EvA: Evolutionary Attacks on Graphs

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Akhondzadeh, Mohammad Sadegh, Zargarbashi, Soroush H., Cao, Jimin, Bojchevski, Aleksandar
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866909684060913664
author Akhondzadeh, Mohammad Sadegh
Zargarbashi, Soroush H.
Cao, Jimin
Bojchevski, Aleksandar
author_facet Akhondzadeh, Mohammad Sadegh
Zargarbashi, Soroush H.
Cao, Jimin
Bojchevski, Aleksandar
contents Even a slight perturbation in the graph structure can cause a significant drop in the accuracy of graph neural networks (GNNs). Most existing attacks leverage gradient information to perturb edges. This relaxes the attack's optimization problem from a discrete to a continuous space, resulting in solutions far from optimal. It also restricts the adaptability of the attack to non-differentiable objectives. Instead, we introduce a few simple yet effective enhancements of an evolutionary-based algorithm to solve the discrete optimization problem directly. Our Evolutionary Attack (EvA) works with any black-box model and objective, eliminating the need for a differentiable proxy loss. This allows us to design two novel attacks that reduce the effectiveness of robustness certificates and break conformal sets. The memory complexity of our attack is linear in the attack budget. Among our experiments, EvA shows $\sim$11\% additional drop in accuracy on average compared to the best previous attack, revealing significant untapped potential in designing attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2507_08212
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle EvA: Evolutionary Attacks on Graphs
Akhondzadeh, Mohammad Sadegh
Zargarbashi, Soroush H.
Cao, Jimin
Bojchevski, Aleksandar
Machine Learning
Even a slight perturbation in the graph structure can cause a significant drop in the accuracy of graph neural networks (GNNs). Most existing attacks leverage gradient information to perturb edges. This relaxes the attack's optimization problem from a discrete to a continuous space, resulting in solutions far from optimal. It also restricts the adaptability of the attack to non-differentiable objectives. Instead, we introduce a few simple yet effective enhancements of an evolutionary-based algorithm to solve the discrete optimization problem directly. Our Evolutionary Attack (EvA) works with any black-box model and objective, eliminating the need for a differentiable proxy loss. This allows us to design two novel attacks that reduce the effectiveness of robustness certificates and break conformal sets. The memory complexity of our attack is linear in the attack budget. Among our experiments, EvA shows $\sim$11\% additional drop in accuracy on average compared to the best previous attack, revealing significant untapped potential in designing attacks.
title EvA: Evolutionary Attacks on Graphs
topic Machine Learning
url https://arxiv.org/abs/2507.08212