JANUS: A Dual-Constraint Generative Framework for Stealthy Node Injection Attacks
Jiahao Zhang, Xiaobing Pei, Zhaokun Zhong, Wenqiang Hao, Zhenghao Tang
Abstract
Graph Neural Networks (GNNs) have demonstrated remarkable performance across web-centric applications, yet they are vulnerable to sophisticated adversarial attacks, particularly node injection attacks. The success of such attacks heavily relies on their stealthiness, the ability to blend in with the original graph and evade detection. However, existing methods often achieve stealthiness by relying on indirect proxy metrics, lacking consideration for the fundamental characteristics of the injected content, or focusing only on imitating local structures, which leads to the problem of local myopia. To overcome these limitations, we propose a dual-constraint stealthy node injection framework, called Joint Alignment of Nodal and Universal Structures (JANUS). At the local level, we introduce a local feature manifold alignment strategy to achieve geometric consistency in the feature space. At the global level, we incorporate structured latent variables and maximize the mutual information with the generated structures, ensuring the injected structures are consistent with the semantic patterns of the original graph. We model the injection attack as a sequential decision process, which is optimized by a reinforcement learning agent. Experiments on multiple standard datasets demonstrate that the JANUS framework significantly outperforms existing methods in terms of both attack effectiveness and stealthiness. Our code and scripts are available at https://github.com/jiahaozhang121/JANUS-WWW2026.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on9
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong et al.NeurIPS 2020 · 3,935 citations
- GNNGuard: Defending Graph Neural Networks against Adversarial AttacksXiang Zhang, Marinka ZitnikNeurIPS 2020 · 416 citations
- Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning ApproachYiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh et al.WWW 2020 · 217 citations
- Understanding and Improving Graph Injection Attack by Promoting UnnoticeabilityYongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma et al.ICLR 2022 · 106 citations
- TDGIA: Effective Injection Attacks on Graph Neural NetworksXu Zou, Qinkai Zheng, Yuxiao Dong, Xinyu Guan et al.KDD 2021 · 83 citations
Related papers
- Highly Imperceptible Black-Box Graph Injection Attacks with Reinforcement LearningMaochang Zhao, Jing ZhangAAAI 2025 · 2 citations
- Let Graph Be the Go Board: Gradient-Free Node Injection Attack for Graph Neural Networks via Reinforcement LearningMingxuan Ju, Yujie Fan, Chuxu Zhang, Yanfang YeAAAI 2023 · 48 citations
- Graph BackdoorZhaohan Xi, Ren Pang, Shouling Ji, Ting WangUSENIX Security 2021 · 12 citations
- SPEAR: A Structure-Preserving Manipulation Method for Graph Backdoor AttacksYuanhao Ding, Yang Liu, Yugang Ji, Weigao Wen et al.WWW 2025 · 12 citations
- Graph Adversarial Defense with Virtual Spectral Anchor InjectionXiangchao Wen, Zhen Liu, Yunfei LiuKDD 2026
