{"id":"https://openalex.org/W4401863326","doi":"https://doi.org/10.1145/3637528.3671890","title":"Attacking Graph Neural Networks with Bit Flips: Weisfeiler and Leman Go Indifferent","display_name":"Attacking Graph Neural Networks with Bit Flips: Weisfeiler and Leman Go Indifferent","publication_year":2024,"publication_date":"2024-08-24","ids":{"openalex":"https://openalex.org/W4401863326","doi":"https://doi.org/10.1145/3637528.3671890"},"language":"en","primary_location":{"id":"doi:10.1145/3637528.3671890","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3637528.3671890","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3637528.3671890","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3637528.3671890","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5000376021","display_name":"Lorenz Kummer","orcid":"https://orcid.org/0000-0001-6538-9107"},"institutions":[{"id":"https://openalex.org/I129774422","display_name":"University of Vienna","ror":"https://ror.org/03prydq77","country_code":"AT","type":"education","lineage":["https://openalex.org/I129774422"]}],"countries":["AT"],"is_corresponding":true,"raw_author_name":"Lorenz Kummer","raw_affiliation_strings":["Doctoral School Computer Science, University of Vienna &amp; Faculty of Computer Science, University of Vienna, Vienna, Austria"],"affiliations":[{"raw_affiliation_string":"Doctoral School Computer Science, University of Vienna &amp; Faculty of Computer Science, University of Vienna, Vienna, Austria","institution_ids":["https://openalex.org/I129774422"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020032226","display_name":"Samir Moustafa","orcid":null},"institutions":[{"id":"https://openalex.org/I129774422","display_name":"University of Vienna","ror":"https://ror.org/03prydq77","country_code":"AT","type":"education","lineage":["https://openalex.org/I129774422"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Samir Moustafa","raw_affiliation_strings":["Doctoral School Computer Science, University of Vienna &amp; Faculty of Computer Science, University of Vienna, Vienna, Austria"],"affiliations":[{"raw_affiliation_string":"Doctoral School Computer Science, University of Vienna &amp; Faculty of Computer Science, University of Vienna, Vienna, Austria","institution_ids":["https://openalex.org/I129774422"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5055367812","display_name":"Sebastian Schrittwieser","orcid":"https://orcid.org/0000-0003-2115-2022"},"institutions":[{"id":"https://openalex.org/I129774422","display_name":"University of Vienna","ror":"https://ror.org/03prydq77","country_code":"AT","type":"education","lineage":["https://openalex.org/I129774422"]},{"id":"https://openalex.org/I4210105054","display_name":"Christian Doppler Laboratory for Thermoelectricity","ror":"https://ror.org/01cbw5x35","country_code":"AT","type":"facility","lineage":["https://openalex.org/I129774422","https://openalex.org/I145847075","https://openalex.org/I4210105054"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Sebastian Schrittwieser","raw_affiliation_strings":["Christian Doppler Laboratory for Assurance and Transparency in Software Protection, University of Vienna &amp; Faculty of Computer Science, University of Vienna, Vienna, Austria"],"affiliations":[{"raw_affiliation_string":"Christian Doppler Laboratory for Assurance and Transparency in Software Protection, University of Vienna &amp; Faculty of Computer Science, University of Vienna, Vienna, Austria","institution_ids":["https://openalex.org/I4210105054","https://openalex.org/I129774422"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5021065276","display_name":"Wilfried N. Gansterer","orcid":"https://orcid.org/0000-0001-5170-1251"},"institutions":[{"id":"https://openalex.org/I129774422","display_name":"University of Vienna","ror":"https://ror.org/03prydq77","country_code":"AT","type":"education","lineage":["https://openalex.org/I129774422"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Wilfried Gansterer","raw_affiliation_strings":["Faculty of Computer Science, University of Vienna, Vienna, Austria"],"affiliations":[{"raw_affiliation_string":"Faculty of Computer Science, University of Vienna, Vienna, Austria","institution_ids":["https://openalex.org/I129774422"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5009569829","display_name":"Nils M. Kriege","orcid":"https://orcid.org/0000-0003-2645-947X"},"institutions":[{"id":"https://openalex.org/I129774422","display_name":"University of Vienna","ror":"https://ror.org/03prydq77","country_code":"AT","type":"education","lineage":["https://openalex.org/I129774422"]}],"countries":["AT"],"is_corresponding":false,"raw_author_name":"Nils Kriege","raw_affiliation_strings":["Research Network Data Science, University of Vienna &amp; Faculty of Computer Science, University of Vienna, Vienna, Austria"],"affiliations":[{"raw_affiliation_string":"Research Network Data Science, University of Vienna &amp; Faculty of Computer Science, University of Vienna, Vienna, Austria","institution_ids":["https://openalex.org/I129774422"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5000376021"],"corresponding_institution_ids":["https://openalex.org/I129774422"],"apc_list":null,"apc_paid":null,"fwci":0.3475,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.65558019,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"1428","last_page":"1439"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10502","display_name":"Advanced Memory and Neural Computing","score":0.992900013923645,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6932045221328735},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.540254533290863},{"id":"https://openalex.org/keywords/bit","display_name":"Bit (key)","score":0.5317389369010925},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.4723972976207733},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.44330033659935},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.30596989393234253},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.21568480134010315}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6932045221328735},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.540254533290863},{"id":"https://openalex.org/C117011727","wikidata":"https://www.wikidata.org/wiki/Q1278488","display_name":"Bit (key)","level":2,"score":0.5317389369010925},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.4723972976207733},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.44330033659935},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.30596989393234253},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.21568480134010315}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3637528.3671890","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3637528.3671890","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3637528.3671890","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3637528.3671890","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3637528.3671890","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3637528.3671890","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","raw_type":"proceedings-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/10","display_name":"Reduced inequalities","score":0.550000011920929}],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4401863326.pdf"},"referenced_works_count":50,"referenced_works":["https://openalex.org/W609902030","https://openalex.org/W2142498761","https://openalex.org/W2803831897","https://openalex.org/W2807835252","https://openalex.org/W2939057911","https://openalex.org/W2962810718","https://openalex.org/W2981860227","https://openalex.org/W2990524908","https://openalex.org/W3012846134","https://openalex.org/W3013520104","https://openalex.org/W3024936300","https://openalex.org/W3035011799","https://openalex.org/W3036619032","https://openalex.org/W3048964647","https://openalex.org/W3090384356","https://openalex.org/W3094572750","https://openalex.org/W3098276446","https://openalex.org/W3109541151","https://openalex.org/W3124962940","https://openalex.org/W3125917269","https://openalex.org/W3130218089","https://openalex.org/W3137188301","https://openalex.org/W3138089704","https://openalex.org/W3162616539","https://openalex.org/W3165439041","https://openalex.org/W3190905285","https://openalex.org/W3191668483","https://openalex.org/W3194259208","https://openalex.org/W3199792160","https://openalex.org/W4200370950","https://openalex.org/W4206199331","https://openalex.org/W4206998764","https://openalex.org/W4224313798","https://openalex.org/W4226343493","https://openalex.org/W4237977885","https://openalex.org/W4242053016","https://openalex.org/W4283833281","https://openalex.org/W4285217780","https://openalex.org/W4288080007","https://openalex.org/W4297337468","https://openalex.org/W4303426745","https://openalex.org/W4312825910","https://openalex.org/W4312942615","https://openalex.org/W4319596548","https://openalex.org/W4365398249","https://openalex.org/W4385212428","https://openalex.org/W4387841511","https://openalex.org/W4391884321","https://openalex.org/W6600575157","https://openalex.org/W6681029592"],"related_works":["https://openalex.org/W2411923897","https://openalex.org/W4394546135","https://openalex.org/W4285347720","https://openalex.org/W4200259850","https://openalex.org/W2333831899","https://openalex.org/W2484894494","https://openalex.org/W2367385042","https://openalex.org/W4381186982","https://openalex.org/W2040781570","https://openalex.org/W4226055750"],"abstract_inverted_index":{"Prior":[0],"attacks":[1,30,164],"on":[2,8,136],"graph":[3,9,47,70,92,111,137],"neural":[4,21,48,71,85,112,168],"networks":[5,49,113],"have":[6],"focused":[7],"poisoning":[10],"and":[11,17,94,178],"evasion,":[12],"neglecting":[13],"the":[14,24,37,57,62,76,96,99,129,151],"network's":[15,152],"weights":[16],"biases.":[18],"For":[19],"convolutional":[20,167],"networks,":[22,86],"however,":[23],"risk":[25],"arising":[26],"from":[27,166],"bit":[28,43,64,119,162],"flip":[29,44,65,120,163],"is":[31,50,172],"well":[32],"recognized.":[33],"We":[34,102],"show":[35],"that":[36,104],"direct":[38],"application":[39],"of":[40,51,98,150],"a":[41,147],"traditional":[42,161],"attack":[45,66,74,171],"to":[46,90,109,118,141,160],"limited":[52],"effectivity.":[53],"Hence,":[54],"we":[55],"discuss":[56],"Injectivity":[58,123],"Bit":[59,124],"Flip":[60,125],"Attack,":[61],"first":[63],"designed":[67],"specifically":[68],"for":[69],"networks.":[72,169],"Our":[73,170],"targets":[75],"learnable":[77],"neighborhood":[78],"aggregation":[79],"functions":[80],"in":[81],"quantized":[82],"message":[83],"passing":[84],"degrading":[87],"their":[88,116],"ability":[89],"distinguish":[91],"structures":[93],"impairing":[95],"expressivity":[97],"Weisfeiler-Leman":[100],"test.":[101],"find":[103],"exploiting":[105],"mathematical":[106],"properties":[107],"specific":[108],"certain":[110],"significantly":[114],"increases":[115],"vulnerability":[117],"attacks.":[121],"The":[122],"Attack":[126],"can":[127],"degrade":[128],"maximal":[130],"expressive":[131],"Graph":[132],"Isomorphism":[133],"Networks":[134],"trained":[135],"property":[138],"prediction":[139],"datasets":[140],"random":[142],"output":[143],"by":[144,175,180],"flipping":[145],"only":[146],"small":[148],"fraction":[149],"bits,":[153],"demonstrating":[154],"its":[155],"higher":[156],"destructive":[157],"power":[158],"compared":[159],"transferred":[165],"transparent,":[173],"motivated":[174],"theoretical":[176],"insights":[177],"confirmed":[179],"extensive":[181],"empirical":[182],"results.":[183]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2024-08-26T00:00:00"}
