arXiv:2602.01113cs.LG2026-02

攻击者仅用一条边注入伪造节点,就能大幅干扰工业图神经网络的异常检测。

Single-Edge Node Injection Threats to GNN-Based Security Monitoring in Industrial Graph Systems

  • 通过单边连接注入伪造节点,绕过拓扑与同质性检测机制。
  • 攻击成功率比基线高至少25%,且所需边数更少。
  • 适用于工业物联网、电网等图神经网络安全监测系统评估与防御。

图神经网络(GNN)在工业图监控系统(如工业互联网设备图、电网拓扑模型、制造通信网络)中广泛用于异常检测、状态估计和资产分类。当少数边缘设备被攻陷时,攻击者可注入伪造节点(如非法传感器、虚拟终端或伪装变电站),在不破坏图结构同质性的情况下误导下游决策。本文提出受限资源下的单边图注入攻击(SEGIA),每个注入节点仅通过一条边连接到主图。SEGIA结合剪枝后的SGC代理、多跳邻域采样、基于反向图卷积的特征合成及相似性正则化目标,以保持局部同质性并抵御边剪枝。理论分析与多数据集、多防御机制下的实验表明,其攻击成功率较主流基线高出至少25%,且边预算显著更低。结果揭示了工业级GNN部署中的系统性风险,呼吁引入轻量级准入验证与邻域一致性监控。

原文摘要 · Abstract (English)

Graph neural networks (GNNs) are increasingly adopted in industrial graph-based monitoring systems (e.g., Industrial internet of things (IIoT) device graphs, power-grid topology models, and manufacturing communication networks) to support anomaly detection, state estimation, and asset classification. In such settings, an adversary that compromises a small number of edge devices may inject counterfeit nodes (e.g., rogue sensors, virtualized endpoints, or spoofed substations) to bias downstream decisions while evading topology- and homophily-based sanitization. This paper formulates deployment-oriented node-injection attacks under constrained resources and proposes the \emph{Single-Edge Graph Injection Attack} (SEGIA), in which each injected node attaches to the operational graph through a single edge. SEGIA integrates a pruned SGC surrogate, multi-hop neighborhood sampling, and reverse graph convolution-based feature synthesis with a similarity-regularized objective to preserve local homophily and survive edge pruning. Theoretical analysis and extensive evaluations across datasets and defenses show at least $25\%$ higher attack success than representative baselines under substantially smaller edge budgets. These results indicate a system-level risk in industrial GNN deployments and motivate lightweight admission validation and neighborhood-consistency monitoring.

图神经网络安全威胁工业物联网对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。