Towards More Practical Adversarial Attacks on Graph Neural Networks
–Neural Information Processing Systems
We demonstrate that the structural inductive biases of GNN models can be an effective source for this type of attacks. Specifically, by exploiting the connection between the backward propagation of GNNs and random walks, we show that the common gradient-based white-box attacks can be generalized to the black-box setting via the connection between the gradient and an importance score similar to PageRank.
Neural Information Processing Systems
Oct-2-2025, 15:08:50 GMT
- Country:
- Europe > United Kingdom
- England > Oxfordshire > Oxford (0.04)
- North America
- Canada (0.04)
- United States > Michigan
- Washtenaw County > Ann Arbor (0.14)
- Europe > United Kingdom
- Genre:
- Research Report (0.68)
- Industry:
- Government > Military (0.68)
- Information Technology > Security & Privacy (1.00)
- Technology: