Rethinking Label Poisoning for GNNs: Pitfalls and Attacks
Vijay Lingam, Mohammad Sadegh Akhondzadeh, Aleksandar Bojchevski
Abstract
Node labels for graphs are usually generated using an automated process, or crowd-sourced from human users. This opens up avenues for malicious users to compromise the training labels, making it unwise to blindly rely on them. While robustness against noisy labels is an active area of research, there are only a handful of papers in the literature that address this for graph-based data. Even more so, the effects of adversarial label perturbations are sparsely studied. A recent work revealed that the entire literature on label poisoning for GNNs is plagued by serious evaluation pitfalls and showed how existing attacks render ineffective post fixing these shortcomings. In this work, we introduce two new simple yet effective attacks that are significantly stronger (up to ∼ 8%) than the previous strongest attack. Our work demonstrates the need for more robust defense mechanisms, especially considering the transferability of our attacks, where a strategy devised for one model can effectively contaminate numerous other models.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- A Cognac Shot To Forget Bad Memories: Corrective Unlearning for Graph Neural NetworksVarshita Kolipaka, Akshit Sinha, Debangan Mishra, Sumit Kumar et al.ICML 2025
- EvA: Evolutionary Attacks on GraphsMohammad Sadegh Akhondzadeh, Soroush H. Zargarbashi, Jimin Cao, Aleksandar BojchevskiICLR 2026
- Certifying Graph Neural Networks Against Label and Structure PoisoningLukas Gosch, Xichuan Chen, Yan Scholten, Stephan GünnemannICML 2026
- Exact Certification of (Graph) Neural Networks Against Label PoisoningMahalakshmi Sabanayagam, Lukas Gosch, Stephan Günnemann, Debarghya GhoshdastidarICLR 2025
- Enhancing Graph Classification Robustness with Singular PoolingSofiane Ennadir, Oleg Smirnov, Yassine Abbahaddou, Lele Cao et al.NeurIPS 2025
Builds on5
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- Gradient Estimation with Stochastic Softmax TricksMax B. Paulus, Dami Choi, Daniel Tarlow, Andreas Krause et al.NeurIPS 2020 · 104 citations
- Are Defenses for Graph Neural Networks Robust?Felix Mujkanovic, Simon Geisler, Stephan Günnemann, Aleksandar BojchevskiNeurIPS 2022 · 79 citations
Related papers
- Deterministic Certification of Graph Neural Networks against Graph Poisoning Attacks with Arbitrary PerturbationsJiate Li, Meng Pang, Yun Dong, Binghui WangCVPR 2025
- Boosting the Adversarial Robustness of Graph Neural Networks: An OOD PerspectiveKuan Li, Yiwen Chen, Yang Liu, Jin Wang et al.ICLR 2024 · 13 citations
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang et al.KDD 2020 · 604 citations
- Are LLM-Enhanced Graph Neural Networks Robust Against Poisoning Attacks?Yuhang Ma, Jie Wang, Zheng YanS&P 2026 · 4 citations
- How does Heterophily Impact the Robustness of Graph Neural Networks?: Theoretical Connections and Practical ImplicationsJiong Zhu, Junchen Jin, Donald Loveland, Michael T. Schaub et al.KDD 2022 · 26 citations
