Let Graph Be the Go Board: Gradient-Free Node Injection Attack for Graph Neural Networks via Reinforcement Learning
Mingxuan Ju, Yujie Fan, Chuxu Zhang, Yanfang Ye
摘要
Graph Neural Networks (GNNs) have drawn significant attentions over the years and been broadly applied to essential applications requiring solid robustness or vigorous security standards, such as product recommendation and user behavior modeling. Under these scenarios, exploiting GNN's vulnerabilities and further downgrading its performance become extremely incentive for adversaries. Previous attackers mainly focus on structural perturbations or node injections to the existing graphs, guided by gradients from the surrogate models. Although they deliver promising results, several limitations still exist. For the structural perturbation attack, to launch a proposed attack, adversaries need to manipulate the existing graph topology, which is impractical in most circumstances. Whereas for the node injection attack, though being more practical, current approaches require training surrogate models to simulate a white-box setting, which results in significant performance downgrade when the surrogate architecture diverges from the actual victim model. To bridge these gaps, in this paper, we study the problem of black-box node injection attack, without training a potentially misleading surrogate model. Specifically, we model the node injection attack as a Markov decision process and propose Gradient-free Graph Advantage Actor Critic, namely G 2 A2C, a reinforcement learning framework in the fashion of advantage actor critic. By directly querying the victim model, G 2 A2C learns to inject highly malicious nodes with extremely limited attacking budgets, while maintaining a similar node feature distribution. Through our comprehensive experiments over eight acknowledged benchmark datasets with different characteristics, we demonstrate the superior performance of our proposed G 2 A2C over the existing state-of-the-art attackers. Source code is publicly available at: https://github.com/jumxglhf/G2A2C .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper20
- GraphPatcher: Mitigating Degree Bias for Graph Neural Networks via Test-time AugmentationMingxuan Ju, Tong Zhao, Wenhao Yu, Neil Shah 等NeurIPS 2023 · 被引用 52 次
- How Does Message Passing Improve Collaborative Filtering?Mingxuan Ju, William Shiao, Zhichun Guo, Yanfang Ye 等NeurIPS 2024 · 被引用 21 次
- Bounding the Expected Robustness of Graph Neural Networks Subject to Node Feature AttacksYassine Abbahaddou, Sofiane Ennadir, Johannes F. Lutzeyer, Michalis Vazirgiannis 等ICLR 2024 · 被引用 15 次
- Node-aware Bi-smoothing: Certified Robustness against Graph Injection AttacksYuni Lai, Yulin Zhu, Bailin Pan, Kai ZhouS&P 2024 · 被引用 11 次
- Unveiling the Threat of Fraud Gangs to Graph Neural Networks: Multi-Target Graph Injection Attacks Against GNN-Based Fraud DetectorsJinhyeok Choi, Heehyeon Kim, Joyce Jiyoung WhangAAAI 2025 · 被引用 6 次
它引用的顶会 Paper4
- Open Graph Benchmark: Datasets for Machine Learning on GraphsWeihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong 等NeurIPS 2020 · 被引用 3,935 次
- Attacking Graph-based Classification via Manipulating the Graph StructureBinghui Wang, Neil Zhenqiang GongCCS 2019 · 被引用 175 次
- Understanding and Improving Graph Injection Attack by Promoting UnnoticeabilityYongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma 等ICLR 2022 · 被引用 106 次
- Adaptive Kernel Graph Neural NetworkMingxuan Ju, Shifu Hou, Yujie Fan, Jianan Zhao 等AAAI 2022 · 被引用 33 次
相关 Paper
- Highly Imperceptible Black-Box Graph Injection Attacks with Reinforcement LearningMaochang Zhao, Jing ZhangAAAI 2025 · 被引用 2 次
- Graph Adversarial Attack via RewiringYao Ma, Suhang Wang, Tyler Derr, Lingfei Wu 等KDD 2021 · 被引用 62 次
- JANUS: A Dual-Constraint Generative Framework for Stealthy Node Injection AttacksJiahao Zhang, Xiaobing Pei, Zhaokun Zhong, Wenqiang Hao 等WWW 2026
- TDGIA: Effective Injection Attacks on Graph Neural NetworksXu Zou, Qinkai Zheng, Yuxiao Dong, Xinyu Guan 等KDD 2021 · 被引用 83 次
- A Hard Label Black-box Adversarial Attack Against Graph Neural NetworksJiaming Mu, Binghui Wang, Qi Li, Kun Sun 等CCS 2021 · 被引用 30 次
