Pith. sign in

REVIEW 2 cited by

HGAttack: Transferable Heterogeneous Graph Adversarial Attack

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2401.09945 v1 pith:FPYOOHYV submitted 2024-01-18 cs.LG cs.CRcs.IR

classification cs.LGcs.CRcs.IR
keywords adversarialheterogeneoushgattackhgnnsattackattackshgnnmethods
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Heterogeneous Graph Neural Networks (HGNNs) are increasingly recognized for their performance in areas like the web and e-commerce, where resilience against adversarial attacks is crucial. However, existing adversarial attack methods, which are primarily designed for homogeneous graphs, fall short when applied to HGNNs due to their limited ability to address the structural and semantic complexity of HGNNs. This paper introduces HGAttack, the first dedicated gray box evasion attack method for heterogeneous graphs. We design a novel surrogate model to closely resemble the behaviors of the target HGNN and utilize gradient-based methods for perturbation generation. Specifically, the proposed surrogate model effectively leverages heterogeneous information by extracting meta-path induced subgraphs and applying GNNs to learn node embeddings with distinct semantics from each subgraph. This approach improves the transferability of generated attacks on the target HGNN and significantly reduces memory costs. For perturbation generation, we introduce a semantics-aware mechanism that leverages subgraph gradient information to autonomously identify vulnerable edges across a wide range of relations within a constrained perturbation budget. We validate HGAttack's efficacy with comprehensive experiments on three datasets, providing empirical analyses of its generated perturbations. Outperforming baseline methods, HGAttack demonstrated significant efficacy in diminishing the performance of target HGNN models, affirming the effectiveness of our approach in evaluating the robustness of HGNNs against adversarial attacks.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. HeteroBA: A Structure-Manipulating Backdoor Attack on Heterogeneous Graphs

    cs.LG 2025-05 conditional novelty 6.0 of 10

    HeteroBA achieves high attack success rates by inserting trigger nodes with sampled features and strategically chosen connections into heterogeneous graphs, with minimal impact on clean accuracy.

  2. HeTa: Relation-wise Heterogeneous Graph Foundation Attack Model

    cs.AI 2025-06 conditional novelty 5.0 of 10

    HeTa learns relational importance weights on a surrogate HGNN, then attacks relations one by one with injected nodes and gradient-selected edges to transfer across target HGNNs.

Pith tools