JOURNAL ARTICLE

Black-Box Adversarial Attack on Graph Neural Networks With Node Voting Mechanism

Liangliang WenJiye LiangKaixuan YaoZhiqiang Wang

Year: 2024 Journal:   IEEE Transactions on Knowledge and Data Engineering Vol: 36 (10)Pages: 5025-5038   Publisher: IEEE Computer Society

Abstract

Graph Neural Networks (GNNs) have attracted significant research interest in various graph data modeling tasks. To advance trustworthy, reliable, and safe Artificial Intelligence (AI) systems for practical applications, adversarial robustness learning on GNNs has drawn widespread attention among researchers. Numerous attack methods, including white-box attacks, gray-box attacks, and black-box attacks, have been proposed, but black-box attacks are widely considered to be the most challenging and practical in real-world applications. In this paper, we focus on the challenging and realistic black-box attack scenario on GNNs, where the attacker has no information about the structure and parameters of the target model. We first theoretically demonstrate that the loss changes of the GNNs are related to the node voting matrix, which is subject to the graph topology information and is independent to the structures of GNNs. Then, we propose a novel black-box attack strategy for GNNs based on the theoretical results, i.e., node voting influence-based GNNs black-box adversarial attack, named VoteAttack. Specifically, the VoteAttack algorithm iteratively chooses a group of significant nodes based on mutual voting among nodes (the node voting matrix) and considers the voting weights among nodes. Furthermore, the VoteAttack algorithm modifies the attributes of the selected nodes to create a perturbed graph and ultimately utilizes the perturbed graph to attack GNNs. Experimental results on popular GNNs and graph datasets indicate that the proposed attack strategy outperforms baseline strategies.

Keywords:
Adversarial system Computer science Node (physics) Mechanism (biology) Voting Graph Computer security Computer network Artificial intelligence Theoretical computer science Engineering Political science Law

Metrics

7
Cited By
4.47
FWCI (Field Weighted Citation Impact)
48
Refs
0.91
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Adversarial Robustness in Machine Learning
Physical Sciences →  Computer Science →  Artificial Intelligence
Advanced Graph Neural Networks
Physical Sciences →  Computer Science →  Artificial Intelligence
Machine Learning and ELM
Physical Sciences →  Computer Science →  Artificial Intelligence

Related Documents

JOURNAL ARTICLE

Black-box Adversarial Attack and Defense on Graph Neural Networks

Haoyang LiShimin DiZijian LiLei ChenJiannong Cao

Journal:   2022 IEEE 38th International Conference on Data Engineering (ICDE) Year: 2022 Pages: 1017-1030
JOURNAL ARTICLE

Cyclical Adversarial Attack Pierces Black-box Deep Neural Networks

Lifeng HuangShuxin WeiChengying GaoNing Liu

Journal:   Pattern Recognition Year: 2022 Vol: 131 Pages: 108831-108831
JOURNAL ARTICLE

Query efficient black-box adversarial attack on deep neural networks

Yang BaiYisen WangYuyuan ZengYong JiangShu‐Tao Xia

Journal:   Pattern Recognition Year: 2022 Vol: 133 Pages: 109037-109037
© 2026 ScienceGate Book Chapters — All rights reserved.