BOCLOAK: Optimal Transport-Guided Adversarial Attacks on Graph Neural Network-Based Bot Detection
Kunal Mukherjee, Zulfikar Alom, Tran Gia Bao Ngo, Cuneyt Akcora, Murat Kantarcioglu
Abstract
The rise of bot accounts on social media poses significant risks to public discourse. To address this threat, modern bot detectors increasingly rely on Graph Neural Networks (GNNs). However, the effectiveness of these GNN-based detectors in realworld settings remains poorly understood. In practice, attackers continuously adapt their strategies as well as must operate under domain-specific and temporal constraints, which can fundamentally limit the applicability of existing attack methods. As a result, there is a critical need for robust GNN-based bot detection methods under realistic, constraint-aware attack scenarios. We introduce BOCLOAK 1 to systematically evaluate the robustness of GNN-based bot detection via both edge editing and node injection adversarial attacks under realistic constraints. BOCLOAK constructs a probability measure over spatio-temporal neighbor features and learns an optimal transport (OT) geometry that separates human and bot behaviors. It then decodes transport plans into sparse, plausible edge edits that evade detection while obeying real-world constraints. We evaluate BOCLOAK across three social bot datasets, five state-of-theart bot detectors, three adversarial defenses, and compare it against four leading graph adversarial attack baselines. BOCLOAK achieves up to 80.13% higher attack success rates while using 99.80% less GPU memory under real-world constraints. BOCLOAK shows that OT provides a lightweight, principled framework for bridging adversarial attacks and real-world bot detection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b2e95428-9a47-4217-a3ec-d9607b3f8b82Builds on6
- Are we really making much progress?: Revisiting, benchmarking and refining heterogeneous graph neural networksQingsong Lv, Ming Ding, Qiang Liu, Yuxiang Chen et al.KDD 2021 · 249 citations
- Robustness of Graph Neural Networks at ScaleSimon Geisler, Tobias Schmidt, Hakan Sirin, Daniel Zügner et al.NeurIPS 2021 · 189 citations
- Heterogeneity-Aware Twitter Bot Detection with Relational Graph TransformersShangbin Feng, Zhaoxuan Tan, Rui Li, Minnan LuoAAAI 2022 · 138 citations
- Pure Message Passing Can Estimate Common Neighbor for Link PredictionKaiwen Dong, Zhichun Guo, Nitesh V. ChawlaNeurIPS 2024 · 30 citations
- Adversarial Training for Graph Neural Networks: Pitfalls, Solutions, and New DirectionsLukas Gosch, Simon Geisler, Daniel Sturm, Bertrand Charpentier et al.NeurIPS 2023 · 19 citations
Related papers
- OTPCL: Optimal Transport Driven Pseudo-Labeling with Contrastive Learning for Social Bot DetectionRuixuan Xu, Mengting Hu, Xinqi Yang, Ming Jiang et al.KDD 2026
- My Brother Helps Me: Node Injection Based Adversarial Attack on Social Bot DetectionLanjun Wang, Xinran Qiao, Yanwei Xie, Weizhi Nie et al.ACM MM 2023 · 3 citations
- Multi-modal Social Bot Detection: Learning Homophilic and Heterophilic Connections AdaptivelyShilong Li, Boyu Qiao, Kun Li, Qianqian Lu et al.ACM MM 2023 · 15 citations
- BotBR: Social Bot Detection with Balanced Feature Fusion and Reliability-Enhanced Graph LearningQilong Lin, Jingya ZhouSIGIR 2025 · 3 citations
- A Hard Label Black-box Adversarial Attack Against Graph Neural NetworksJiaming Mu, Binghui Wang, Qi Li, Kun Sun et al.CCS 2021 · 30 citations
