Exploiting Meta-Learning-based Poisoning Attacks for Graph Link Prediction

📅 2025-04-08
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Variational Graph Autoencoders (VGAEs) lack robustness evaluation against adversarial structural poisoning attacks in link prediction—a critical yet underexplored gap. Method: We propose the first meta-learning–based (MAML) unweighted graph structure poisoning attack, operating in a black-box setting that optimizes minimal edge perturbations without accessing model weights. Our approach jointly performs adversarial optimization and discrete edge-level search, achieving high efficiency, cross-model transferability, and low query cost—overcoming limitations of gradient-based or heuristic alternatives. Contribution/Results: On benchmark citation networks (Cora, Citeseer, Pubmed), our attack reduces VGAE’s AUC by 15–32%, significantly outperforming state-of-the-art methods including FGA and NETTACK. This work establishes a novel paradigm for evaluating robustness of graph neural networks under structural adversarial perturbations.

Technology Category

Application Category

📝 Abstract
Link prediction in graph data utilizes various algorithms and machine learning/deep learning models to predict potential relationships between graph nodes. This technique has found widespread use in numerous real-world applications, including recommendation systems, community networks, and biological structures. However, recent research has highlighted the vulnerability of link prediction models to adversarial attacks, such as poisoning and evasion attacks. Addressing the vulnerability of these models is crucial to ensure stable and robust performance in link prediction applications. While many works have focused on enhancing the robustness of the Graph Convolution Network (GCN) model, the Variational Graph Auto-Encoder (VGAE), a sophisticated model for link prediction, has not been thoroughly investigated in the context of graph adversarial attacks. To bridge this gap, this article proposes an unweighted graph poisoning attack approach using meta-learning techniques to undermine VGAE's link prediction performance. We conducted comprehensive experiments on diverse datasets to evaluate the proposed method and its parameters, comparing it with existing approaches in similar settings. Our results demonstrate that our approach significantly diminishes link prediction performance and outperforms other state-of-the-art methods.
Problem

Research questions and friction points this paper is trying to address.

Investigates VGAE vulnerability to poisoning attacks
Proposes meta-learning-based attack on link prediction
Evaluates attack effectiveness across diverse datasets
Innovation

Methods, ideas, or system contributions that make the work stand out.

Meta-learning-based poisoning attack on VGAE
Unweighted graph poisoning for link prediction
Outperforms state-of-the-art adversarial methods
M
Mingchen Li
Department of Electrical Engineering, University of South Florida, Tampa, FL 33620 USA
Z
Zhuang Di
Snap Inc., Santa Monica, CA 90405 USA
K
Keyu Chen
Department of Electrical Engineering, University of South Florida, Tampa, FL 33620 USA
D
Dumindu Samaraweera
Embry-Riddle Aeronautical University, Daytona Beach, FL 32114
Morris Chang
Morris Chang
University of South Florida
Wireless NetworksEnergy-aware Computing