{"id":"https://openalex.org/W7140217403","doi":"https://doi.org/10.48550/arxiv.2603.21155","title":"Can LLMs Fool Graph Learning? Exploring Universal Adversarial Attacks on Text-Attributed Graphs","display_name":"Can LLMs Fool Graph Learning? Exploring Universal Adversarial Attacks on Text-Attributed Graphs","publication_year":2026,"publication_date":"2026-03-22","ids":{"openalex":"https://openalex.org/W7140217403","doi":"https://doi.org/10.48550/arxiv.2603.21155"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.21155","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.21155","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.21155","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Chen, Zihui","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chen, Zihui","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":null,"display_name":"Wang, Yuling","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Yuling","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":null,"display_name":"Jiao, Pengfei","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jiao, Pengfei","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":null,"display_name":"Wu, Kai","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wu, Kai","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":null,"display_name":"Wang, Xiao","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Xiao","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":null,"display_name":"Ao, Xiang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ao, Xiang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":null,"display_name":"Zhang, Dalin","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Dalin","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":7,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.8295999765396118,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.8295999765396118,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.05130000039935112,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.04490000009536743,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7757999897003174},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.5271000266075134},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.4681999981403351},{"id":"https://openalex.org/keywords/encode","display_name":"ENCODE","score":0.45260000228881836},{"id":"https://openalex.org/keywords/boosting","display_name":"Boosting (machine learning)","score":0.36570000648498535},{"id":"https://openalex.org/keywords/limiting","display_name":"Limiting","score":0.34709998965263367},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.3167000114917755},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.31049999594688416},{"id":"https://openalex.org/keywords/empirical-evidence","display_name":"Empirical evidence","score":0.2992999851703644}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7757999897003174},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7089999914169312},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.5271000266075134},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.5170000195503235},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.4681999981403351},{"id":"https://openalex.org/C66746571","wikidata":"https://www.wikidata.org/wiki/Q1134833","display_name":"ENCODE","level":3,"score":0.45260000228881836},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.37630000710487366},{"id":"https://openalex.org/C46686674","wikidata":"https://www.wikidata.org/wiki/Q466303","display_name":"Boosting (machine learning)","level":2,"score":0.36570000648498535},{"id":"https://openalex.org/C188198153","wikidata":"https://www.wikidata.org/wiki/Q1613840","display_name":"Limiting","level":2,"score":0.34709998965263367},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3197000026702881},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3167000114917755},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3124000132083893},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.31049999594688416},{"id":"https://openalex.org/C166052673","wikidata":"https://www.wikidata.org/wiki/Q83021","display_name":"Empirical evidence","level":2,"score":0.2992999851703644},{"id":"https://openalex.org/C59404180","wikidata":"https://www.wikidata.org/wiki/Q17013334","display_name":"Feature learning","level":2,"score":0.29899999499320984},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.2969000041484833},{"id":"https://openalex.org/C75553542","wikidata":"https://www.wikidata.org/wiki/Q178161","display_name":"A priori and a posteriori","level":2,"score":0.29350000619888306},{"id":"https://openalex.org/C2777522414","wikidata":"https://www.wikidata.org/wiki/Q648457","display_name":"Social graph","level":3,"score":0.28859999775886536},{"id":"https://openalex.org/C43091099","wikidata":"https://www.wikidata.org/wiki/Q1067788","display_name":"Through-the-lens metering","level":3,"score":0.28679999709129333},{"id":"https://openalex.org/C177769412","wikidata":"https://www.wikidata.org/wiki/Q278090","display_name":"Prior probability","level":3,"score":0.2809000015258789},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.27649998664855957},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.26739999651908875},{"id":"https://openalex.org/C2993807640","wikidata":"https://www.wikidata.org/wiki/Q103709453","display_name":"Attention network","level":2,"score":0.26249998807907104},{"id":"https://openalex.org/C64339825","wikidata":"https://www.wikidata.org/wiki/Q722659","display_name":"Graph property","level":5,"score":0.2590999901294708},{"id":"https://openalex.org/C199845137","wikidata":"https://www.wikidata.org/wiki/Q145490","display_name":"Network topology","level":2,"score":0.25850000977516174},{"id":"https://openalex.org/C2776576444","wikidata":"https://www.wikidata.org/wiki/Q303569","display_name":"Attack surface","level":2,"score":0.25679999589920044},{"id":"https://openalex.org/C2779439875","wikidata":"https://www.wikidata.org/wiki/Q1078276","display_name":"Natural language understanding","level":3,"score":0.251800000667572}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.21155","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.21155","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.21155","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.21155","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Text-attributed":[0],"graphs":[1],"(TAGs)":[2],"enhance":[3],"graph":[4,26,39,96,135,156],"learning":[5,27],"by":[6],"integrating":[7],"rich":[8],"textual":[9,53,144],"semantics":[10],"and":[11,43,52,92,94,143,176,181,193],"topological":[12],"context":[13],"for":[14],"each":[15],"node.":[16],"While":[17],"boosting":[18],"expressiveness,":[19],"they":[20],"also":[21],"expose":[22],"new":[23],"vulnerabilities":[24],"in":[25,55,88],"through":[28],"text-based":[29],"adversarial":[30,68],"surfaces.":[31],"Recent":[32],"advances":[33],"leverage":[34],"diverse":[35],"backbones,":[36],"such":[37],"as":[38],"neural":[40],"networks":[41],"(GNNs)":[42],"pre-trained":[44],"language":[45,129],"models":[46,130],"(PLMs),":[47],"to":[48,74,112,137,158,186],"capture":[49],"both":[50,140],"structural":[51],"information":[54],"TAGs.":[56],"This":[57],"diversity":[58],"raises":[59],"a":[60,121,149,187],"key":[61],"question:":[62],"How":[63],"can":[64],"we":[65,118,147],"design":[66,148],"universal":[67,175],"attacks":[69,111,178],"that":[70,102,125,154,172],"generalize":[71],"across":[72,179],"architectures":[73],"assess":[75],"the":[76,85,100],"security":[77],"of":[78,133],"TAG":[79],"models?":[80],"The":[81],"challenge":[82],"arises":[83],"from":[84],"stark":[86],"contrast":[87],"how":[89],"different":[90],"backbones-GNNs":[91],"PLMs-perceive":[93],"encode":[95],"patterns,":[97],"coupled":[98],"with":[99,184],"fact":[101],"many":[103],"PLMs":[104],"are":[105],"only":[106],"accessible":[107],"via":[108],"APIs,":[109],"limiting":[110],"black-box":[113],"settings.":[114],"To":[115],"address":[116],"this,":[117],"propose":[119],"BadGraph,":[120],"novel":[122],"attack":[123,162],"framework":[124],"deeply":[126],"elicits":[127],"large":[128],"(LLMs)":[131],"understanding":[132],"general":[134],"knowledge":[136],"jointly":[138],"perturb":[139],"node":[141],"topology":[142],"semantics.":[145],"Specifically,":[146],"target":[150],"influencer":[151],"retrieval":[152],"module":[153],"leverages":[155],"priors":[157],"construct":[159],"cross-modally":[160],"aligned":[161],"shortcuts,":[163],"thereby":[164],"enabling":[165],"efficient":[166],"LLM-based":[167,182],"perturbation":[168],"reasoning.":[169],"Experiments":[170],"show":[171],"BadGraph":[173],"achieves":[174],"effective":[177],"GNN-":[180],"reasoners,":[183],"up":[185],"76.3%":[188],"performance":[189],"drop,":[190],"while":[191],"theoretical":[192],"empirical":[194],"analyses":[195],"confirm":[196],"its":[197],"stealthy":[198],"yet":[199],"interpretable":[200],"nature.":[201]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-03-25T00:00:00"}
