Please wait a minute...
浙江大学学报(工学版)  2026, Vol. 60 Issue (8): 1739-1748    DOI: 10.3785/j.issn.1008-973X.2026.08.013
计算机技术     
面向图神经网络谣言检测器的高效攻击模型
范业博(),李逸成,刘勇*(),张薇
黑龙江大学 计算机与大数据学院(网络安全学院),黑龙江 哈尔滨 150080
Efficient attack model targeting GNN-based rumor detectors
Yebo FAN(),Yicheng LI,Yong LIU*(),Wei ZHANG
School of Computer and Big Data (School of Cyber Security), Heilongjiang University, Harbin 150080, China
 全文: PDF(858 KB)   HTML
摘要:

为了研究图神经网络(GNN)谣言检测器在对抗攻击下的潜在脆弱性,提出基于虚假节点注入的对抗攻击模型EAT-GNN,通过构造虚假节点及其边连接,对谣言检测器进行干扰. 在节点层面,通过多层感知机(MLP)结合新闻特征及其变换表示、邻居节点平均池化特征和标签信息,生成虚假节点特征. 在边层面,通过MLP结合虚假节点特征、新闻特征、邻居特征及标签信息对候选边进行评分,选择干扰效果最强的潜在边连接候选节点与虚假节点. 实验结果表明,EAT-GNN能有效降低图神经网络谣言检测器的性能,攻击速度较现有方法平均提升约2个量级,具有揭示GNN谣言检测器脆弱性的能力.

关键词: 谣言检测器图神经网络(GNN)对抗攻击节点注入多层感知机    
Abstract:

A study was conducted to explore the potential vulnerability of graph neural network (GNN)-based rumor detectors under adversarial attacks, and a false node injection-based adversarial attack model named EAT-GNN was proposed. The model was designed to interfere with rumor detectors by constructing false nodes and their associated connections. At the node level, false node features were generated using a multilayer perceptron (MLP) that incorporated news features, their transformed representations, averaged neighbor node features via pooling, and label information. At the edge level, candidate edges were scored by an MLP based on false node features, news features, neighbor features, and label information; edges with the highest potential disruption effect were selected to connect candidate nodes to false nodes. Experimental results indicate that EAT-GNN effectively reduces the performance of GNN-based rumor detectors. The attack speed is improved by approximately two orders of magnitude compared to existing methods, demonstrating the proposed model’s capability to reveal vulnerabilities in GNN-based rumor detectors.

Key words: rumor detector    graph neural network (GNN)    adversarial attack    node injection    multilayer perceptron
收稿日期: 2025-07-29 出版日期: 2026-07-16
CLC:  TP 391  
基金资助: 国家自然科学基金资助项目(62472148);黑龙江省自然科学基金资助项目(PL2024F029).
通讯作者: 刘勇     E-mail: 2231971@s.hlju.edu.cn;liuyong123456@hlju.edu.cn
作者简介: 范业博(2001—),男,硕士生,从事谣言检测研究. orcid.org/0009-0004-7295-2788. E-mail:2231971@s.hlju.edu.cn
服务  
把本文推荐给朋友
加入引用管理器
E-mail Alert
作者相关文章  
范业博
李逸成
刘勇
张薇

引用本文:

范业博,李逸成,刘勇,张薇. 面向图神经网络谣言检测器的高效攻击模型[J]. 浙江大学学报(工学版), 2026, 60(8): 1739-1748.

Yebo FAN,Yicheng LI,Yong LIU,Wei ZHANG. Efficient attack model targeting GNN-based rumor detectors. Journal of ZheJiang University (Engineering Science), 2026, 60(8): 1739-1748.

链接本文:

https://www.zjujournals.com/eng/CN/10.3785/j.issn.1008-973X.2026.08.013        https://www.zjujournals.com/eng/CN/Y2026/V60/I8/1739

图 1  面向图神经网络谣言检测器的高效攻击模型的整体架构
数据集真新闻假新闻用户数边数
Politifact2253721207279559
Gossipcop12641395826109762254
Weibo8775909854534
表 1  对比实验数据集统计
新闻类型模型ASR(Politifact)ASR(Gossipcop)
GCNGATSAGEU-GCNU-GATU-SAGEGCNGATSAGEU-GCNU-GATU-SAGE
假新闻未受攻击0.200.200.270.260.270.260.020.040.100.020.020.02
DICE0.290.340.370.310.280.520.040.080.100.040.060.06
MARL0.970.430.560.390.310.560.630.210.310.050.040.04
SGA1.000.680.840.550.450.890.770.400.370.060.200.21
GAFSI1.000.700.850.980.480.960.570.230.920.850.750.68
IBAttack1.000.790.890.920.840.920.980.780.940.890.810.77
HMIA-LLM0.880.800.770.810.640.790.800.860.900.700.880.77
EAT-GNN0.960.920.900.900.950.910.950.920.940.930.890.84
真新闻未受攻击0.040.100.120.100.140.130.080.030.020.050.060.05
DICE0.300.180.150.110.170.260.180.110.130.080.080.07
MARL0.810.390.320.130.250.320.750.220.350.080.160.18
SGA0.950.670.650.150.410.731.000.480.850.120.440.52
GAFSI0.950.550.700.720.520.861.000.480.910.840.640.68
IBAttack0.960.860.920.780.930.860.990.710.960.850.900.78
HMIA-LLM0.670.910.880.800.880.900.930.750.890.640.740.78
EAT-GNN0.980.980.960.830.970.950.950.790.980.910.930.82
表 2  不同模型在2个数据集上针对6种图神经网络架构的攻击成功率比较
新闻类型图神经网络ASR
MARLGAFSIHMIA-LLMEAT-GNN
假新闻GCN0.921.000.780.87
GAT0.510.630.890.97
SAGE0.600.820.670.79
U-GCN0.370.650.790.89
U-GAT0.440.550.640.91
U-SAGE0.530.870.730.95
真新闻GCN0.780.890.910.98
GAT0.480.540.810.83
SAGE0.350.730.720.80
U-GCN0.280.880.560.94
U-GAT0.160.660.710.83
U-SAGE0.310.700.930.93
表 3  EAT-GNN在Weibo数据集上的攻击成功率
图 2  模块消融实验结果对比
数据集t/s
MARLSGAGAFSIEAT-GNN
Politifact51. 770. 780. 505. 34×10?3
Gossipcop54. 242. 201. 696. 19×10?3
表 4  模型攻击的平均运行时间对比
1 ABONIZIO H Q, DE MORAIS J I, TAVARES G M, et al Language-independent fake news detection: English, Portuguese, and Spanish mutual features[J]. Future Internet, 2020, 12 (5): 87
doi: 10.3390/fi12050087
2 ISLAM M S, SARKAR T, KHAN S H, et al COVID-19-related infodemic and its impact on public health: a global social media analysis[J]. The American Journal of Tropical Medicine and Hygiene, 2020, 103 (4): 1621- 1629
doi: 10.4269/ajtmh.20-0812
3 BIAN T, XIAO X, XU T, et al. Rumor detection on social media with bi-directional graph convolutional networks [C]// Proceedings of the AAAI Conference on Artificial Intelligence. New York: AAAI Press, 2020: 549–556.
4 DOU Y, SHU K, XIA C, et al. User preference-aware fake news detection [C]// Proceedings of the 44th International ACM SIGIR Conference on Research and Development in Information Retrieval. [S.l.]: ACM, 2021: 2051–2055.
5 杨广浩, 万书振, 董方敏, 等 基于时间步局部动态交互的多任务谣言检测方法[J]. 计算机工程与应用, 2025, 61 (6): 183- 191
YANG Guanghao, WAN Shuzhen, DONG Fangmin, et al Multi-task rumor detection method based on time-step dynamic interaction[J]. Computer Engineering and Applications, 2025, 61 (6): 183- 191
6 成雪, 张琛, 李清旭 基于语义增强的虚假新闻检测[J]. 计算机应用与软件, 2025, 42 (2): 202- 209
CHENG Xue, ZHANG Chen, LI Qingxu False news detection based on semantic enhancement[J]. Computer Applications and Software, 2025, 42 (2): 202- 209
7 CHEN J, GONG Z, WANG W, et al Adversarial caching training: unsupervised inductive network representation learning on large-scale graphs[J]. IEEE Transactions on Neural Networks and Learning Systems, 2022, 33 (12): 7079- 7090
doi: 10.1109/TNNLS.2021.3084195
8 SHANG Y, ZHANG Y, CHEN J, et al. Transferable structure-based adversarial attack of heterogeneous graph neural network [C]// Proceedings of the 32nd ACM International Conference on Information and Knowledge Management. Birmingham: ACM, 2023: 2188–2197.
9 WANG H, DOU Y, CHEN C, et al. Attacking fake news detectors via manipulating news social engagement [C]// Proceedings of the ACM Web Conference 2023. Austin: ACM, 2023: 3978–3986.
10 LUO Y, LI Y, WEN D, et al. Message injection attack on rumor detection under the black-box evasion setting using large language model [C]// Proceedings of the ACM Web Conference 2024. Singapore: ACM, 2024: 4512–4522.
11 ZHU P, PAN Z, LIU Y, et al. A general black-box adversarial attack on graph-based fake news detectors [C]// Proceedings of the Thirty-Third International Joint Conference on Artificial Intelligence (IJCAI 2024). Jeju: IJCAI, 2024: 568–576.
12 LAO A, SHI C, YANG Y. Rumor detection with field of linear and non-linear propagation [C]// Proceedings of the Web Conference 2021. Ljubljana: ACM, 2021: 3178–3187.
13 HAN Y, KARUNASEKERA S, LECKIE C. Continual learning for fake news detection from social media [C]// Artificial Neural Networks and Machine Learning – ICANN 2021. [S.l.]: Springer, 2021: 372–384.
14 CHANDRA S, MISHRA P, YANNAKOUDAKIS H, et al. Graph-based modeling of online communities for fake news detection [EB/OL]. (2020–11–23)[2025–05–29]. https://arxiv.org/pdf/2008.06274.
15 NGUYEN V H, SUGIYAMA K, NAKOV P, et al FANG: leveraging social context for fake news detection using graph representation[J]. Communications of the ACM, 2022, 65 (4): 124- 132
doi: 10.1145/3517214
16 邓璐, 肖克晶, 姜丹, 等 基于图同构网络的多模态虚假新闻检测[J]. 计算机科学与应用, 2025, 15 (4): 124- 133
DENG Lu, XIAO Kejing, JIANG Dan, et al Multimodal fake news detection utilizing graph isomorphism networks[J]. Computer Science and Application, 2025, 15 (4): 124- 133
doi: 10.12677/csa.2025.154085
17 许莉芬, 曹霑懋, 郑明杰, 等 基于用户权威度和多特征融合的微博谣言检测模型[J]. 计算机工程与科学, 2024, 46 (4): 752- 760
XU Lifen, CAO Zhanmao, ZHENG Mingjie, et al A microblog rumor detection model based on user authority and multi-feature fusion[J]. Computer Engineering and Science, 2024, 46 (4): 752- 760
doi: 10.3969/j.issn.1007-130X.2024.04.020
18 SUN Y, WANG S, TANG X, et al. Node injection attacks on graphs via reinforcement learning [EB/OL]. (2019–09–14)[2025–05–29]. https://arxiv.org/pdf/1909.06543.
19 ZOU X, ZHENG Q, DONG Y, et al. TDGIA: effective injection attacks on graph neural networks [C]// Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. [S.l.]: ACM, 2021: 2461–2471.
20 RAMAN M, CHAN A, AGARWAL S, et al. Learning to deceive knowledge graph augmented models via targeted perturbation [C]// Proceedings of the International Conference on Learning Representations. Vienna: [s.n.], 2021: 1–13.
21 ZHANG M, WANG X, SHI C, et al. Minimum topology attacks for graph neural networks [C]// Proceedings of the ACM Web Conference 2023. Austin: ACM, 2023: 630–640.
22 DOU Y, MA G, YU P S, et al. Robust spammer detection by Nash reinforcement learning [C]// Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. [S.l.]: ACM, 2020: 924–933.
23 HE B, AHAMAD M, KUMAR S. PETGEN: personalized text generation attack on deep sequence embedding-based classification models [C]// Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. [S.l.]: ACM, 2021: 575–584.
24 HORNE B D, NØRREGAARD J, ADALI S Robust fake news detection over time and attack[J]. ACM Transactions on Intelligent Systems and Technology, 2020, 11 (1): 1- 23
doi: 10.1145/3363818
25 ZENG X, PENG H, LI A. Robustness evaluation of graph-based news detection using network structural information [C]// Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining. [S.l.]: ACM, 2025: 3716–3727.
26 SHU K, MAHUDESWARAN D, WANG S, et al FakeNewsNet: a data repository with news content, social context, and spatiotemporal information for studying fake news on social media[J]. Big Data, 2020, 8 (3): 171- 188
doi: 10.1089/big.2020.0062
27 MA J, GAO W, MITRA P, et al. Detecting rumors from microblogs with recurrent neural networks [C]// Proceedings of the International Joint Conference on Artificial Intelligence. [S.l.]: AAAI Press, 2016: 3818–3824.
28 PENNINGTON J, SOCHER R, MANNING C. GloVe: global vectors for word representation [C]// Proceedings of the 2014 Conference on Empirical Methods in Natural Language Processing (EMNLP). Doha: Association for Computational Linguistics, 2014: 1532–1543.
29 WANG L, WANG Z, WU L, et al. Bots shield fake news: adversarial attack on user engagement based fake news detection [C]// Proceedings of the 33rd ACM International Conference on Information and Knowledge Management. Boise: ACM, 2024: 2369–2378.
30 KIPF T N, WELLING M. Semi-supervised classification with graph convolutional networks [EB/OL]. (2017–02–22)[2025–05–29]. https://arxiv.org/pdf/1609.02907.
31 VELICKOVIC P, CUCURULL G, CASANOVA A, et al. Graph attention networks [EB/OL]. (2018–02–04)[2025–05–29]. https://arxiv.org/pdf/1710.10903.
32 JIN D, ZHANG Y, FENG B, et al Backdoor attack on propagation-based rumor detectors[J]. Proceedings of the AAAI Conference on Artificial Intelligence, 2025, 39 (17): 17680- 17688
doi: 10.1609/aaai.v39i17.33944
33 WANIEK M, MICHALAK T P, RAHWAN T, et al. Hiding individuals and communities in a social network [EB/OL]. (2016–08–01)[2025–05–29]. https://arxiv.org/pdf/1608.00375.
34 LI J, XIE T, CHEN L, et al Adversarial attack on large scale graph[J]. IEEE Transactions on Knowledge and Data Engineering, 2023, 35 (1): 82- 95
doi: 10.1109/tkde.2021.3078755
[1] 王彦乐,张瑞峰,李锵. 融合全局信息和对比学习的图神经网络推荐模型[J]. 浙江大学学报(工学版), 2026, 60(2): 351-359.
[2] 孙月,张兴兰. 基于双重引导的目标对抗攻击方法[J]. 浙江大学学报(工学版), 2026, 60(1): 81-89.
[3] 罗伟,颜作涛,关佳浩,韩建. 基于改进SegFormer的太阳能电池缺陷分割模型[J]. 浙江大学学报(工学版), 2024, 58(12): 2459-2468.
[4] 赵嘉墀,王天琪,曾丽芳,邵雪明. 基于GRU的扑翼非定常气动特性快速预测[J]. 浙江大学学报(工学版), 2023, 57(6): 1251-1256.
[5] 许佳辉,王敬昌,陈岭,吴勇. 基于图神经网络的地表水水质预测模型[J]. 浙江大学学报(工学版), 2021, 55(4): 601-607.
[6] 李诺,郭斌,刘琰,景瑶,於志文. 神经协同过滤智能商业选址方法[J]. 浙江大学学报(工学版), 2019, 53(9): 1788-1794.