My Brother Helps Me: Node Injection Based Adversarial Attack on Social Bot Detection
Lanjun Wang, Xinran Qiao, Yanwei Xie, Weizhi Nie, Yongdong Zhang, Anan Liu
摘要
Social platforms such as Twitter are under siege from a multitude of fraudulent users. In response, social bot detection tasks have been developed to identify such fake users. Due to the structure of social networks, the majority of methods are based on the graph neural network(GNN), which is susceptible to attacks. In this study, we propose a node injection-based adversarial attack method designed to deceive bot detection models. Notably, neither the target bot nor the newly injected bot can be detected when a new bot is added around the target bot. This attack operates in a black-box fashion, implying that any information related to the victim model remains unknown. To our knowledge, this is the first study exploring the resilience of bot detection through graph node injection. Furthermore, we develop an attribute recovery module to revert the injected node embedding from the graph embedding space back to the original feature space, enabling the adversary to manipulate node perturbation effectively. We conduct adversarial attacks on four commonly used GNN structures for bot detection on two widely used datasets: Cresci-2015 and TwiBot-22. The attack success rate is over 73% and the rate of newly injected nodes being detected as bots is below 13% on these two datasets.
• Computing methodologies → Machine learning algorithms; • Security and privacy → Human and societal aspects of security and privacy.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- BOCLOAK: Optimal Transport-Guided Adversarial Attacks on Graph Neural Network-Based Bot DetectionKunal Mukherjee, Zulfikar Alom, Tran Gia Bao Ngo, Cuneyt Akcora 等ICML 2026 · 被引用 3 次
- Robustness in Text-Attributed Graph Learning: Insights, Trade-offs, and New DefensesRunlin Lei, Lu Yi, Mingguo He, Pengyu Qiu 等ICLR 2026 · 被引用 1 次
- FediScan: Collaborative Social Bot Detection in the FediverseMin Gao, Wen Wen, Haoran Du, Qiang Duan 等WWW 2026
它引用的顶会 Paper8
- Are we really making much progress?: Revisiting, benchmarking and refining heterogeneous graph neural networksQingsong Lv, Ming Ding, Qiang Liu, Yuxiang Chen 等KDD 2021 · 被引用 249 次
- Adversarial Attacks on Graph Neural Networks via Node Injections: A Hierarchical Reinforcement Learning ApproachYiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh 等WWW 2020 · 被引用 217 次
- Towards More Practical Adversarial Attacks on Graph Neural NetworksJiaqi Ma, Shuangrui Ding, Qiaozhu MeiNeurIPS 2020 · 被引用 160 次
- Meta Gradient Adversarial AttackZheng Yuan, Jie Zhang, Yunpei Jia, Chuanqi Tan 等ICCV 2021 · 被引用 95 次
- Graph Adversarial Attack via RewiringYao Ma, Suhang Wang, Tyler Derr, Lingfei Wu 等KDD 2021 · 被引用 62 次
相关 Paper
- Devil in Disguise: Breaching Graph Neural Networks Privacy through InfiltrationLingshuo Meng, Yijie Bai, Yanjiao Chen, Yutong Hu 等CCS 2023 · 被引用 9 次
- Highly Imperceptible Black-Box Graph Injection Attacks with Reinforcement LearningMaochang Zhao, Jing ZhangAAAI 2025 · 被引用 2 次
- TDGIA: Effective Injection Attacks on Graph Neural NetworksXu Zou, Qinkai Zheng, Yuxiao Dong, Xinyu Guan 等KDD 2021 · 被引用 83 次
- JANUS: A Dual-Constraint Generative Framework for Stealthy Node Injection AttacksJiahao Zhang, Xiaobing Pei, Zhaokun Zhong, Wenqiang Hao 等WWW 2026
- Are Your Models Still Fair? Fairness Attacks on Graph Neural Networks via Node InjectionsZihan Luo, Hong Huang, Yongkang Zhou, Jiping Zhang 等NeurIPS 2024 · 被引用 4 次
