Intruding with Words: Towards Understanding Graph Injection Attacks at the Text Level
Runlin Lei, Yuwei Hu, Yuchen Ren, Zhewei Wei
摘要
Graph Neural Networks (GNNs) excel across various applications but remain vulnerable to adversarial attacks, particularly Graph Injection Attacks (GIAs), which inject malicious nodes into the original graph and pose realistic threats. Text-attributed graphs (TAGs), where nodes are associated with textual features, are crucial due to their prevalence in real-world applications and are commonly used to evaluate these vulnerabilities. However, existing research only focuses on embedding-level GIAs, which inject node embeddings rather than actual textual content, limiting their applicability and simplifying detection. In this paper, we pioneer the exploration of GIAs at the text level, presenting three novel attack designs that inject textual content into the graph. Through theoretical and empirical analysis, we demonstrate that text interpretability, a factor previously overlooked at the embedding level, plays a crucial role in attack strength. Among the designs we investigate, the Word-frequency-based Text-level GIA (WTGIA) is particularly notable for its balance between performance and interpretability. Despite the success of WTGIA, we discover that defenders can easily enhance their defenses with customized text embedding methods or large language model (LLM)-based predictors. These insights underscore the necessity for further research into the potential and practical significance of text-level GIAs. The code is available at https://github.com/Leirunlin/Text-level-Graph-Attack .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Robustness in Text-Attributed Graph Learning: Insights, Trade-offs, and New DefensesRunlin Lei, Lu Yi, Mingguo He, Pengyu Qiu 等ICLR 2026 · 被引用 1 次
- Towards Robust Text-Attributed Federated Graph Learning: Multimodal Threats and DefenseZitong Shi, Guancheng Wan, Wenke Huang, Yuxin Wu 等AAAI 2026
- GraphTextack: A Realistic Black-Box Node Injection Attack on LLM-Enhanced GNNsJiaji Ma, Puja Trivedi, Danai KoutraAAAI 2026
- Unveiling the Vulnerability of Graph-LLMs: An Interpretable Multi-Dimensional Adversarial Attack on TAGsBowen Fan, Zhilin Guo, Xunkai Li, Yihan Zhou 等WWW 2026
- Can LLMs Fool Graph Learning? Exploring Universal Adversarial Attacks on Text-Attributed GraphsZihui Chen, Yuling Wang, Pengfei Jiao, Kai Wu 等WWW 2026
它引用的顶会 Paper8
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong 等NeurIPS 2020 · 被引用 3,935 次
- Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning ApproachYiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh 等WWW 2020 · 被引用 217 次
- Large Dual Encoders Are Generalizable RetrieversJianmo Ni, Chen Qu, Jing Lu, Zhuyun Dai 等EMNLP 2022 · 被引用 145 次
- Can GNN be Good Adapter for LLMs?Xuanwen Huang, Kaiqiao Han, Yang Yang, Dezheng Bao 等WWW 2024 · 被引用 107 次
- Understanding and Improving Graph Injection Attack by Promoting UnnoticeabilityYongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma 等ICLR 2022 · 被引用 106 次
相关 Paper
- TDGIA: Effective Injection Attacks on Graph Neural NetworksXu Zou, Qinkai Zheng, Yuxiao Dong, Xinyu Guan 等KDD 2021 · 被引用 83 次
- Are LLM-Enhanced Graph Neural Networks Robust Against Poisoning Attacks?Yuhang Ma, Jie Wang, Zheng YanS&P 2026 · 被引用 4 次
- Jointly Attacking Graph Neural Network and its ExplanationsWenqi Fan, Han Xu, Wei Jin, Xiaorui Liu 等ICDE 2023 · 被引用 23 次
- Fight Fire with Fire: Towards Robust Graph Neural Networks on Dynamic Graphs via Actively DefenseHaoyang Li, Shimin Di, Calvin Hong Yi Li, Lei Chen 等VLDB 2024 · 被引用 6 次
- Are Your Models Still Fair? Fairness Attacks on Graph Neural Networks via Node InjectionsZihan Luo, Hong Huang, Yongkang Zhou, Jiping Zhang 等NeurIPS 2024 · 被引用 4 次
