Paper proposes a black-box adversarial attack method for graph embedding models.
problem Robustness of graph embedding models against adversarial attacks.
method GF-Attack constructs a generalized adversarial attacker by the graph filter and feature matrix, performing the attack on the graph filter in a black-box fashion.
result GF-Attack can consistently make strong attacks on different graph embedding models even with small perturbations.
Efficiently attacks large-scale graphs without using the whole graph.
problem Vulnerability of graph neural networks to adversarial attacks.
method Simplified Gradient-based Attack (SGA) method for large-scale graphs.
result SGA achieves significant time and memory efficiency improvements.
Paper proposes efficient algorithms for exact inference in Bayesian attack graphs.
problem Analyzing network vulnerabilities and attacker paths using Bayesian networks.
method Efficient algorithms for exact inference in Bayesian attack graphs.
result Computational advantages in time and memory use compared to existing approaches.
New attacks manipulate knowledge graph embeddings by adding or deleting facts.
problem Lack of robustness of KGE to adversarial attacks.
method Data poisoning attack strategies to manipulate knowledge graph embeddings.
result Demonstrated effectiveness and efficiency of proposed attack strategies.
Graph deep learning models are vulnerable to adversarial attacks, which this paper addresses.
problem Adversarial attacks on graph data models, especially their discreteness and imperceptible perturbations.
method Proposed both attack and defense techniques, including integrated gradients for attacks and graph inspection for defenses.
result Demonstrated the effectiveness of proposed methods through experiments on various datasets.
Pro-GNN defends graph neural networks from adversarial attacks by learning graph structure.
problem Vulnerability of GNNs to adversarial attacks on real-world graphs.
method Pro-GNN learns a structural graph and a robust GNN model jointly from perturbed graphs guided by intrinsic graph properties.
result Pro-GNN achieves significantly better performance than state-of-the-art defense methods, even on heavily perturbed graphs.
This paper tackles adversarial attacks on graph data structures.
problem Robustness of graph neural networks against adversarial attacks.
method Reinforcement learning, genetic algorithms, gradient methods.
result Graph Neural Network models are vulnerable to adversarial attacks.
New attacks and defenses for GNNs on large graphs.
problem Vulnerability of GNNs to adversarial attacks on large graphs.
method Proposed two sparsity-aware first-order optimization attacks and a robust aggregation function.
result Attacks can double in strength, and defenses are effective at all scales.
Paper presents an optimization-based attack and defense for graph neural networks.
problem Adversarial robustness of graph neural networks (GNNs).
method Gradient-based attack and optimization-based adversarial training.
result Optimization-based attack can significantly decrease GNN classification performance with minimal edge perturbations.
Study of adversarial attacks on neural networks for graph data.
problem Robustness of neural networks for graph data to adversarial attacks.
method Introduced first study of adversarial attacks on attributed graphs, focusing on graph convolutions. Developed efficient algorithm Nettack for generating unnoticeable perturbations.
result Significant drop in accuracy of node classification even with few perturbations, and attacks are transferable.
Graph neural networks are vulnerable to adversarial attacks that manipulate graph structure.
problem Vulnerability of graph neural networks to adversarial attacks.
method Meta-learning approach to solve bilevel optimization problem of training-time attacks.
result Small graph perturbations can significantly degrade graph neural network performance.
Graph neural networks are vulnerable to adversarial attacks by manipulating graph structure.
problem Vulnerability of Graph Neural Networks to adversarial attacks.
method Categorization and review of existing attacks and defenses.
result Developed a repository for empirical studies on graph adversarial attacks and defenses.
New black-box attack method improves GNN defense without needing training data.
problem Vulnerability of Graph Neural Networks to adversarial attacks.
method Developed a gradient-based black-box attack algorithm, BBGA, which does not require access to training data.
result BBGA achieves stable attack performance without accessing training sets, and is effective against various defenses.
Indirect attacks can fool graph classifiers even with poisoned neighbors.
problem How to evaluate and defend graph convolutional neural networks against indirect adversarial attacks.
method Proposed a method to generate adversarial perturbations on a single node far from the target.
result 99% attack success rate within two-hops from the target in two datasets.
Bayesian optimisation method targets graph classification models against adversarial attacks.
problem Adversarial attacks on graph classification models, especially for graph-level tasks.
method Bayesian optimisation-based attack method for graph classification models.
result Effectiveness and flexibility of the proposed method validated on various graph classification tasks.
DefenseVGAE defends graph neural networks against adversarial attacks.
problem Vulnerability of GNNs to adversarial structural perturbations.
method Variational Graph Autoencoder (VGAE) to reconstruct graph structure.
result DefenseVGAE reduces adversarial perturbations and boosts GCN performance.
FATE framework attacks graph learning models to amplify bias deceptively.
problem Achieving poisoning attacks on graph learning models to exacerbate bias deceptively.
method Bi-level optimization problem and meta learning-based framework named FATE.
result FATE amplifies bias of graph neural networks while maintaining downstream task utility.
Poisoning attacks improve graph-based recommender system recommendations.
problem Designing effective poisoning attacks for graph-based recommender systems.
method Formulated as an optimization problem, solved with techniques to assign rating scores to fake users.
result Outperforms existing attacks for graph-based recommender systems, recommending target items to 580 times more normal users.
UM-GNN improves GNN robustness against poisoning attacks.
problem Vulnerability of GNNs to poisoning attacks.
method UM-GNN uses epistemic uncertainties from message passing to build a surrogate predictor.
result UM-GNN achieves significantly improved robustness against poisoning attacks.
Paper tackles node injection attacks on graphs using reinforcement learning.
problem Tackles the problem of injecting adversarial nodes into real-world graph applications to reduce node classification performance.
method Uses reinforcement learning to sequentially modify the adversarial information of injected nodes.
result Demonstrates superior performance of the proposed method NIPA compared to existing methods.
Efficiently analyzes network vulnerabilities using approximate inference.
problem Scalability issue in exact Bayesian inference for large attack graphs.
method Loopy Belief Propagation applied to attack graphs for approximate inference.
result Approximate inference scales linearly with network size, making analysis viable for larger networks.
Novel method HAO mitigates Graph Injection Attack by preserving homophily.
problem Graph Injection Attack's high flexibility can harm graph homophily.
method Introduce homophily unnoticeability constraint and Harmonious Adversarial Objective (HAO).
result GIA with HAO breaks homophily-based defenses and outperforms previous attacks.
Graph embedding leaks sensitive graph properties and subgraphs.
problem Privacy risks in graph embedding sharing.
method Three inference attacks and a defense mechanism.
result High accuracy in inferring graph properties and subgraphs.
AdvImmune improves certifiable robustness of GNNs against adversarial attacks.
problem Vulnerability of graph neural networks to adversarial attacks.
method Proposes AdvImmune, an algorithm that optimizes with meta-gradient to improve certifiable robustness.
result Remarkably improves the ratio of robust nodes by 12%, 42%, 65% with an affordable immune budget of only 5% edges.
GNNGuard defends Graph Neural Networks against structural perturbations.
problem Adversarial attacks on graph neural networks can degrade performance catastrophically.
method Detects and quantifies the relationship between graph structure and node features, then uses this to mitigate attacks.
result GNNGuard outperforms existing defenses by 15.3% on average across various attacks and datasets.
This paper explores vulnerabilities in hierarchical graph pooling neural networks for graph classification.
problem Vulnerability of hierarchical graph pooling neural networks in graph classification tasks.
method Proposes an adversarial attack framework using a surrogate model to generate adversarial samples.
result Adversarial samples can fool hierarchical GNN-based graph classification models, demonstrating their vulnerability.
SAG is a scalable method for adversarial attacks on GNNs.
problem Scalability and robustness of GNNs to adversarial attacks.
method Decomposing large graphs into smaller partitions, using ADMM for optimization.
result SAG reduces computation and memory overhead for large graphs.
Paper proposes a novel graph recovery attack from node embeddings.
problem Privacy risks of integrating graph embeddings with machine learning pipelines.
method Model-agnostic graph recovery attack exploiting preserved structural information in node embeddings.
result Adversaries can recover graph edges with decent accuracy from node embeddings alone.
PA-GNN enhances GNN robustness against poisoning attacks using clean graph knowledge.
problem Improving robustness of GNNs against poisoning attacks.
method PA-GNN uses a penalized aggregation mechanism and meta-optimization to transfer robustness from clean graphs.
result PA-GNN significantly improves GNN robustness against poisoning attacks on real-world graphs.
Rewiring edges subtly improves graph neural networks' robustness.
problem Vulnerability of graph neural networks to subtle structural perturbations.
method Proposes a graph rewiring operation and uses reinforcement learning to learn attack strategies.
result Demonstrates the effectiveness of the proposed framework on real-world graphs.
APGE protects graph node representations from inference attacks.
problem Privacy leakage in graph embedding methods.
method Adversarial training framework with disentangling and purging mechanisms.
result APGE preserves structural and utility attributes while concealing private information.
Survey on adversarial attacks and defenses for images, graphs, and text.
problem Adversarial examples threaten the safety of deep learning applications.
method Review of adversarial attack and defense mechanisms for images, graphs, and text.
result Systematic overview of adversarial attacks and countermeasures.
Heterophily affects GNN robustness; separating ego- and neighbor-embeddings improves defense.
problem The robustness of GNNs to adversarial attacks.
method Formalized relation between heterophily and GNN robustness; empirical analysis; design principles for improved robustness.
result Separating ego- and neighbor-embeddings increases GNN robustness.
Adversarial attacks degrade node embeddings and downstream tasks.
problem Robustness of node embeddings to adversarial attacks.
method Graph poisoning to perturb network structure.
result Efficient adversarial perturbations degrade embeddings and tasks.
Enhances GCNs to resist graph attacks.
problem Vulnerability of GCNs to topological attacks.
method Introduces a new robust convolution operator and training paradigm.
result Improves adversarial robustness and performance.
Paper introduces a data poisoning attack on unsupervised node embedding methods.
problem Robustness of unsupervised node embedding methods against adversarial attacks.
method Data poisoning attack on DeepWalk and LINE methods.
result Data poisoning can significantly affect link prediction results by altering graph structures slightly.
DefNet defends GNNs against adversarial attacks by identifying and mitigating vulnerabilities.
problem Vulnerability of GNNs to adversarial attacks.
method Investigates latent vulnerabilities in GNN layers, proposes dual-stage aggregation and bottleneck perceptron, and uses adversarial contrastive learning for training.
result DefNet significantly improves GNN robustness under various adversarial attacks.
GTA is the first backdoor attack on GNNs, demonstrating vulnerabilities in graph-oriented security models.
problem Vulnerability of graph neural networks to backdoor attacks.
method Graph-oriented triggers, dynamic adaptation, model-agnostic, attack-extensible.
result Demonstrates severe threats to graph classification and node classification tasks.
Graph attacks can be successful with just a few bad nodes.
problem Adversarial attacks on graph neural networks.
method Identifying and exploiting anchor nodes to compromise graph models.
result A few bad nodes can significantly degrade graph model performance.
RoGAT enhances GAT robustness against adversarial attacks.
problem Vulnerability of GAT to adversarial attacks.
method Dynamic adjustment of edge weights and features, with an extra attention score.
result RoGAT outperforms other defensive methods in robustness tests.
Enhances GNN robustness against attacks.
problem Adversarial attacks on GNNs during training and testing.
method pLapGNN framework based on weighted p-Laplacian.
result Empirically validated robustness and efficiency.
Graph Information Bottleneck (GIB) optimizes graph representations for robustness against adversarial attacks.
problem Challenges in learning graph representations due to structure and feature information.
method GIB is an information-theoretic principle that balances expressiveness and robustness by maximizing mutual information between representation and target, while constraining mutual information with input data.
result GIB-based models are more robust to adversarial attacks, achieving up to 31% improvement.
PeerNets improve deep learning models' robustness to adversarial attacks.
problem Vulnerability of deep learning models to adversarial attacks.
method Alternating classical Euclidean convolutions with graph convolutions to condition latent features on the global structure of a graph of peer samples.
result 3 times more robust to adversarial attacks compared to conventional architectures with almost no drop in accuracy.
Paper shows how to hide individuals in graphs to fool community detection models.
problem Adversarial attack on community detection models by hiding individuals.
method Iterative learning framework that updates a graph generator and a community detection model.
result Adversarial graphs generated by the method can fool multiple community detection models.
UAG defends GNNs against adversarial attacks by quantifying and explaining uncertainties.
problem Lack of uncertainty quantification in GNNs makes them vulnerable to adversarial attacks.
method UAG uses Bayesian Uncertainty Technique (BUT) and Uncertainty-aware Attention Technique (UAT).
result UAG outperforms state-of-the-art solutions in defending adversarial attacks on GNNs.
This work generates diverse adversarial attacks for different domains using latent variable perturbation.
problem Adversarial attacks on deep neural networks are limited to a single perturbation.
method Frame adversarial attacks as learning a distribution of perturbations, enabling generation of diverse attacks.
result Framework generates competitive or superior adversarial attacks across diverse domains (images, text, graphs).
New method attacks GNNs with limited node access, increasing misclassification rate.
problem Attacking GNNs with limited node access and limited attack nodes.
method Generalized gradient-based attacks using importance scores derived from random walks.
result Proposed greedy procedure significantly increases misclassification rate.
Survey of graph adversarial learning tasks and their attacks and defenses.
problem Uncertainty and unreliability of deep learning models on graphs against adversarial examples.
method Unified problem definition and comprehensive review of existing works.
result Unified definitions and taxonomies for graph adversarial learning tasks.