BinarizedAttack: Structural Poisoning Attacks to Graph-based Anomaly Detection
Yulin Zhu, Yuni Lai, Kaifa Zhao, Xiapu Luo, Mingquan Yuan, Jian Ren, Kai Zhou
Abstract
Graph-based Anomaly Detection (GAD) is becoming prevalent due to the powerful representation abilities of graphs as well as recent advances in graph mining techniques. These GAD tools, however, expose a new attacking surface, ironically due to their unique advantage of being able to exploit the relations among data. That is, attackers now can manipulate those relations (i.e., the structure of the graph) to allow some target nodes to evade detection. In this paper, we exploit this vulnerability by designing a new type of targeted structural poisoning attacks to a representative regression-based GAD system termed OddBall. Specifically, we formulate the attack against OddBall as a bi-level optimization problem, where the key technical challenge is to efficiently solve the problem in a discrete domain. We propose a novel attack method termed BinarizedAttack based on gradient descent. Comparing to prior arts, BinarizedAttack can better use the gradient information, making it particularly suitable for solving combinatorial optimization problems. Furthermore, we investigate the attack transferability of BinarizedAttack by employing it to attack other representation-learning-based GAD systems. Our comprehensive experiments demonstrate that BinarizedAttack is very effective in enabling target nodes to evade graph-based anomaly detection tools with limited attacker's budget, and in the black-box transfer attack setting, BinarizedAttack is also tested effective and in particular, can significantly change the node embeddings learned by the GAD systems. Our research thus opens the door to studying a new type of attack against security analytic tools that rely on graph data.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a8e98a9b-1ae8-419e-9f72-46fe46869d07Cited by top-tier papers4
- Reliable Representations Make A Stronger Defender: Unsupervised Structure Refinement for Robust GNNKuan Li, Yang Liu, Xiang Ao, Jianfeng Chi et al.KDD 2022 · 63 citations
- A Fine-grained Chinese Software Privacy Policy Dataset for Sequence Labeling and Regulation Compliant IdentificationKaifa Zhao, Le Yu, Shiyao Zhou, Jing Li et al.EMNLP 2022 · 7 citations
- Refine then Classify: Robust Graph Neural Networks with Reliable Neighborhood Contrastive RefinementShuman Zhuang, Zhihao Wu, Zhaoliang Chen, Hong-Ning Dai et al.AAAI 2025 · 4 citations
- Revisiting Graph Adversarial Attack and Defense From a Data Distribution PerspectiveKuan Li, Yang Liu, Xiang Ao, Qing HeICLR 2023
Builds on2
Related papers
- How to Cover up Anomalous Accesses to Electronic Health RecordsXiaojun Xu, Qingying Hao, Zhuolin Yang, Bo Li et al.USENIX Security 2023
- Attacking Graph-based Classification via Manipulating the Graph StructureBinghui Wang, Neil Zhenqiang GongCCS 2019 · 175 citations
- Structural Attack against Graph Based Android Malware DetectionKaifa Zhao, Hao Zhou, Yulin Zhu, Xian Zhan et al.CCS 2021 · 48 citations
- Curriculum Graph PoisoningHanwen Liu, Peilin Zhao, Tingyang Xu, Yatao Bian et al.WWW 2023 · 3 citations
- A Hard Label Black-box Adversarial Attack Against Graph Neural NetworksJiaming Mu, Binghui Wang, Qi Li, Kun Sun et al.CCS 2021 · 30 citations
