Fool Graph Learning? Exploring Universal Adversarial Attacks on Text-Attributed GraphsZihui Chen, Yuling Wang, Pengfei Jiao, Kai Wu et al.WWW 2026
Builds on8
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning ApproachYiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh et al.WWW 2020 · 217 citations
- Large Dual Encoders Are Generalizable RetrieversJianmo Ni, Chen Qu, Jing Lu, Zhuyun Dai et al.EMNLP 2022 · 145 citations
- Can GNN be Good Adapter for LLMs?Xuanwen Huang, Kaiqiao Han, Yang Yang, Dezheng Bao et al.WWW 2024 · 107 citations
- Understanding and Improving Graph Injection Attack by Promoting UnnoticeabilityYongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma et al.ICLR 2022 · 106 citations
Related papers
- TDGIA: Effective Injection Attacks on Graph Neural NetworksXu Zou, Qinkai Zheng, Yuxiao Dong, Xinyu Guan et al.KDD 2021 · 83 citations
- Are LLM-Enhanced Graph Neural Networks Robust Against Poisoning Attacks?Yuhang Ma, Jie Wang, Zheng YanS&P 2026 · 4 citations
- Jointly Attacking Graph Neural Network and its ExplanationsWenqi Fan, Han Xu, Wei Jin, Xiaorui Liu et al.ICDE 2023 · 23 citations
- Fight Fire with Fire: Towards Robust Graph Neural Networks on Dynamic Graphs via Actively DefenseHaoyang Li, Shimin Di, Calvin Hong Yi Li, Lei Chen et al.VLDB 2024 · 6 citations
- Are Your Models Still Fair? Fairness Attacks on Graph Neural Networks via Node InjectionsZihan Luo, Hong Huang, Yongkang Zhou, Jiping Zhang et al.NeurIPS 2024 · 4 citations
