Understanding and Improving Graph Injection Attack by Promoting Unnoticeability
Yongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma, Tongliang Liu, Bo Han, James Cheng
Abstract
Recently Graph Injection Attack (GIA) emerges as a practical attack scenario on Graph Neural Networks (GNNs), where the adversary can merely inject few malicious nodes instead of modifying existing nodes or edges, i.e., Graph Modification Attack (GMA). Although GIA has achieved promising results, little is known about why it is successful and whether there is any pitfall behind the success. To understand the power of GIA, we compare it with GMA and find that GIA can be provably more harmful than GMA due to its relatively high flexibility. However, the high flexibility will also lead to great damage to the homophily distribution of the original graph, i.e., similarity among neighbors. Consequently, the threats of GIA can be easily alleviated or even prevented by homophily-based defenses designed to recover the original homophily. To mitigate the issue, we introduce a novel constraint -- homophily unnoticeability that enforces GIA to preserve the homophily, and propose Harmonious Adversarial Objective (HAO) to instantiate it. Extensive experiments verify that GIA with HAO can break homophily-based defenses and outperform previous GIA attacks by a significant margin. We believe our methods can serve for a more reliable evaluation of the robustness of GNNs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 516664a4-a566-4921-bb5d-4fccaca74fa7Cited by top-tier papers42
- Learning Causally Invariant Representations for Out-of-Distribution Generalization on GraphsYongqiang Chen, Yonggang Zhang, Yatao Bian, Han Yang et al.NeurIPS 2022 · 246 citations
- Natural Color Fool: Towards Boosting Black-box Unrestricted AttacksShengming Yuan, Qilong Zhang, Lianli Gao, Yaya Cheng et al.NeurIPS 2022 · 86 citations
- Unnoticeable Backdoor Attacks on Graph Neural NetworksEnyan Dai, Minhua Lin, Xiang Zhang, Suhang WangWWW 2023 · 85 citations
- EvenNet: Ignoring Odd-Hop Neighbors Improves Robustness of Graph Neural NetworksRunlin Lei, Zhen Wang, Yaliang Li, Bolin Ding et al.NeurIPS 2022 · 72 citations
- Does Invariant Graph Learning via Environment Augmentation Learn Invariance?Yongqiang Chen, Yatao Bian, Kaiwen Zhou, Binghui Xie et al.NeurIPS 2023 · 71 citations
Builds on14
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- DropEdge: Towards Deep Graph Convolutional Networks on Node ClassificationYu Rong, Wenbing Huang, Tingyang Xu, Junzhou HuangICLR 2020 · 1,599 citations
- Beyond Homophily in Graph Neural Networks: Current Limitations and Effective DesignsJiong Zhu, Yujun Yan, Lingxiao Zhao, Mark Heimann et al.NeurIPS 2020 · 1,490 citations
- Geom-GCN: Geometric Graph Convolutional NetworksHongbin Pei, Bingzhe Wei, Kevin Chen-Chuan Chang, Yu Lei et al.ICLR 2020 · 1,445 citations
- GraphSAINT: Graph Sampling Based Inductive Learning MethodHanqing Zeng, Hongkuan Zhou, Ajitesh Srivastava, Rajgopal Kannan et al.ICLR 2020 · 1,155 citations
Related papers
- Are Your Models Still Fair? Fairness Attacks on Graph Neural Networks via Node InjectionsZihan Luo, Hong Huang, Yongkang Zhou, Jiping Zhang et al.NeurIPS 2024 · 4 citations
- HyperNear: Unnoticeable Node Injection Attacks on Hypergraph Neural NetworksTingyi Cai, Yunliang Jiang, Ming Li, Lu Bai et al.ICML 2025
- How does Heterophily Impact the Robustness of Graph Neural Networks?: Theoretical Connections and Practical ImplicationsJiong Zhu, Junchen Jin, Donald Loveland, Michael T. Schaub et al.KDD 2022 · 26 citations
- TDGIA: Effective Injection Attacks on Graph Neural NetworksXu Zou, Qinkai Zheng, Yuxiao Dong, Xinyu Guan et al.KDD 2021 · 83 citations
- Making Classic GNNs Strong Baselines Across Varying Homophily: A Smoothness-Generalization PerspectiveMing Gu, Zhuonan Zheng, Sheng Zhou, Meihan Liu et al.NeurIPS 2025 · 4 citations
