TY - JOUR
T1 - Unsupervised graph poisoning via augmentation-free cluster contrast
AU - Peng, Xingyu
AU - Xu, Ke
N1 - Publisher Copyright:
© 2026 Elsevier B.V.
PY - 2026/8/3
Y1 - 2026/8/3
N2 - Unsupervised graph poisoning attacks have garnered increasing attention due to their practicality in label-scarce scenarios. A dominant paradigm involves gradient-based strategies that attack graph contrastive learning objectives to disrupt representation learning. However, the reliance on data augmentation poses a fundamental challenge: the stochastic and non-differentiable nature of augmentations induces biased and high-variance gradients, resulting in suboptimal perturbations. To overcome this limitation, we propose a novel augmentation-free cluster-contrastive attack that operates directly on the original graph. By leveraging clustering-derived pseudo-labels and jointly maximizing intra-cluster inconsistency and node-prototype misalignment, our method yields faithful and potent gradient signals. Furthermore, we introduce a disjoint multi-edge perturbation strategy to update multiple structurally independent edges in parallel. This approach mitigates gradient interference and ensures uniform disruption, significantly enhancing both efficiency and effectiveness. Extensive experiments demonstrate that our method consistently outperforms existing unsupervised attack baselines across diverse graph settings, while exhibiting strong scalability and transferability.
AB - Unsupervised graph poisoning attacks have garnered increasing attention due to their practicality in label-scarce scenarios. A dominant paradigm involves gradient-based strategies that attack graph contrastive learning objectives to disrupt representation learning. However, the reliance on data augmentation poses a fundamental challenge: the stochastic and non-differentiable nature of augmentations induces biased and high-variance gradients, resulting in suboptimal perturbations. To overcome this limitation, we propose a novel augmentation-free cluster-contrastive attack that operates directly on the original graph. By leveraging clustering-derived pseudo-labels and jointly maximizing intra-cluster inconsistency and node-prototype misalignment, our method yields faithful and potent gradient signals. Furthermore, we introduce a disjoint multi-edge perturbation strategy to update multiple structurally independent edges in parallel. This approach mitigates gradient interference and ensures uniform disruption, significantly enhancing both efficiency and effectiveness. Extensive experiments demonstrate that our method consistently outperforms existing unsupervised attack baselines across diverse graph settings, while exhibiting strong scalability and transferability.
KW - Graph contrastive learning
KW - Graph neural networks
KW - Graph poisoning attack
UR - https://www.scopus.com/pages/publications/105041016376
U2 - 10.1016/j.knosys.2026.116364
DO - 10.1016/j.knosys.2026.116364
M3 - 文章
AN - SCOPUS:105041016376
SN - 0950-7051
VL - 348
JO - Knowledge-Based Systems
JF - Knowledge-Based Systems
M1 - 116364
ER -