{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/adversarial-attacks-on-graph-classification","title":"Adversarial Attacks on Graph Classification via Bayesian Optimisation","arxiv_id":"2111.02842","date":"2021-11-04","proceeding":null,"authors":["Xingchen Wan","Henry Kenlay","Binxin Ru","Arno Blaas","Michael A. Osborne","Xiaowen Dong"],"abstract":"Graph neural networks, a popular class of models effective in a wide range of graph-based learning tasks, have been shown to be vulnerable to adversarial attacks. While the majority of the literature focuses on such vulnerability in node-level classification tasks, little effort has been dedicated to analysing adversarial attacks on graph-level classification, an important problem with numerous real-life applications such as biochemistry and social network analysis. The few existing methods often require unrealistic setups, such as access to internal information of the victim models, or an impractically-large number of queries. We present a novel Bayesian optimisation-based attack method for graph classification models. Our method is black-box, query-efficient and parsimonious with respect to the perturbation applied. We empirically validate the effectiveness and flexibility of the proposed method on a wide range of graph classification tasks involving varying graph properties, constraints and modes of attack. Finally, we analyse common interpretable patterns behind the adversarial samples produced, which may shed further light on the adversarial robustness of graph classification models.","url_abs":"https://arxiv.org/abs/2111.02842v1","url_pdf":"https://arxiv.org/pdf/2111.02842v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"adversarial-attacks-on-graph-classification","repo_url":"https://github.com/xingchenwan/grabnel","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[{"task_slug":"adversarial-robustness","task_name":"Adversarial Robustness"},{"task_slug":"bayesian-optimisation","task_name":"Bayesian Optimisation"},{"task_slug":"classification-1","task_name":"Classification"},{"task_slug":"graph-classification","task_name":"Graph Classification"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2111.02842","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2111.02842"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/xingchenwan/grabnel","reach":{"status":"ok"}},{"provenance":"deterministic:regex_extraction","url":"https://github.com/Hanjun-Dai/graph_adversarial_attack","reach":{"status":"ok","spdx":"MIT"}},{"provenance":"deterministic:regex_extraction","url":"https://github.com/bknyaz/graph_","reach":{"status":"gone","observed_at":"2026-09-17","how":"tree_404+repo_404"}},{"provenance":"deterministic:regex_extraction","url":"https://github.com/HongyangGao/Graph-U-Nets","reach":null}],"summary":{"unverified":3},"by_repo_kind":{"found_in_text":{"samples":3,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"ba8ee3dc4e80a754","entry":"gnn_spmm","repo":"Hanjun-Dai/graph_adversarial_attack","repo_kind":"found_in_text","path":"code/common/graph_embedding.py","file_url":"https://github.com/Hanjun-Dai/graph_adversarial_attack/blob/HEAD/code/common/graph_embedding.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"ba8ee3dc4e80a754"}},{"code_sha256_prefix":"795806855976704d","entry":"hash_state_action","repo":"Hanjun-Dai/graph_adversarial_attack","repo_kind":"found_in_text","path":"code/graph_attack/nstep_replay_mem.py","file_url":"https://github.com/Hanjun-Dai/graph_adversarial_attack/blob/HEAD/code/graph_attack/nstep_replay_mem.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"795806855976704d"}},{"code_sha256_prefix":"19fc47c0fdecaf66","entry":"node_greedy_actions","repo":"Hanjun-Dai/graph_adversarial_attack","repo_kind":"found_in_text","path":"code/node_attack/q_net_node.py","file_url":"https://github.com/Hanjun-Dai/graph_adversarial_attack/blob/HEAD/code/node_attack/q_net_node.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"19fc47c0fdecaf66"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}