Skip to content

Attacking Graph Foundation Models Through Their Shared Representation

Jul 2026 · arXiv.org · Vol abs/2607.18567 · 0 citations · 39 references
Computer Science

TL;DR

This work attacks the alignment layer, the component that separates a graph foundation model from a graph neural network, and shows it is a distinct attack surface that prior work has not studied.

Abstract

A graph foundation model generalizes across graph domains by mapping every input into one shared representation before any task reasoning. We call this map the alignment layer, the component that separates a graph foundation model from a graph neural network, and we show it is a distinct attack surface that prior work has not studied. We attack it at inference time, with no access to training, on six public models spanning spectral tokenizers, text embedding spaces, and a discrete codebook. A directed representation-space perturbation collapses every model, but at a budget comparable to the representation norm a plain graph network also needs, with one exception: OpenGraph, whose spectral tokenizer collapses at a fifth of that budget, an alignment-specific fragility a plain network does not share and which a same-representation control traces to the tokenizer rather than the decoder. A realizable input-space attack that edits edges, features, or text removes at least half the correct predictions on three of the six models at peak. How much of this fragility an input-access attacker realizes tracks how directly the decoder reads the representation, and not the clean accuracy a task leaves; we measure this carrier gain structurally from the decoder's local Lipschitz sensitivity, and report clean-accuracy headroom as a within-model ordering heuristic that does not survive on realizable attacks.

View source

Similar papers

Preprint Aug 2026

Agentic Graph Token Reasoning

This work introduces agentic graph token reasoning, which recasts graph tokenization as part of the reasoning process itself and pushes LLM-based graph analysis from static graph-token encoders towards a graph-native agent paradigm.

Zhuo Peng, Yi Yang · 0 citations
Preprint Aug 2026

Trojaning the Alignment: Stealthy Backdoor Attacks against Graph Foundation Models

STAG is proposed, a stealthy trojan attack framework designed for the graph-language alignment interface of GFMs on TAGs that realizes trigger nodes as readable text through candidate retrieval and regularizes the trigger-attached subgraph so that its local structure remains close to the original subgraph.

Min-hua Lin, Zhi-Cheng Gao, Yilong Wang et al. · 0 citations
Open access Sep 2026

Graph Neural Networks with Code Structure Embeddings for Model-Agnostic Multi-Class Detection of AI-Generated Programs

GraphCSE, a detector for unseen generators of AI-generated code, represents a program as a heterogeneous code graph with four edge relations and fuses structural and semantic node channels through a learned per-node gate before relation-aware graph attention, restoring model-agnostic detection.

Dr.Hayder Kareem Algabri · 0 citations
#artificial intelligence Preprint Sep 2026

GTA: Graph Theory Agent and Benchmark for Algorithmic Graph Reasoning with LLMs

The Graph Theory Agent (GTA), which pairs a preference-trained representation selector with plan-and-decompose scaffolding around a frozen executor LLM, is proposed, which lifts Phi-4 from 53.5% to 69.1% on the benchmark's easy split and from 33.0% to 41.5% on its hard split.

Zi-Xiang Xu, Yan-Bo Wang, Chenxi Wang et al. · 2 citations · ⚡1
Preprint Aug 2026

Unifying Graph Neural Networks Through a Common Layer Equation

A common layer equation is introduced that represents covered architectures through seven components: an update domain, channel set, propagation bank, per-channel message maps, channel-fusion operator, ego/residual map, and update map, which exposes the empirical inverse problem of mapping measurable graph and task pro...

S. Navuluru, Siddhartha Shankar Das, B. Ni et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.