Aug 2026· Neural Networks· Vol 205 Pt B, pp.
109513
· 0 citations· 47 references
Medicine
TL;DR
A novel transferable graph prompt attack, called TGPA, is proposed, which shifts the attack paradigm by introducing a hierarchical structural decoupling mechanism, which reduces the performance of pre-trained graph models with graph prompts by up to 28.9%, while guaranteeing robustness, stealthiness, and transferability.
Abstract
Graph prompt learning effectively mitigates the challenges associated with complex tuning processes, which can address the inherent inconsistency between downstream tasks and pre-training objectives. As graph prompts play a pivotal role in the inference of graph pre-trained models, the malicious attacks on graph prompts can substantially compromise the predictive accuracy of model. Unfortunately, existing graph adversarial attacks largely rely on single-scale topological perturbations, which overlook the multi-granular structural dependencies that graph prompts use to transfer knowledge. Consequently, they fail to maintain transferability across different downstream tasks. To alleviate this issue, we propose a novel transferable graph prompt attack, called TGPA, which shifts the attack paradigm by introducing a hierarchical structural decoupling mechanism. Specifically, the hierarchical subgraph information extraction is first employed to obtain the global information and local information. Subsequently, the corresponding node selection based on local and global knowledge is utilized to identify the target nodes. Finally, the perturbations between features and structures are applied to generate malicious samples through the selection of target nodes, which can be utilized to mislead the graph prompt learning. Large-scale experiments across multiple popular graph datasets demonstrate that TGPA successfully reduces the performance of pre-trained graph models with graph prompts by up to 28.9%, while guaranteeing robustness, stealthiness, and transferability.
A graph embedding-based error detection method via contrastive learning that treats each triple as a hyper-node, enabling data-driven modeling of semantic consistency and integrates a semantic matching-based scoring mechanism with a contrastive learning-based scoring mechanism.
Gaojun Shan, Liping Cong, Xiaohong Sun et al.· International journal of sof...· 0 citations
Advanced Persistent Threat (APT) attacks pose a critical challenge to modern systems, as their stealthy, multi-stage nature renders conventional detection methods ineffective. While provenance graphs provide rich behavioral context for attack investigation, attack-relevant evidence is often sparse and embedded in large volumes of routine system activity, making full-graph learning both computationally expensive and difficult to correlate over long attack sequences. We present TGL-APT, an adaptive investigation framework built on the observation that attack-relevant information is non-uniformly distributed and often mediated by structurally influential or behaviorally distinctive entities, which we characterize as information-bottleneck nodes. TGL-APT combines three complementary components: (1) information-bottleneck-guided graph distillation that suppresses provenance redundancy while bounding structural distortion and preserving causal reachability; (2) adaptive temporal graph learning that continuously refines the core node set as node relevance evolves; and (3) cross-spatiotemporal attack fingerprint alignment that associates fragmented suspicious activities across different entities and time windows. Finally, causal expansion and stage characterization reconstruct coherent attack processes for investigation. Experiments on three DARPA E3 datasets show F1-scores of 95.7%, 90.9%, and 88.9%, while reducing training time, detection latency, and memory usage by approximately 39%, 33%, and 22%, respectively, compared with KAIROS. These results demonstrate that TGL-APT effectively balances detection performance, computational efficiency, and investigation capability for provenance-based APT analysis.
Jing Chen, Ayong Ye, Yuanhuang Liu et al.· 0 citations
Hierarchical Interaction MOdeling for zero-shot generalist GAD enables anomaly detection across diverse graph domains without retraining or access to target-domain supervision by modeling the evolutionary trajectories of node representations across hierarchical structural depths, thereby capturing interaction patterns that exhibit strong cross-domain stability.
Xiangping Zheng, Xuan Feng, Bo Wu et al.· Proceedings of the 32nd ACM...· 0 citations
LoSplit is proposed, the first training-time defense framework in graph that leverages this early-stage loss drift to accurately split target nodes, and dynamically selects epochs with maximal loss divergence, clusters target nodes via Gaussian Mixture Models, and applies a Decoupling-Forgetting strategy to break the association between target nodes and malicious label.
Di Jin, Yuxiang Zhang, Bingdao Feng et al.· Neural Information Processin...· 4 citations