TDGIA: Effective Injection Attacks on Graph Neural Networks
Xu Zou, Qinkai Zheng, Yuxiao Dong, Xinyu Guan, Evgeny Kharlamov, Jialiang Lu, Jie Tang
Abstract
Graph Neural Networks (GNNs) have achieved promising performance in various real-world applications. However, recent studies find that GNNs are vulnerable to adversarial attacks. In this paper, we study a recently-introduced realistic attack scenario on graphsgraph injection attack (GIA). In the GIA scenario, the adversary is not able to modify the existing link structure or node attributes of the input graph, instead the attack is performed by injecting adversarial nodes into it. We present an analysis on the topological vulnerability of GNNs under GIA setting, based on which we propose the Topological Defective Graph Injection Attack (TDGIA) for effective injection attacks. TDGIA first introduces the topological defective edge selection strategy to choose the original nodes for connecting with the injected ones. It then designs the smooth feature optimization objective to generate the features for the injected nodes. Extensive experiments on large-scale datasets show that TD-GIA can consistently and significantly outperform various attack baselines in attacking dozens of defense GNN models. Notably, the performance drop on target GNNs resultant from TDGIA is more than double the damage brought by the best attack solution among hundreds of submissions on KDD-CUP 2020. CCS CONCEPTS • Security and privacy → Software and application security; • Mathematics of computing → Graph algorithms.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext afa0a118-e1b7-47e4-b470-058a9b3b0e32Cited by top-tier papers35
- Unnoticeable Backdoor Attacks on Graph Neural NetworksEnyan Dai, Minhua Lin, Xiang Zhang, Suhang WangWWW 2023 · 85 citations
- On the Robustness of Graph Neural Diffusion to Topology PerturbationsYang Song, Qiyu Kang, Sijie Wang, Kai Zhao et al.NeurIPS 2022 · 48 citations
- Adversarial Robustness in Graph Neural Networks: A Hamiltonian ApproachKai Zhao, Qiyu Kang, Yang Song, Rui She et al.NeurIPS 2023 · 45 citations
- CogDL: A Comprehensive Library for Graph Deep LearningYukuo Cen, Zhenyu Hou, Yan Wang, Qibin Chen et al.WWW 2023 · 25 citations
- Unleashing the Potential of Fractional Calculus in Graph Neural Networks with FRONDQiyu Kang, Kai Zhao, Qinxu Ding, Feng Ji et al.ICLR 2024 · 21 citations
Builds on4
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- TextBugger: Generating Adversarial Text Against Real-world ApplicationsJinfeng Li, Shouling Ji, Tianyu Du, Bo Li et al.NDSS 2019 · 876 citations
- Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning ApproachYiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh et al.WWW 2020 · 217 citations
Related papers
- Fight Fire with Fire: Towards Robust Graph Neural Networks on Dynamic Graphs via Actively DefenseHaoyang Li, Shimin Di, Calvin Hong Yi Li, Lei Chen et al.VLDB 2024 · 6 citations
- Are Your Models Still Fair? Fairness Attacks on Graph Neural Networks via Node InjectionsZihan Luo, Hong Huang, Yongkang Zhou, Jiping Zhang et al.NeurIPS 2024 · 4 citations
- Understanding and Improving Graph Injection Attack by Promoting UnnoticeabilityYongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma et al.ICLR 2022 · 106 citations
- Highly Imperceptible Black-Box Graph Injection Attacks with Reinforcement LearningMaochang Zhao, Jing ZhangAAAI 2025 · 2 citations
- Intruding with Words: Towards Understanding Graph Injection Attacks at the Text LevelRunlin Lei, Yuwei Hu, Yuchen Ren, Zhewei WeiNeurIPS 2024 · 11 citations
