Graph Neural Networks (GNNs) are powerful in learning rich network representations that aid the performance of downstream tasks. However, recent studies showed that GNNs are vulnerable to adversarial attacks involving node injection and network perturbation. Among these, node injection attacks are more practical as they do not require manipulation in the existing network and can be performed more realistically. In this paper, we propose a novel problem statement - a class-specific poison attack on graphs in which the attacker aims to misclassify specific nodes in the target class into a different class using node injection. Additionally, nodes are injected in such a way that they camouflage as benign nodes. We propose NICKI, a novel attacking strategy that utilizes an optimization-based approach to sabotage the performance of GNN-based node classifiers. NICKI works in two phases - it first learns the node representation and then generates the features and edges of the injected nodes. Extensive experiments and ablation studies on four benchmark networks show that NICKI is consistently better than four baseline attacking strategies for misclassifying nodes in the target class. We also show that the injected nodes are properly camouflaged as benign, thus making the poisoned graph indistinguishable from its clean version w.r.t various topological properties.

Download full-text PDF

Source
http://dx.doi.org/10.1016/j.neunet.2023.07.025DOI Listing

Publication Analysis

Top Keywords

node injection
16
nodes target
8
target class
8
injected nodes
8
node
6
nodes
6
injection class-specific
4
network
4
class-specific network
4
network poisoning
4

Similar Publications

Purpose: The purpose of this study was to evaluate the feasibility and safety of indocyanine green (ICG) fluorescence as an alternative to traditional sentinel lymph node biopsy (SLNB) techniques in breast cancer (BC) patients undergoing neoadjuvant chemotherapy (NAC). Specifically, the study aimed to assess sentinel node identification rates and the effectiveness of ICG in axillary staging without the use of radioactive tracers.

Methods: This retrospective study included 71 BC patients treated with NAC, who underwent SLNB using ICG fluorescence between 2020 and 2024.

View Article and Find Full Text PDF

Redosing with Intralymphatic GAD-Alum in the Treatment of Type 1 Diabetes: The DIAGNODE-B Pilot Trial.

Int J Mol Sci

January 2025

Division of Pediatrics, Department of Biomedical and Clinical Sciences, Faculty of Medicine and Health Sciences, Linköping University, 581 83 Linköping, Sweden.

Immunotherapies aimed at preserving residual beta cell function in type 1 diabetes have been successful, although the effect has been limited, or raised safety concerns. Transient effects often observed may necessitate redosing to prolong the effect, although this is not always feasible or safe. Treatment with intralymphatic GAD-alum has been shown to be tolerable and safe in persons with type 1 diabetes and has shown significant efficacy to preserve C-peptide with associated clinical benefit in individuals with the human leukocyte antigen DR3DQ2 haplotype.

View Article and Find Full Text PDF

Objective: The necessity of preoperative lymphoscintigraphy before intraoperative sentinel lymph node (SLN) identification is still unclear. The aim of the present study was to evaluate the impact of SLN imaging on intraoperative SLN detection in breast cancer patients.

Methods: Retrospective, comparative, single center study of patients with breast cancer stage pT1 and pT2 who underwent axillary staging.

View Article and Find Full Text PDF

Spectral adversarial attack on graph via node injection.

Neural Netw

January 2025

School of Big Data and Computer Science, Guizhou Normal University, Guiyang 550025, China.

Graph Neural Networks (GNNs) have shown remarkable achievements and have been extensively applied in various downstream tasks, such as node classification and community detection. However, recent studies have demonstrated that GNNs are vulnerable to subtle adversarial perturbations on graphs, including node injection attacks, which negatively affect downstream tasks. Existing node injection attacks have mainly focused on the limited local nodes, neglecting the analysis of the whole graph which restricts the attack's ability.

View Article and Find Full Text PDF

Background: Cachexia is defined by chronic loss of fat and muscle, is a frequent complication of pancreatic ductal adenocarcinoma (PDAC), and negatively impacts patient outcomes. Nutritional supplementation cannot fully reverse tissue wasting, and the mechanisms underlying this phenotype are unclear. This work aims to define the relative contributions of catabolism and anabolism to adipose wasting in PDAC-bearing mice.

View Article and Find Full Text PDF

Want AI Summaries of new PubMed Abstracts delivered to your In-box?

Enter search terms and have AI summaries delivered each week - change queries or unsubscribe any time!