Adversarial Attack on Graph Neural Networks as An Influence Maximization Problem