TY - JOUR
T1 - SOPA
T2 - Sensitivity-Oriented Poisoning Attack for Self-Supervised Graph Embedding Model via Bilevel Evolutionary Optimization
AU - You, Shen
AU - Zhou, Kai
AU - Li, Zhongshen
AU - Tan, Kay Chen
AU - Lin, Qiuzhen
AU - Li, Xiangtao
AU - Wong, Ka-Chun
PY - 2026/6
Y1 - 2026/6
N2 - Despite the popularity of graph neural networks (GNNs), perturbed graph data is still a serious threat toward its inherent vulnerabilities. Adversarial examples can easily manipulate the output of GNNs across various attack scenarios. Meanwhile, studying attacks on graph networks is crucial, as it can help model designers enhance the robustness of their models. In this study, we propose a sensitivity-oriented poisoning attack for self-supervised graph embedding model through bilevel optimization, which employs different optimization methods at each level. To further enhance attack effectiveness, we analyze graph structure to identify sensitive nodes and edges that guide attack directions, combining gradient-based and query-based methods to target both edge connections and node attributes. Besides, according to the defects of existing graph masked autoencoders models, we design the feature sensitivity and feature variance to reduce the feature differentiability, which impairs the performance of the downstream model. Ablation studies validate the effectiveness of our operator on three citation datasets. And benchmark-based experiments support the effectiveness of our method on three different graph tasks. Specifically, our approach achieve an average reduction of 3% in the accuracy of node classification compared to existing methods for attacking graph structures alone. When attacking both graph structures and attributes, our model has even achieved an average reduction of 4.5% for the node classification task, outperforming the existing methods.
© 2025 IEEE. All rights reserved, including rights for text and data mining, and training of artificial intelligence and similar technologies.
AB - Despite the popularity of graph neural networks (GNNs), perturbed graph data is still a serious threat toward its inherent vulnerabilities. Adversarial examples can easily manipulate the output of GNNs across various attack scenarios. Meanwhile, studying attacks on graph networks is crucial, as it can help model designers enhance the robustness of their models. In this study, we propose a sensitivity-oriented poisoning attack for self-supervised graph embedding model through bilevel optimization, which employs different optimization methods at each level. To further enhance attack effectiveness, we analyze graph structure to identify sensitive nodes and edges that guide attack directions, combining gradient-based and query-based methods to target both edge connections and node attributes. Besides, according to the defects of existing graph masked autoencoders models, we design the feature sensitivity and feature variance to reduce the feature differentiability, which impairs the performance of the downstream model. Ablation studies validate the effectiveness of our operator on three citation datasets. And benchmark-based experiments support the effectiveness of our method on three different graph tasks. Specifically, our approach achieve an average reduction of 3% in the accuracy of node classification compared to existing methods for attacking graph structures alone. When attacking both graph structures and attributes, our model has even achieved an average reduction of 4.5% for the node classification task, outperforming the existing methods.
© 2025 IEEE. All rights reserved, including rights for text and data mining, and training of artificial intelligence and similar technologies.
UR - https://www.scopus.com/pages/publications/105010264184
UR - https://www.scopus.com/record/pubmetrics.uri?eid=2-s2.0-105010264184&origin=recordpage
U2 - 10.1109/TEVC.2025.3586128
DO - 10.1109/TEVC.2025.3586128
M3 - RGC 21 - Publication in refereed journal
SN - 1089-778X
VL - 30
SP - 1108
EP - 1122
JO - IEEE Transactions on Evolutionary Computation
JF - IEEE Transactions on Evolutionary Computation
IS - 3
ER -