arXiv:2602.00318cs.LGcs.AI2026-02中稿 · Proceedings of the…被引 3

用最优传输方法生成真实场景下的图神经网络对抗攻击,提升检测绕过率。

Optimal Transport-Guided Adversarial Attacks on Graph Neural Network-Based Bot Detection

  • 基于最优传输构建时空邻居特征分布,生成可解释的稀疏边修改
  • 在真实约束下攻击成功率提升80.13%,显存占用减少99.80%
  • 适用于评估社交机器人检测系统鲁棒性,尤其适合安全与反欺诈研究者

社交媒体中的机器人账号对公共讨论构成重大威胁。当前越来越多的机器人检测依赖图神经网络(GNN),但其在真实环境下的有效性仍不明确。现实中攻击者需应对领域和时间约束,现有攻击方法难以适用。为此,本文提出BOCLOAK,通过边编辑与节点注入攻击,在真实约束下系统评估GNN-based社交机器人检测的鲁棒性。BOCLOAK在时空邻居特征上构建概率测度,学习区分人类与机器人行为的最优传输几何,并将传输方案解码为稀疏、可信的边修改,规避检测同时满足现实限制。在三个社交机器人数据集、五种先进检测模型、三种防御机制上评估,对比四种主流基线,BOCLOAK实现最高80.13%的攻击成功率提升,且GPU内存消耗降低99.80%。结果表明,最优传输为对抗攻击与真实检测之间提供了轻量、合理的方法框架。

原文摘要 · Abstract (English)

The rise of bot accounts on social media poses significant risks to public discourse. To address this threat, modern bot detectors increasingly rely on Graph Neural Networks (GNNs). However, the effectiveness of these GNN-based detectors in real-world settings remains poorly understood. In practice, attackers continuously adapt their strategies as well as must operate under domain-specific and temporal constraints, which can fundamentally limit the applicability of existing attack methods. As a result, there is a critical need for robust GNN-based bot detection methods under realistic, constraint-aware attack scenarios. To address this gap, we introduce BOCLOAK to systematically evaluate the robustness of GNN-based social bot detection via both edge editing and node injection adversarial attacks under realistic constraints. BOCLOAK constructs a probability measure over spatio-temporal neighbor features and learns an optimal transport geometry that separates human and bot behaviors. It then decodes transport plans into sparse, plausible edge edits that evade detection while obeying real-world constraints. We evaluate BOCLOAK across three social bot datasets, five state-of-the-art bot detectors, three adversarial defenses, and compare it against four leading graph adversarial attack baselines. BOCLOAK achieves up to 80.13% higher attack success rates while using 99.80% less GPU memory under realistic real-world constraints. Most importantly, BOCLOAK shows that optimal transport provides a lightweight, principled framework for bridging the gap between adversarial attacks and real-world bot detection.

图神经网络对抗攻击机器人检测最优传输

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。