{"id":"https://openalex.org/W7138230679","doi":"https://doi.org/10.1609/aaai.v40i29.39668","title":"Surrogate as Teacher: Distillation-Guided Graph Poisoning Attack","display_name":"Surrogate as Teacher: Distillation-Guided Graph Poisoning Attack","publication_year":2026,"publication_date":"2026-03-14","ids":{"openalex":"https://openalex.org/W7138230679","doi":"https://doi.org/10.1609/aaai.v40i29.39668"},"language":null,"primary_location":{"id":"doi:10.1609/aaai.v40i29.39668","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i29.39668","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://doi.org/10.1609/aaai.v40i29.39668","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5129695825","display_name":"Xingyu Peng","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Xingyu Peng","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5129668806","display_name":"Ke Xu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ke Xu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5129695825"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.39196941,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"40","issue":"29","first_page":"24820","last_page":"24827"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.7325000166893005,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.7325000166893005,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.22120000422000885,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.007799999788403511,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7548999786376953},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.5989999771118164},{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.5218999981880188},{"id":"https://openalex.org/keywords/divergence","display_name":"Divergence (linguistics)","score":0.3483999967575073},{"id":"https://openalex.org/keywords/redundancy","display_name":"Redundancy (engineering)","score":0.3082999885082245}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7548999786376953},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7087000012397766},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.5989999771118164},{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.5218999981880188},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.448199987411499},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4049000144004822},{"id":"https://openalex.org/C207390915","wikidata":"https://www.wikidata.org/wiki/Q1230525","display_name":"Divergence (linguistics)","level":2,"score":0.3483999967575073},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.30979999899864197},{"id":"https://openalex.org/C152124472","wikidata":"https://www.wikidata.org/wiki/Q1204361","display_name":"Redundancy (engineering)","level":2,"score":0.3082999885082245},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2948000133037567},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.29019999504089355},{"id":"https://openalex.org/C88230418","wikidata":"https://www.wikidata.org/wiki/Q131476","display_name":"Graph theory","level":2,"score":0.2840999960899353}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1609/aaai.v40i29.39668","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i29.39668","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1609/aaai.v40i29.39668","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i29.39668","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"sustainable_development_goals":[{"display_name":"Quality Education","id":"https://metadata.un.org/sdg/4","score":0.8125506043434143}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"While":[0],"leveraging":[1],"pseudo-labels":[2,25,75],"has":[3],"become":[4],"a":[5,54,68,77,104],"common":[6],"paradigm":[7],"in":[8],"untargeted":[9],"gray-box":[10],"graph":[11,44,163],"poisoning":[12],"attacks,":[13],"it":[14,119],"suffers":[15],"from":[16],"two":[17,93],"critical":[18],"limitations:":[19],"the":[20,43,59,81,87,98,121,129,136],"use":[21],"of":[22],"brittle":[23],"hard":[24],"that":[26,38,57,109,144],"overlook":[27],"uncertainty":[28],"and":[29,35,147,158],"can":[30],"amplify":[31],"surrogate":[32],"model":[33,70],"errors,":[34],"static":[36],"guidance":[37,137],"progressively":[39],"becomes":[40],"stale":[41],"as":[42,61,103],"is":[45],"perturbed.":[46],"To":[47],"resolve":[48],"these":[49],"issues,":[50],"we":[51],"propose":[52],"MetaDist,":[53],"novel":[55],"framework":[56],"reframes":[58],"attack":[60,82,107],"an":[62],"adversarial":[63],"self-knowledge":[64],"distillation":[65],"process.":[66],"Here,":[67],"\"teacher\"":[69],"provides":[71],"continuously":[72],"refined":[73],"soft":[74],"to":[76,85,134],"\"student\"":[78],"model,":[79],"with":[80],"objective":[83],"being":[84],"maximize":[86],"divergence":[88,102],"between":[89],"them.":[90],"MetaDist":[91,145],"makes":[92],"synergistic":[94],"innovations.":[95],"It":[96],"employs":[97],"Reverse":[99],"KL":[100],"(RKL)":[101],"more":[105],"strategic":[106],"loss":[108],"efficiently":[110],"converts":[111],"uncertain":[112],"nodes":[113],"into":[114],"robust,":[115],"high-confidence":[116],"errors.":[117],"Concurrently,":[118],"introduces":[120],"Online":[122],"Adaptive":[123],"Teacher":[124],"(OAT)":[125],"mechanism,":[126],"which":[127],"adapts":[128],"teacher":[130],"via":[131],"student":[132],"feedback":[133],"ensure":[135],"signal":[138],"remains":[139],"relevant.":[140],"Extensive":[141],"experiments":[142],"demonstrate":[143],"consistently":[146],"significantly":[148],"outperforms":[149],"strong":[150],"baselines":[151],"across":[152],"multiple":[153],"datasets,":[154],"proving":[155],"its":[156],"effectiveness":[157],"transferability":[159],"even":[160],"against":[161],"advanced":[162],"defenses.":[164]},"counts_by_year":[],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2026-03-18T00:00:00"}
