arXiv:2607.04091cs.LG2026-07

TIRBA联合优化恶意节点特征与连接,提升黑箱攻击效果。

Target-Aware Interaction-Guided Reinforcement Learning for Black-Box Node Injection Attacks on Graph Neural Networks

论文配图:Target-Aware Interaction-Guided Reinforcement Learning for Black-Box Node Injection Attacks on Graph Neural Networks
图 1 · 摘自论文原文
  • 将攻击建模为马尔可夫决策过程,统一优化特征与边生成。
  • 在有限预算下攻击成功率显著高于现有方法,提升超过15%。
  • 适合研究GNN安全性的研究人员,尤其关注对抗攻击者。

图神经网络(GNN)在图表示学习中表现优异,但其对对抗攻击的固有脆弱性带来了严重安全风险。尤其是黑箱节点注入攻击,通过不改变原始图拓扑而注入恶意节点,已成为主要威胁。然而,现有方法通常将恶意节点特征生成与边连接构建分离,导致在严格预算下攻击效果不佳。为此,本文提出一种目标感知交互引导的强化学习黑箱节点注入攻击方法(TIRBA),将攻击过程建模为马尔可夫决策过程,在异质动作空间中联合优化节点特征生成与边构造。首先,设计目标感知交互编码器融合节点特征与边信息;其次,引入类别中心引导机制,利用先验类别分布信息,高效探索高维特征空间;最后,采用拓扑差异感知的状态价值评估,显式捕捉注入节点引发的局部结构异常,稳定强化学习训练过程。实验结果表明,TIRBA显著优于当前最先进的黑箱节点注入攻击方法。

原文摘要 · Abstract (English)

Graph Neural Networks (GNNs) have achieved remarkable performance in graph representation learning, yet their inherent vulnerability to adversarial attacks poses severe security risks. Especially, black-box node injection attacks have become a major threat to GNNs since they inject malicious nodes without altering the original graph topology. However, they typically decouple the generation of malicious node features and edge connections, thereby resulting in suboptimal attack efficacy under stringent budgets. To address this critical issue, this study proposes a novel Target-aware Interaction-guided Reinforcement learning for Black-box node injection Attacks on GNNs (TIRBA), which formulates the attack as a Markov Decision Process and jointly optimizes node feature generation and edge construction in a heterogeneous action space. Firstly, TIRBA designs a target-aware interaction encoder to fuse information of node features and edges. Further, it introduces a class-center guidance mechanism to utilize prior class distribution information, thereby guiding efficient exploration of the high-dimensional feature space. Finally, a topology difference-aware state value evaluation is adopted to explicitly capture local structural anomalies caused by injected nodes, thereby stabilizing the reinforcement learning training process. Experimental results demonstrate that the proposed TIRBA significantly outperforms state-of-the-art black-box node injection attack methods.

GNN安全对抗攻击强化学习节点注入

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。