LiSA: Leveraging Link Recommender to Attack Graph Neural Networks via Subgraph Injection

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Zhang, Wenlun, Dai, Enyan, Yoshioka, Kentaro
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866916801940553728
author Zhang, Wenlun
Dai, Enyan
Yoshioka, Kentaro
author_facet Zhang, Wenlun
Dai, Enyan
Yoshioka, Kentaro
contents Graph Neural Networks (GNNs) have demonstrated remarkable proficiency in modeling data with graph structures, yet recent research reveals their susceptibility to adversarial attacks. Traditional attack methodologies, which rely on manipulating the original graph or adding links to artificially created nodes, often prove impractical in real-world settings. This paper introduces a novel adversarial scenario involving the injection of an isolated subgraph to deceive both the link recommender and the node classifier within a GNN system. Specifically, the link recommender is mislead to propose links between targeted victim nodes and the subgraph, encouraging users to unintentionally establish connections and that would degrade the node classification accuracy, thereby facilitating a successful attack. To address this, we present the LiSA framework, which employs a dual surrogate model and bi-level optimization to simultaneously meet two adversarial objectives. Extensive experiments on real-world datasets demonstrate the effectiveness of our method.
format Preprint
id arxiv_https___arxiv_org_abs_2502_09271
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle LiSA: Leveraging Link Recommender to Attack Graph Neural Networks via Subgraph Injection
Zhang, Wenlun
Dai, Enyan
Yoshioka, Kentaro
Machine Learning
Artificial Intelligence
Graph Neural Networks (GNNs) have demonstrated remarkable proficiency in modeling data with graph structures, yet recent research reveals their susceptibility to adversarial attacks. Traditional attack methodologies, which rely on manipulating the original graph or adding links to artificially created nodes, often prove impractical in real-world settings. This paper introduces a novel adversarial scenario involving the injection of an isolated subgraph to deceive both the link recommender and the node classifier within a GNN system. Specifically, the link recommender is mislead to propose links between targeted victim nodes and the subgraph, encouraging users to unintentionally establish connections and that would degrade the node classification accuracy, thereby facilitating a successful attack. To address this, we present the LiSA framework, which employs a dual surrogate model and bi-level optimization to simultaneously meet two adversarial objectives. Extensive experiments on real-world datasets demonstrate the effectiveness of our method.
title LiSA: Leveraging Link Recommender to Attack Graph Neural Networks via Subgraph Injection
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2502.09271