ZeroGAR:零样本图模型对抗鲁棒性基准测试
ZeroGAR: Benchmarking the Adversarial Robustness of Zero-Shot Graph Models
浏览论文内容
中文总结 AI 辅助
针对零样本图模型在未见目标图上对抗攻击鲁棒性未知的问题,提出首个系统基准ZeroGAR,评估13个模型在8个数据集上多种攻击下的表现,发现强干净性能不保证鲁棒性,并揭示模型特定脆弱模式及防御方法失效现象。
中文摘要 AI 辅助
零样本图模型(ZGMs)从源图学习可迁移知识,并直接应用于未见过的目标图而无需任何适配,已取得令人瞩目的性能并吸引了广泛关注。尽管此类模型层出不穷,现有ZGMs主要在干净图上进行评估,而现有的图鲁棒性基准主要关注监督设置,导致一个基本问题在很大程度上未被探索:当ZGMs的未见目标图暴露于对抗性操纵时,其鲁棒性如何?在本文中,我们通过提出ZeroGAR来回答这一问题,这是首个系统评估ZGMs对抗鲁棒性的基准。ZeroGAR在4个领域的8个图数据集上评估了来自3种不同范式的13个代表性ZGMs,涵盖了在结构攻击、文本攻击和节点注入攻击下,在域内和跨域迁移场景中的表现,并设置了多种扰动预算。它进一步探究了现有图防御方法在零样本设置下是否仍然有效。大量实验表明,强大的干净零样本性能并不能保证对抗鲁棒性,并得出三个关键发现:(1)脆弱性模式与模型预测机制相关:基于GNN的方法对结构攻击和节点注入攻击尤为脆弱,而基于LLM的方法对文本攻击更为脆弱;(2)更强的LLM骨干引入了结构-文本鲁棒性权衡;(3)现有的图防御方法并不能一致地提升零样本鲁棒性,且可能损害干净性能。我们希望ZeroGAR能够促进快速、公平的评估,并激发ZGM安全领域的进一步创新研究。
英文摘要
Zero-shot graph models (ZGMs), which learn transferable knowledge from source graphs and directly apply to unseen target graphs without any adaptation, have achieved promising performance and attracted considerable attention. Despite their proliferation, existing ZGMs are predominantly evaluated on clean graphs, while existing graph robustness benchmarks mainly focus on supervised settings, leaving a fundamental question largely unexplored: How robust are ZGMs when their unseen target graphs are exposed to adversarial manipulation? In this paper, we answer this question by proposing ZeroGAR, the first systematic benchmark for evaluating the adversarial robustness of ZGMs. ZeroGAR evaluates 13 representative ZGMs from 3 different paradigms on 8 graph datasets across 4 domains, covering both in-domain and cross-domain transfer under structural, textual, and node injection attacks with multiple perturbation budgets. It further investigates whether existing graph defenses remain effective in the zero-shot setting. Extensive experiments reveal that strong clean zero-shot performance does not guarantee adversarial robustness, with three key findings: (1) Vulnerability patterns are related to model prediction mechanisms: GNN-based methods are particularly vulnerable to structural and node injection attacks, whereas LLM-based methods are more vulnerable to textual attacks; (2) Stronger LLM backbones introduce a structure-text robustness trade-off; (3) Existing graph defense methods do not consistently improve zero-shot robustness and may compromise clean performance. We hope that ZeroGAR will facilitate rapid, equitable evaluation and inspire further innovative research in ZGM security.