{"id":"https://openalex.org/W3038342492","doi":"https://doi.org/10.1145/3394520","title":"Adversarial Attacks on Graph Neural Networks","display_name":"Adversarial Attacks on Graph Neural Networks","publication_year":2020,"publication_date":"2020-06-21","ids":{"openalex":"https://openalex.org/W3038342492","doi":"https://doi.org/10.1145/3394520","mag":"3038342492"},"language":"en","primary_location":{"id":"doi:10.1145/3394520","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3394520","pdf_url":null,"source":{"id":"https://openalex.org/S41523882","display_name":"ACM Transactions on Knowledge Discovery from Data","issn_l":"1556-4681","issn":["1556-4681","1556-472X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Knowledge Discovery from Data","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5025058751","display_name":"Daniel Z\u00fcgner","orcid":"https://orcid.org/0000-0003-1626-5065"},"institutions":[{"id":"https://openalex.org/I62916508","display_name":"Technical University of Munich","ror":"https://ror.org/02kkvpp62","country_code":"DE","type":"education","lineage":["https://openalex.org/I62916508"]}],"countries":["DE"],"is_corresponding":true,"raw_author_name":"Daniel Z\u00fcgner","raw_affiliation_strings":["Technical University of Munich, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Technical University of Munich, Germany","institution_ids":["https://openalex.org/I62916508"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5003441467","display_name":"Oliver Borchert","orcid":"https://orcid.org/0009-0006-1880-0542"},"institutions":[{"id":"https://openalex.org/I62916508","display_name":"Technical University of Munich","ror":"https://ror.org/02kkvpp62","country_code":"DE","type":"education","lineage":["https://openalex.org/I62916508"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Oliver Borchert","raw_affiliation_strings":["Technical University of Munich, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Technical University of Munich, Germany","institution_ids":["https://openalex.org/I62916508"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014557575","display_name":"Amir Akbarnejad","orcid":"https://orcid.org/0000-0002-4873-3487"},"institutions":[{"id":"https://openalex.org/I62916508","display_name":"Technical University of Munich","ror":"https://ror.org/02kkvpp62","country_code":"DE","type":"education","lineage":["https://openalex.org/I62916508"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Amir Akbarnejad","raw_affiliation_strings":["Technical University of Munich, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Technical University of Munich, Germany","institution_ids":["https://openalex.org/I62916508"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5074504351","display_name":"Stephan G\u00fcnnemann","orcid":null},"institutions":[{"id":"https://openalex.org/I62916508","display_name":"Technical University of Munich","ror":"https://ror.org/02kkvpp62","country_code":"DE","type":"education","lineage":["https://openalex.org/I62916508"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Stephan G\u00fcnnemann","raw_affiliation_strings":["Technical University of Munich, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Technical University of Munich, Germany","institution_ids":["https://openalex.org/I62916508"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5025058751"],"corresponding_institution_ids":["https://openalex.org/I62916508"],"apc_list":null,"apc_paid":null,"fwci":5.9837,"has_fulltext":false,"cited_by_count":99,"citation_normalized_percentile":{"value":0.96943921,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":"14","issue":"5","first_page":"1","last_page":"31"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9950000047683716,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10064","display_name":"Complex Network Analysis Techniques","score":0.9251999855041504,"subfield":{"id":"https://openalex.org/subfields/3109","display_name":"Statistical and Nonlinear Physics"},"field":{"id":"https://openalex.org/fields/31","display_name":"Physics and Astronomy"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.905154824256897},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7668657898902893},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5549342632293701},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5360429883003235},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.5102002620697021},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.46387967467308044},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.42303037643432617},{"id":"https://openalex.org/keywords/node","display_name":"Node (physics)","score":0.4179367125034332},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.40402212738990784}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.905154824256897},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7668657898902893},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5549342632293701},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5360429883003235},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.5102002620697021},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.46387967467308044},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.42303037643432617},{"id":"https://openalex.org/C62611344","wikidata":"https://www.wikidata.org/wiki/Q1062658","display_name":"Node (physics)","level":2,"score":0.4179367125034332},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.40402212738990784},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C66938386","wikidata":"https://www.wikidata.org/wiki/Q633538","display_name":"Structural engineering","level":1,"score":0.0},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3394520","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3394520","pdf_url":null,"source":{"id":"https://openalex.org/S41523882","display_name":"ACM Transactions on Knowledge Discovery from Data","issn_l":"1556-4681","issn":["1556-4681","1556-472X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Knowledge Discovery from Data","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2854317504","display_name":null,"funder_award_id":"291763","funder_id":"https://openalex.org/F4320334960","funder_display_name":"Seventh Framework Programme"},{"id":"https://openalex.org/G5540546246","display_name":null,"funder_award_id":"GU 1409/2-1","funder_id":"https://openalex.org/F4320320879","funder_display_name":"Deutsche Forschungsgemeinschaft"}],"funders":[{"id":"https://openalex.org/F4320320879","display_name":"Deutsche Forschungsgemeinschaft","ror":"https://ror.org/018mejw64"},{"id":"https://openalex.org/F4320334960","display_name":"Seventh Framework Programme","ror":"https://ror.org/00k4n6c32"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":35,"referenced_works":["https://openalex.org/W1583837637","https://openalex.org/W1972978214","https://openalex.org/W2000042664","https://openalex.org/W2033193852","https://openalex.org/W2078290701","https://openalex.org/W2082137964","https://openalex.org/W2091158010","https://openalex.org/W2144906988","https://openalex.org/W2149427297","https://openalex.org/W2153959628","https://openalex.org/W2154851992","https://openalex.org/W2162630660","https://openalex.org/W2180612164","https://openalex.org/W2403788960","https://openalex.org/W2501871465","https://openalex.org/W2584187726","https://openalex.org/W2744095836","https://openalex.org/W2745001864","https://openalex.org/W2752586018","https://openalex.org/W2803831897","https://openalex.org/W2907492528","https://openalex.org/W2912269676","https://openalex.org/W2951823788","https://openalex.org/W2962756421","https://openalex.org/W2962881240","https://openalex.org/W2963224980","https://openalex.org/W3098276446","https://openalex.org/W3099608705","https://openalex.org/W3103362336","https://openalex.org/W3104097132","https://openalex.org/W3106390645","https://openalex.org/W3111818035","https://openalex.org/W4210257598","https://openalex.org/W4236965008","https://openalex.org/W4238452917"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W4310988119","https://openalex.org/W4285226279","https://openalex.org/W4288019534"],"abstract_inverted_index":{"Deep":[0],"learning":[1,45,99],"models":[2,46,68,184],"for":[3,9,47],"graphs":[4,48],"have":[5],"achieved":[6],"strong":[7],"performance":[8],"the":[10,38,83,93,106,110,116,126,138,175,198,203],"task":[11],"of":[12,59,71,87,96,158,211],"node":[13,159,182],"classification.":[14],"Despite":[15],"their":[16,22],"proliferation,":[17],"little":[18],"is":[19,200],"known":[20],"about":[21,197],"robustness":[23],"to":[24,34,76,179,226],"adversarial":[25,60,103,212,228],"attacks.":[26],"Yet,":[27],"in":[28,120],"domains":[29],"where":[30],"they":[31],"are":[32,41,173,190],"likely":[33],"be":[35,49],"used,":[36],"e.g.,":[37],"web,":[39],"adversaries":[40],"common.":[42],"Can":[43],"deep":[44],"easily":[50],"fooled?":[51],"In":[52,74],"this":[53],"work,":[54],"we":[55,81,123,142,206],"present":[56],"a":[57,97,220],"study":[58,154],"attacks":[61,77,172,177,213,229],"on":[62,67,92,214,230],"attributed":[63],"graphs,":[64],"specifically":[65],"focusing":[66],"exploiting":[69,149],"ideas":[70],"graph":[72,111,199,215],"convolutions.":[73],"addition":[75],"at":[78],"test":[79],"time,":[80,205],"tackle":[82],"more":[84],"challenging":[85],"class":[86],"poisoning/causative":[88],"attacks,":[89],"which":[90],"focus":[91],"training":[94],"phase":[95],"machine":[98],"model.":[100],"We":[101],"generate":[102],"perturbations":[104,127],"targeting":[105],"node\u2019s":[107],"features":[108],"and":[109,185,188],"structure":[112],",":[113],"thus,":[114],"taking":[115],"dependencies":[117],"between":[118],"instances":[119],"account.":[121],"Moreover,":[122],"ensure":[124],"that":[125,156],"remain":[128],"unnoticeable":[129],"by":[130],"preserving":[131],"important":[132,209],"data":[133],"characteristics.":[134],"To":[135],"cope":[136],"with":[137],"underlying":[139],"discrete":[140],"domain,":[141],"propose":[143],"an":[144],"efficient":[145],"algorithm":[146],"N":[147],"ettack":[148],"incremental":[150],"computations.":[151],"Our":[152],"experimental":[153],"shows":[155],"accuracy":[157],"classification":[160,183],"significantly":[161],"drops":[162],"even":[163,192],"when":[164,193],"performing":[165],"only":[166,194],"few":[167],"perturbations.":[168],"Even":[169],"more,":[170],"our":[171],"transferable:":[174],"learned":[176],"generalize":[178],"other":[180],"state-of-the-art":[181],"unsupervised":[186],"approaches,":[187],"likewise":[189],"successful":[191],"limited":[195],"knowledge":[196],"given.":[201],"For":[202],"first":[204,221],"successfully":[207],"identify":[208],"patterns":[210],"neural":[216],"networks":[217],"(GNNs)":[218],"\u2014":[219],"step":[222],"towards":[223],"being":[224],"able":[225],"detect":[227],"GNNs.":[231]},"counts_by_year":[{"year":2026,"cited_by_count":4},{"year":2025,"cited_by_count":29},{"year":2024,"cited_by_count":22},{"year":2023,"cited_by_count":14},{"year":2022,"cited_by_count":14},{"year":2021,"cited_by_count":14},{"year":2020,"cited_by_count":2}],"updated_date":"2026-05-07T13:39:58.223016","created_date":"2025-10-10T00:00:00"}
