Adversarial Techniques in Graph Neural Networks
Summary
Graph neural networks (GNNs) have become a cornerstone of machine learning for relational data, powering applications from social‐network analysis to molecular property prediction. However, their reliance on graph structure and node features renders them vulnerable to adversarial manipulation. Adversarial techniques in this context encompass both attack strategies—where perturbations to graph topology or attributes degrade model performance or achieve targeted misclassification—and corresponding defences that seek to restore robustness. Attacks are commonly classified into poisoning attacks, which corrupt the training graph; evasion attacks, which exploit the trained model at inference; and backdoor or injection attacks, which implant hidden triggers that activate under specific conditions. Defences range from adversarial training, where models are exposed to pessimistic perturbations during optimisation, to graph sanitisation and robust aggregation schemes that detect or neutralise malicious changes. Recent work further explores certified defences that provide provable guarantees under bounded perturbations, as well as preprocessing techniques that transform input graphs to suppress adversarial noise. Together, these advances highlight an evolving arms race between increasingly sophisticated attacks—often operating under black‐box constraints—and versatile defensive mechanisms that must balance computational efficiency, theoretical rigour and real‐world applicability.
Research from Nature Portfolio
No recent Nature Portfolio content available.
Adversarial Techniques in Graph Neural Networks publication trend
The graph below shows the total number of articles in adversarial techniques in graph neural networks across all publications each year (not limited to Nature Index journals).
Technical terms
Adversarial attack: A deliberate perturbation of graph structure or node features to degrade model performance or force incorrect outputs.
Poisoning attack: An attack during the training phase where the adversary corrupts the input graph to influence the learned parameters.
Evasion attack: A runtime attack that subtly alters test‐time inputs to mislead a fixed, trained model.
Backdoor attack: A concealed manipulation that causes the model to behave normally except in the presence of a specific trigger pattern.
Adversarial training: A defence mechanism that augments training with worst‐case perturbations to improve model robustness.
Certified defence: A method that provides formal guarantees of performance under bounded adversarial perturbations.
References
- A graph transformer defence against graph perturbation by a flexible-pass filter. Information Fusion (2024).
- Graph neural networks: a survey on the links between privacy and security. Artificial Intelligence Review (2024).
- Imperceptible graph injection attack on graph neural networks. Complex & Intelligent Systems (2023).
About these summaries
This Nature Research Intelligence Topic summary is created with the cited references and a large language model. We take care to ground generated text with facts, and have systems in place to gain human feedback on the overall quality of the process in line with our AI principles. We strive to create accurate and useful summaries for people unfamiliar with the research topic and that supports this goal. These pages are a beta release and will be updated as we learn how best to help people gain value from a research topic summary.
Turn complex research questions into confident strategic decisions
When you're under pressure to set direction, justify investment, or understand your competitive position, you need more than raw data — you need trusted insights you can act on.
Benchmark your performance against global peers using robust, methodologically sound analysis.
Combine quantitative metrics with qualitative expert insight to uncover strengths, gaps and emerging opportunities.
Gain tailored, decision-ready recommendations aligned to your strategic priorities.
Talk to us to learn more about our data dashboards and bespoke strategy reports.
Grow research skills, confidence and careers with training built for every stage of the research lifecycle.
Developed with Nature Portfolio journal Editors and internationally renowned experts. Discover three ways to learn:
Self-paced, online courses in convenient bite-sized units, covering key skills across scientific writing, publishing, grant writing, data analysis, and more.
Expert trainer-led workshops with hands-on exercises and real-time feedback across core research skills, delivered via interactive group sessions.
Editor-led workshops combining core principles in writing and publishing, personalised 1:1 feedback from Nature Portfolio Editors and hands-on exercises.
Explore course catalogues and workshop agendas, enquire about the options or request institutional pricing.