A novel Target-aware Interaction-guided Reinforcement learning for Black-box node injection Attacks on GNNs (TIRBA), which formulates the attack as a Markov Decision Process and jointly optimizes node feature generation and edge construction in a heterogeneous action space.
Abstract
Graph Neural Networks (GNNs) have achieved remarkable performance in graph representation learning, yet their inherent vulnerability to adversarial attacks poses severe security risks. Especially, black-box node injection attacks have become a major threat to GNNs since they inject malicious nodes without altering the original graph topology. However, they typically decouple the generation of malicious node features and edge connections, thereby resulting in suboptimal attack efficacy under stringent budgets. To address this critical issue, this study proposes a novel Target-aware Interaction-guided Reinforcement learning for Black-box node injection Attacks on GNNs (TIRBA), which formulates the attack as a Markov Decision Process and jointly optimizes node feature generation and edge construction in a heterogeneous action space. Firstly, TIRBA designs a target-aware interaction encoder to fuse information of node features and edges. Further, it introduces a class-center guidance mechanism to utilize prior class distribution information, thereby guiding efficient exploration of the high-dimensional feature space. Finally, a topology difference-aware state value evaluation is adopted to explicitly capture local structural anomalies caused by injected nodes, thereby stabilizing the reinforcement learning training process. Experimental results demonstrate that the proposed TIRBA significantly outperforms state-of-the-art black-box node injection attack methods.
This research introduces a new graph adversarial attack protection approach termed evolutionary algorithm integration of neighbor importance estimate to tackle this issue and attains notably superior performance in comparison to alternative defense methodologies.
Hong Pan, Jingwei Guo, Liang Cheng et al.· International Journal of Mac...· 0 citations
The evolution of 6G networks from bit-oriented transmission to semantic communication renders communication systems vulnerable to emerging security threats targeting information interpretation, specifically semantic distortion. Consequently, identifying critical attack paths is essential for understanding and mitigating semantic attack propagation at the network level. Reinforcement learning (RL) has been increasingly adopted to identify critical paths in complex networks, yet existing solutions typically rely on agents tailored to specific environments characterized by discrete nodes and fixed semantic attributes. These discrete formulations constrain scalability in large-scale networks and hinder generalization across dynamic topologies. To alleviate these limitations, we propose Sem-DRL (Semantic-aware Deep Reinforcement Learning), a continuous RL framework featuring invariant observation and action spaces. Sem-DRL leverages Graph Neural Networks (GNNs) to extract permutation-invariant embeddings, which enables zero-shot generalization across unseen network topologies. By decoupling the action space from the network size, the proposed framework ensures scalability in large-scale networks. Furthermore, Sem-DRL utilizes PLMs as semantic judges to quantify distortion rewards within a continuous latent space. Extensive experiments demonstrate that the proposed framework achieves stable convergence in networks with up to 500 nodes and attains zero-shot transfer success rates of 76%–90% across previously unseen network topologies.
Pengyu Chen, Yuehan Dong, Yalun Wu et al.· IEEE Transactions on Cogniti...· 0 citations
An active paradigm that repurposes the offensive tactic of node injection into a structural defense, ANIE significantly enhances GNN robustness, outperforming state-of-the-art defenses by up to 2× in classification accuracy under poisoning and evasion attacks.
Xiangchao Wen, Zhen Liu, Yunfei Liu· Proceedings of the 32nd ACM...· 0 citations
A novel transferable graph prompt attack, called TGPA, is proposed, which shifts the attack paradigm by introducing a hierarchical structural decoupling mechanism, which reduces the performance of pre-trained graph models with graph prompts by up to 28.9%, while guaranteeing robustness, stealthiness, and transferability.
Ju Jia, Haonan Wang, Tian Wu et al.· Neural Networks· 0 citations