H3NI: Non-target-specific Node Injection Attacks on Hypergraph Neural Networks Via Genetic Algorithm

Heyuan Shi,Binqi Zeng,Ruishi Yu,Yulin Yang,Zijian Zouxia,Chao Hu,Ronghua Shi
DOI: https://doi.org/10.1016/j.neucom.2024.128746
IF: 6
2025-01-01
Neurocomputing
Abstract:Node injection attack is widely used in graph neural networks (GNNs) attacks, which misleads GNNs by injecting nodes. Though hypergraph neural networks (HNNs) are an extension of GNNs, node injection attacks have not yet been studied in HNNs. Since each edge of a hypergraph can connect more than two nodes, existing node injection methods designed for GNNs cannot effectively select the hyperedges connected to the injected nodes when applied to hypergraphs. In this paper, we propose a Hypergraph Neural Network Node I njection attack method called H3NI, which utilizes a genetic algorithm and a predefined budget model to implement the first black-box node injection framework designed for HNNs attacks. We conducted experiments on the datasets of Cora co-authorship and co-citation. Experimental results show the effectiveness and superior performance of H3NI in attacking HNNs, which reduces the model accuracy by 18%-20% within 5% of the total injected nodes and achieves a 2-4X improvement compared to existing gradient-based node injection methods.
What problem does this paper attempt to address?