跳到主要导航 跳到搜索 跳到主要内容

Can LLMs Fool Graph Learning? Exploring Universal Adversarial Attacks on Text-Attributed Graphs

  • Zihui Chen
  • , Yuling Wang*
  • , Pengfei Jiao
  • , Kai Wu
  • , Xiao Wang
  • , Xiang Ao
  • , Dalin Zhang
  • *此作品的通讯作者
  • Hangzhou Dianzi University
  • CAS - Institute of Computing Technology

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Text-attributed graphs (TAGs) enhance graph learning by integrating rich textual semantics and topological context for each node. While boosting expressiveness, they also expose new vulnerabilities in graph learning through text-based adversarial surfaces. Recent advances leverage diverse backbones, such as graph neural networks (GNNs) and pre-trained language models (PLMs), to capture both structural and textual information in TAGs. This diversity raises a key question: How can we design universal adversarial attacks that generalize across architectures to assess the security of TAG models? The challenge arises from the stark contrast in how different backbones - GNNs and PLMs - perceive and encode graph patterns, coupled with the fact that many PLMs are only accessible via APIs, limiting attacks to black-box settings. To address this, we propose BadGraph, a novel attack framework that deeply elicits large language models' (LLMs) understanding of general graph knowledge to jointly perturb both node topology and textual semantics. Specifically, we design a target influencer retrieval module that leverages graph priors to construct cross-modally aligned attack shortcuts, thereby enabling efficient LLM-based perturbation reasoning. Experiments show that BadGraph achieves universal and effective attacks across GNN- and LLM-based reasoners, with up to a 76.3% performance drop, while theoretical and empirical analyses confirm its stealthy yet interpretable nature.

源语言英语
主期刊名WWW 2026 - Proceedings of the ACM Web Conference 2026
出版商Association for Computing Machinery, Inc
1217-1228
页数12
ISBN(电子版)9798400723070
DOI
出版状态已出版 - 12 4月 2026
活动35th ACM Web Conference, WWW 2026 - Dubai, 阿拉伯联合酋长国
期限: 29 6月 20263 7月 2026

出版系列

姓名WWW 2026 - Proceedings of the ACM Web Conference 2026

会议

会议35th ACM Web Conference, WWW 2026
国家/地区阿拉伯联合酋长国
Dubai
时期29/06/263/07/26

指纹

探究 'Can LLMs Fool Graph Learning? Exploring Universal Adversarial Attacks on Text-Attributed Graphs' 的科研主题。它们共同构成独一无二的指纹。

引用此