arXiv:2511.12423cs.CRcs.LG2025-11AAAI被引 1

提出首个针对大模型增强图神经网络的黑盒多模态节点注入攻击。

GRAPHTEXTACK: A Realistic Black-Box Node Injection Attack on LLM-Enhanced GNNs

  • 设计进化优化框架,联合优化节点结构与语义特征。
  • 在5个数据集上使模型性能下降超40%,显著优于12个基线。
  • 无需模型内部信息,适用于真实场景下的隐蔽攻击。

文本属性图(TAGs)在多个领域广泛应用,近期研究将大语言模型(LLMs)与图神经网络(GNNs)结合,同时建模语义与结构,实现更优性能。然而该融合引入双重脆弱性:GNN对结构扰动敏感,而LLM生成特征易受提示注入和对抗性措辞影响。现有攻击多独立扰动结构或文本,效果有限;且常假设白盒访问或直接修改图数据,不切实际。为此,我们提出GRAPHTEXTACK,首个黑盒、多模态、污染型节点注入攻击,可无须依赖模型内部信息或替代模型,在真实威胁下注入精心设计的节点,以破坏模型表现。为应对连接与特征分配的组合式、非可微搜索空间,提出新颖的多目标进化优化框架,平衡局部预测干扰与全局图影响。在五个数据集和两个先进模型上的实验表明,GRAPHTEXTACK显著超越12个强基线。

原文摘要 · Abstract (English)

Text-attributed graphs (TAGs), which combine structural and textual node information, are ubiquitous across many domains. Recent work integrates Large Language Models (LLMs) with Graph Neural Networks (GNNs) to jointly model semantics and structure, resulting in more general and expressive models that achieve state-of-the-art performance on TAG benchmarks. However, this integration introduces dual vulnerabilities: GNNs are sensitive to structural perturbations, while LLM-derived features are vulnerable to prompt injection and adversarial phrasing. While existing adversarial attacks largely perturb structure or text independently, we find that uni-modal attacks cause only modest degradation in LLM-enhanced GNNs. Moreover, many existing attacks assume unrealistic capabilities, such as white-box access or direct modification of graph data. To address these gaps, we propose GRAPHTEXTACK, the first black-box, multi-modal{, poisoning} node injection attack for LLM-enhanced GNNs. GRAPHTEXTACK injects nodes with carefully crafted structure and semantics to degrade model performance, operating under a realistic threat model without relying on model internals or surrogate models. To navigate the combinatorial, non-differentiable search space of connectivity and feature assignments, GRAPHTEXTACK introduces a novel evolutionary optimization framework with a multi-objective fitness function that balances local prediction disruption and global graph influence. Extensive experiments on five datasets and two state-of-the-art LLM-enhanced GNN models show that GRAPHTEXTACK significantly outperforms 12 strong baselines.

图神经网络大模型安全对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。