Blindfolded Attackers Still Threatening: Strict Black-Box Adversarial Attacks on Graphs
Jiarong Xu, Yizhou Sun, Xin Jiang, Yanhao Wang, Chunping Wang, Jiangang Lu, Yang Yang
Abstract
Adversarial attacks on graphs have attracted considerable research interests. Existing works assume the attacker is either (partly) aware of the victim model, or able to send queries to it. These assumptions are, however, unrealistic. To bridge the gap between theoretical graph attacks and real-world scenarios, in this work, we propose a novel and more realistic setting: strict black-box graph attack, in which the attacker has no knowledge about the victim model at all and is not allowed to send any queries. To design such an attack strategy, we first propose a generic graph filter to unify different families of graph-based models. The strength of attacks can then be quantified by the change in the graph filter before and after attack. By maximizing this change, we are able to find an effective attack strategy, regardless of the underlying model. To solve this optimization problem, we also propose a relaxation technique and approximation theories to reduce the difficulty as well as the computational expense. Experiments demonstrate that, even with no exposure to the model, the Macro-F1 drops 6.4% in node classification and 29.5% in graph classification, which is a significant result compared with existent works.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cd1c0dc5-306f-4e3e-8b5e-da85048f1b57Cited by top-tier papers5
- CogDL: A Comprehensive Library for Graph Deep LearningYukuo Cen, Zhenyu Hou, Yan Wang, Qibin Chen et al.WWW 2023 · 25 citations
- Tree of Preferences for Diversified RecommendationHanyang Yuan, Ning Tang, Tongya Zheng, Jiarong Xu et al.NeurIPS 2025 · 3 citations
- Can Graph Neural Networks Expose Training Data Properties? An Efficient Risk Assessment ApproachHanyang Yuan, Jiarong Xu, Renhong Huang, Mingli Song et al.NeurIPS 2024 · 3 citations
- HyperNear: Unnoticeable Node Injection Attacks on Hypergraph Neural NetworksTingyi Cai, Yunliang Jiang, Ming Li, Lu Bai et al.ICML 2025
- A First-Principles Evaluation of Graph-Based Network Intrusion Detection SystemsRui Zhao, Wajih UI HassanCCS 2026
Builds on2
Related papers
- A Hard Label Black-box Adversarial Attack Against Graph Neural NetworksJiaming Mu, Binghui Wang, Qi Li, Kun Sun et al.CCS 2021 · 30 citations
- Adversarial Attacks on Graph Classifiers via Bayesian OptimisationXingchen Wan, Henry Kenlay, Robin Ru, Arno Blaas et al.NeurIPS 2021 · 27 citations
- Bandits for Structure Perturbation-based Black-box Attacks to Graph Neural Networks with Theoretical GuaranteesBinghui Wang, Youqi Li, Pan ZhouCVPR 2022 · 16 citations
- Revisiting Graph Adversarial Attack: A Perspective of Budget OptimizationXiangchao Wen, Zhen Liu, Yuxin YouKDD 2025
- Devil in Disguise: Breaching Graph Neural Networks Privacy through InfiltrationLingshuo Meng, Yijie Bai, Yanjiao Chen, Yutong Hu et al.CCS 2023 · 9 citations
