Paper accepted at PAKDD 2025 with Best Paper Award: “LiSA”
Existing attacks on graph neural networks (GNNs) either manipulate the original graph directly or attach edges to artificially created nodes, which is often impractical in real-world services. This work introduces a more realistic adversarial scenario in which the attacker only injects an isolated subgraph.
The proposed framework, LiSA, deceives both the link recommender and the node classifier at the same time. The link recommender is misled into proposing links between targeted victim nodes and the injected subgraph, so that users themselves establish those connections, which in turn degrades node classification accuracy. A dual surrogate model and bi-level optimization let LiSA satisfy both adversarial objectives simultaneously. The paper received the Best Paper Award at PAKDD 2025.
[Paper]
Wenlun Zhang, Enyan Dai, Kentaro Yoshioka, “LiSA: Leveraging Link Recommender to Attack Graph Neural Networks via Subgraph Injection,” Proceedings of the 29th Pacific-Asia Conference on Knowledge Discovery and Data Mining (PAKDD 2025), 2025. (Best Paper Award)