{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/adversarial-attacks-on-graph-neural-networks","title":"Adversarial Attacks on Graph Neural Networks via Meta Learning","arxiv_id":"1902.08412","date":"2019-02-22","proceeding":"ICLR 2019 5","authors":["Daniel Zügner","Stephan Günnemann"],"abstract":"Deep learning models for graphs have advanced the state of the art on many tasks. Despite their recent success, little is known about their robustness. We investigate training time attacks on graph neural networks for node classification that perturb the discrete graph structure. Our core principle is to use meta-gradients to solve the bilevel problem underlying training-time attacks, essentially treating the graph as a hyperparameter to optimize. Our experiments show that small graph perturbations consistently lead to a strong decrease in performance for graph convolutional networks, and even transfer to unsupervised embeddings. Remarkably, the perturbations created by our algorithm can misguide the graph neural networks such that they perform worse than a simple baseline that ignores all relational information. Our attacks do not assume any knowledge about or access to the target classifiers.","url_abs":"https://arxiv.org/abs/1902.08412v2","url_pdf":"https://arxiv.org/pdf/1902.08412v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"adversarial-attacks-on-graph-neural-networks","repo_url":"https://github.com/danielzuegner/gnn-meta-attack","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"tf","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[{"task_slug":"classification","task_name":"General Classification"},{"task_slug":"meta-learning","task_name":"Meta-Learning"},{"task_slug":"node-classification","task_name":"Node Classification"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1902.08412","atlas_url":"https://app.syntology.ai/?focus=1902.08412","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1902.08412"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/danielzuegner/gnn-meta-attack","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"ran":3,"unverified":1},"by_repo_kind":{"official":{"samples":4,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"11c8a4ad13f75fe4","entry":"largest_connected_components","repo":"danielzuegner/gnn-meta-attack","repo_kind":"official","path":"metattack/utils.py","file_url":"https://github.com/danielzuegner/gnn-meta-attack/blob/HEAD/metattack/utils.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"11c8a4ad13f75fe4"}},{"code_sha256_prefix":"4d18cf730d25baa5","entry":"load_npz","repo":"danielzuegner/gnn-meta-attack","repo_kind":"official","path":"metattack/utils.py","file_url":"https://github.com/danielzuegner/gnn-meta-attack/blob/HEAD/metattack/utils.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"4d18cf730d25baa5"}},{"code_sha256_prefix":"1d93a3510e01307b","entry":"preprocess_graph","repo":"danielzuegner/gnn-meta-attack","repo_kind":"official","path":"metattack/utils.py","file_url":"https://github.com/danielzuegner/gnn-meta-attack/blob/HEAD/metattack/utils.py","link_basis":"harvester_set","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"1d93a3510e01307b"}},{"code_sha256_prefix":"81be8a5f4732fe52","entry":"sparse_dropout","repo":"danielzuegner/gnn-meta-attack","repo_kind":"official","path":"metattack/meta_gradient_attack.py","file_url":"https://github.com/danielzuegner/gnn-meta-attack/blob/HEAD/metattack/meta_gradient_attack.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"81be8a5f4732fe52"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}