Node Injection Attack Based on Label Propagation Against Graph Neural Network
arXiv:2405.18824 · doi:10.1109/TCSS.2024.3395794
Abstract
Graph Neural Network (GNN) has achieved remarkable success in various graph learning tasks, such as node classification, link prediction and graph classification. The key to the success of GNN lies in its effective structure information representation through neighboring aggregation. However, the attacker can easily perturb the aggregation process through injecting fake nodes, which reveals that GNN is vulnerable to the graph injection attack. Existing graph injection attack methods primarily focus on damaging the classical feature aggregation process while overlooking the neighborhood aggregation process via label propagation. To bridge this gap, we propose the label-propagation-based global injection attack (LPGIA) which conducts the graph injection attack on the node classification task. Specifically, we analyze the aggregation process from the perspective of label propagation and transform the graph injection attack problem into a global injection label specificity attack problem. To solve this problem, LPGIA utilizes a label propagation-based strategy to optimize the combinations of the nodes connected to the injected node. Then, LPGIA leverages the feature mapping to generate malicious features for injected nodes. In extensive experiments against representative GNNs, LPGIA outperforms the previous best-performing injection attack method in various datasets, demonstrating its superiority and transferability.
Accepted by TCSS;DOI:10.1109/TCSS.2024.3395794
References in corpus (13)
- Near linear time algorithm to detect community structures in large-scale networks
- Simplifying Graph Convolutional Networks
- GNNGuard: Defending Graph Neural Networks against Adversarial Attacks
- Geom-GCN: Geometric Graph Convolutional Networks
- Combining Label Propagation and Simple Models Out-performs Graph Neural Networks
- LESSON: Multi-Label Adversarial False Data Injection Attack for Deep Learning Locational Detection
- TDGIA:Effective Injection Attacks on Graph Neural Networks
- Single Node Injection Attack against Graph Neural Networks
- GIN-SD: Source Detection in Graphs with Incomplete Nodes via Positional Encoding and Attentive Fusion
- Understanding and Improving Graph Injection Attack by Promoting Unnoticeability
- Cluster Attack: Query-based Adversarial Attacks on Graphs with Graph-Dependent Priors
- GraphAttacker: A General Multi-Task GraphAttack Framework
- Single Node Injection Label Specificity Attack on Graph Neural Networks via Reinforcement Learning