{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T12:53:40Z","timestamp":1743080020244,"version":"3.40.3"},"publisher-location":"Cham","reference-count":31,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031402821"},{"type":"electronic","value":"9783031402838"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-40283-8_18","type":"book-chapter","created":{"date-parts":[[2023,8,8]],"date-time":"2023-08-08T23:02:48Z","timestamp":1691535768000},"page":"203-217","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Black-Box Adversarial Attack on\u00a0Graph Neural Networks Based on\u00a0Node Domain Knowledge"],"prefix":"10.1007","author":[{"given":"Qin","family":"Sun","sequence":"first","affiliation":[]},{"given":"Zheng","family":"Yang","sequence":"additional","affiliation":[]},{"given":"Zhiming","family":"Liu","sequence":"additional","affiliation":[]},{"given":"Quan","family":"Zou","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2023,8,9]]},"reference":[{"key":"18_CR1","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 39\u201357. IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"18_CR2","doi-asserted-by":"crossref","unstructured":"Chang, H., et al.: A restricted black-box adversarial framework towards attacking graph embedding models. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 34, pp. 3389\u20133396 (2020)","DOI":"10.1609\/aaai.v34i04.5741"},{"key":"18_CR3","doi-asserted-by":"crossref","unstructured":"Chen, Y., et al.: Practical attacks against graph-based clustering. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 1125\u20131142 (2017)","DOI":"10.1145\/3133956.3134083"},{"key":"18_CR4","unstructured":"Dai, H., et al.: Adversarial attack on graph structured data. In: International Conference on Machine Learning, pp. 1115\u20131124. PMLR (2018)"},{"key":"18_CR5","unstructured":"Fang, Z., Tan, S., Wang, Y., Lu, J.: Elementary subgraph features for link prediction with neural networks. IEEE Trans. Knowl. Data Eng. (2021)"},{"key":"18_CR6","unstructured":"Gao, H., Ji, S.: Graph U-Nets. In: International Conference on Machine Learning, pp. 2083\u20132092. PMLR (2019)"},{"key":"18_CR7","unstructured":"Hamilton, W., Ying, Z., Leskovec, J.: Inductive representation learning on large graphs. In: Advances in Neural Information Processing Systems, vol. 30 (2017)"},{"key":"18_CR8","doi-asserted-by":"publisher","DOI":"10.1016\/j.is.2022.102154","volume":"114","author":"Y Hao","year":"2023","unstructured":"Hao, Y., Meng, G., Wang, J., Zong, C.: A detection method for hybrid attacks in recommender systems. Inf. Syst. 114, 102154 (2023)","journal-title":"Inf. Syst."},{"key":"18_CR9","doi-asserted-by":"crossref","unstructured":"Hsieh, I.C., Li, C.T.: Netfense: adversarial defenses against privacy attacks on neural networks for graph data. IEEE Trans. Knowl. Data Eng. (2021)","DOI":"10.1109\/TKDE.2021.3087515"},{"key":"18_CR10","unstructured":"Kipf, T.N., Welling, M.: Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907 (2016)"},{"key":"18_CR11","doi-asserted-by":"crossref","unstructured":"Li, H., Di, S., Li, Z., Chen, L., Cao, J.: Black-box adversarial attack and defense on graph neural networks. In: 2022 IEEE 38th International Conference on Data Engineering (ICDE), pp. 1017\u20131030. IEEE (2022)","DOI":"10.1109\/ICDE53745.2022.00081"},{"key":"18_CR12","doi-asserted-by":"crossref","unstructured":"Ma, J., Deng, J., Mei, Q.: Adversarial attack on graph neural networks as an influence maximization problem. In: Proceedings of the Fifteenth ACM International Conference on Web Search and Data Mining, pp. 675\u2013685 (2022)","DOI":"10.1145\/3488560.3498497"},{"key":"18_CR13","unstructured":"Ma, J., Ding, S., Mei, Q.: Towards more practical adversarial attacks on graph neural networks. In: Advances in Neural Information Processing Systems, vol. 33, pp. 4756\u20134766 (2020)"},{"key":"18_CR14","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"key":"18_CR15","doi-asserted-by":"crossref","unstructured":"Mu, J., Wang, B., Li, Q., Sun, K., Xu, M., Liu, Z.: A hard label black-box adversarial attack against graph neural networks. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 108\u2013125 (2021)","DOI":"10.1145\/3460120.3484796"},{"key":"18_CR16","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1109\/TNN.2008.2005605","volume":"20","author":"F Scarselli","year":"2008","unstructured":"Scarselli, F., Gori, M., Tsoi, A.C., Hagenbuchner, M., Monfardini, G.: The graph neural network model. IEEE Trans. Neural Networks 20, 61\u201380 (2008)","journal-title":"IEEE Trans. Neural Networks"},{"key":"18_CR17","doi-asserted-by":"crossref","unstructured":"Shen, Y., He, X., Han, Y., Zhang, Y.: Model stealing attacks against inductive graph neural networks. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 1175\u20131192. IEEE (2022)","DOI":"10.1109\/SP46214.2022.9833607"},{"key":"18_CR18","doi-asserted-by":"crossref","unstructured":"Sun, Y., Wang, S., Tang, X., Hsieh, T.Y., Honavar, V.: Adversarial attacks on graph neural networks via node injections: A hierarchical reinforcement learning approach. In: Proceedings of the Web Conference 2020, pp. 673\u2013683 (2020)","DOI":"10.1145\/3366423.3380149"},{"key":"18_CR19","first-page":"1","volume":"20","author":"H Suyeon","year":"2023","unstructured":"Suyeon, H., et al.: A fast and flexible FPGA-based accelerator for natural language processing neural networks. ACM Trans. Archit. Code Opt. 20, 1\u201324 (2023)","journal-title":"ACM Trans. Archit. Code Opt."},{"key":"18_CR20","unstructured":"Veli\u010dkovi\u0107, P., Cucurull, G., Casanova, A., Romero, A., Lio, P., Bengio, Y.: Graph attention networks. arXiv preprint arXiv:1710.10903 (2017)"},{"key":"18_CR21","doi-asserted-by":"crossref","unstructured":"Xiao, Y., Sun, Z., Shi, G., Niyato, D.: Imitation learning-based implicit semantic-aware communication networks: Multi-layer representation and collaborative reasoning. IEEE J. Sel. Areas Commun. (2022)","DOI":"10.1109\/JSAC.2022.3229419"},{"key":"18_CR22","doi-asserted-by":"crossref","unstructured":"Xu, J., et al.: Blindfolded attackers still threatening: strict black-box adversarial attacks on graphs. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 36, pp. 4299\u20134307 (2022)","DOI":"10.1609\/aaai.v36i4.20350"},{"key":"18_CR23","doi-asserted-by":"crossref","unstructured":"Xu, K., et al.: Topology attack and defense for graph neural networks: an optimization perspective. arXiv preprint arXiv:1906.04214 (2019)","DOI":"10.24963\/ijcai.2019\/550"},{"key":"18_CR24","unstructured":"Xu, K., Hu, W., Leskovec, J., Jegelka, S.: How powerful are graph neural networks? arXiv preprint arXiv:1810.00826 (2018)"},{"key":"18_CR25","unstructured":"Xu, X., Yu, Y., Li, B., Song, L., Liu, C., Gunter, C.: Characterizing malicious edges targeting on graph neural networks. https:\/\/openreview.net\/forum?id=HJxdAoCcYX (2019)"},{"key":"18_CR26","doi-asserted-by":"publisher","first-page":"206","DOI":"10.1109\/TIFS.2022.3219342","volume":"18","author":"X Yin","year":"2022","unstructured":"Yin, X., Lin, W., Sun, K., Wei, C., Chen, Y.: A 2 s 2-GNN: rigging GNN-based social status by adversarial attacks in signed social networks. IEEE Trans. Inf. Forensics Secur. 18, 206\u2013220 (2022)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"18_CR27","unstructured":"Yu, Z., Gao, H.: Molecular representation learning via heterogeneous motif graph neural networks. In: International Conference on Machine Learning, pp. 25581\u201325594. PMLR (2022)"},{"key":"18_CR28","doi-asserted-by":"publisher","first-page":"701","DOI":"10.1109\/TIFS.2020.3021899","volume":"16","author":"H Zhang","year":"2020","unstructured":"Zhang, H., Avrithis, Y., Furon, T., Amsaleg, L.: Walking on the edge: fast, low-distortion adversarial examples. IEEE Trans. Inf. Forensics Secur. 16, 701\u2013713 (2020)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"18_CR29","doi-asserted-by":"publisher","first-page":"1667","DOI":"10.1109\/TIFS.2023.3246766","volume":"18","author":"J Zhang","year":"2023","unstructured":"Zhang, J., Peng, S., Gao, Y., Zhang, Z., Hong, Q.: APMSA: adversarial perturbation against model stealing attacks. IEEE Trans. Inf. Forensics Secur. 18, 1667\u20131679 (2023)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"18_CR30","doi-asserted-by":"publisher","first-page":"247","DOI":"10.1109\/TPAMI.2022.3141433","volume":"45","author":"Z Zhang","year":"2022","unstructured":"Zhang, Z., Wang, L., Wang, Y., Zhou, L., Zhang, J., Chen, F.: Dataset-driven unsupervised object discovery for region-based instance image retrieval. IEEE Trans. Pattern Anal. Mach. Intell. 45, 247\u2013263 (2022)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"18_CR31","doi-asserted-by":"crossref","unstructured":"Z\u00fcgner, D., Akbarnejad, A., G\u00fcnnemann, S.: Adversarial attacks on neural networks for graph data. In: Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pp. 2847\u20132856 (2018)","DOI":"10.1145\/3219819.3220078"}],"container-title":["Lecture Notes in Computer Science","Knowledge Science, Engineering and Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-40283-8_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,8]],"date-time":"2023-08-08T23:10:50Z","timestamp":1691536250000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-40283-8_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031402821","9783031402838"],"references-count":31,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-40283-8_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"9 August 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"KSEM","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Knowledge Science, Engineering and Management","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Guangzhou","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 August 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 August 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ksem2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.ksem2023.conferences.academy\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"395","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"114","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"30","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"29% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2,5","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}