skip to main content
10.1145/3637528.3671716acmconferencesArticle/Chapter ViewAbstractPublication PageskddConference Proceedingsconference-collections

Unsupervised Heterogeneous Graph Rewriting Attack via Node Clustering

Published: 24 August 2024 Publication History


Self-supervised learning (SSL) has become one of the most popular learning paradigms and has achieved remarkable success in the graph field. Recently, a series of pre-training studies on heterogeneous graphs (HGs) using SSL have been proposed considering the heterogeneity of real-world graph data. However, verification of the robustness of heterogeneous graph pre-training is still a research gap. Most existing researches focus on supervised attacks on graphs, which are limited to a specific scenario and will not work when labels are not available. In this paper, we propose a novel unsupervised heterogeneous graph rewriting attack via node clustering (HGAC) that can effectively attack HG pre-training models without using labels. Specifically, a heterogeneous edge rewriting strategy is designed to ensure the rationality and concealment of the attacks. Then, a tailored heterogeneous graph contrastive learning (HGCL) is used as a surrogate model. Moreover, we leverage node clustering results of the clean HGs as the pseudo-labels to guide the optimization of structural attacks. Extensive experiments exhibit powerful attack performances of our HGAC on various downstream tasks (i.e., node classification, node clustering, metapath prediction, and visualization) under poisoning attack and evasion attack.

Supplemental Material

MP4 File - Unsupervised Heterogeneous Graph Rewriting Attack via Node Clustering
Promotional Video of Unsupervised Heterogeneous Graph Rewriting Attack via Node Clustering


Aleksandar Bojchevski and Stephan Günnemann. 2019. Adversarial attacks on node embeddings via graph poisoning. In International Conference on Machine Learning. PMLR, 695--704.
Feng Chen and Daniel B Neill. 2014. Non-parametric scan statistics for event detection and forecasting in heterogeneous social media graphs. In Proceedings of the 20th ACM SIGKDD international conference on Knowledge discovery and data mining. 1166--1175.
Yongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma, Tongliang Liu, Bo Han, and James Cheng. 2022. Understanding and Improving Graph Injection Attack by Promoting Unnoticeability. In The Tenth International Conference on Learning Representations, ICLR 2022, Virtual Event, April 25--29, 2022. https://openreview. net/forum?id=wkMG8cdvh7-
Shaohua Fan, Junxiong Zhu, Xiaotian Han, Chuan Shi, Linmei Hu, Biyu Ma, and Yongliang Li. 2019. Metapath-guided heterogeneous graph neural network for intent recommendation. In Proceedings of the 25th ACM SIGKDD international conference on knowledge discovery & data mining. 2478--2486.
Xinyu Fu, Jiani Zhang, Ziqiao Meng, and Irwin King. 2020. MAGNN: Metapath Aggregated Graph Neural Network for Heterogeneous Graph Embedding. In Proceedings of TheWeb Conference 2020 (Taipei, Taiwan) (WWW'20). Association for Computing Machinery, New York, NY, USA, 2331--2341. 1145/3366423.3380297
Jiayan Guo, Lun Du, Wendong Bi, Qiang Fu, Xiaojun Ma, Xu Chen, Shi Han, Dongmei Zhang, and Yan Zhang. 2023. Homophily-oriented heterogeneous graph rewiring. In Proceedings of the ACM Web Conference 2023. 511--522.
Shifu Hou, Yujie Fan, Yiming Zhang, Yanfang Ye, Jingwei Lei, Wenqiang Wan, JiabinWang, Qi Xiong, and Fudong Shao. 2019. ??cyber: Enhancing robustness of android malware detection system against adversarial attacks on heterogeneous graph based model. In Proceedings of the 28th ACM international conference on information and knowledge management. 609--618.
Binbin Hu, Yuan Fang, and Chuan Shi. 2019. Adversarial learning on heterogeneous information networks. In Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining. 120--129.
Ziniu Hu, Yuxiao Dong, Kuansan Wang, and Yizhou Sun. 2020. Heterogeneous Graph Transformer. In WWW '20: The Web Conference 2020, Taipei, Taiwan, April 20--24, 2020. ACM / IW3C2, 2704--2710.
Yeonjun In, Kanghoon Yoon, and Chanyoung Park. 2023. Similarity Preserving Adversarial Graph Contrastive Learning. In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining (KDD '23). Association for Computing Machinery, New York, NY, USA, 867--878. 3580305.3599503
Eric Jang, Shixiang Gu, and Ben Poole. 2017. Categorical Reparameterization with Gumbel-Softmax. In 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24--26, 2017, Conference Track Proceedings.
Wei Jin, Yaxin Li, Han Xu, Yiqi Wang, and Jiliang Tang. 2020. Adversarial attacks and defenses on graphs: A review and empirical study. arXiv preprint arXiv:2003.00653 10, 3447556.3447566 (2020).
Baoyu Jing, Chanyoung Park, and Hanghang Tong. 2021. HDMI: High-Order Deep Multiplex Infomax. In Proceedings of the Web Conference 2021 (Ljubljana, Slovenia) (WWW '21). Association for Computing Machinery, New York, NY, USA, 2414--2424.
Diederik P Kingma and Jimmy Ba. 2014. Adam: A method for stochastic optimization. ICLR.
Udesh Kumarasinghe, Mohamed Nabeel, Kasun De Zoysa, Kasun Gunawardana, and Charitha Elvitigala. 2022. HeteroGuard: Defending Heterogeneous Graph Neural Networks against Adversarial Attacks. In 2022 IEEE International Conference on Data Mining Workshops (ICDMW). IEEE, 698--705.
Qing Li, Ziyue Wang, and Zehao Li. 2023. PAGCL: An unsupervised graph poisoned attack for graph contrastive learning model. Future Generation Computer Systems 149 (2023), 240--249.
Xiang Li, Danhao Ding, Ben Kao, Yizhou Sun, and Nikos Mamoulis. 2021. Leveraging meta-path contexts for classification in heterogeneous information networks. In 2021 IEEE 37th International Conference on Data Engineering (ICDE). IEEE, 912--923.
Zhe Li, Xinyi Tu, Yuping Chen, and Wenbin Lin. 2023. HetDDI: a pre-trained heterogeneous graph neural network model for drug--drug interaction prediction. Briefings in Bioinformatics 24, 6 (2023), bbad385.
Can Liu, Li Sun, Xiang Ao, Jinghua Feng, Qing He, and Hao Yang. 2021. Intentionaware heterogeneous graph attention networks for fraud transactions detection. In Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining. 3280--3288.
Zhiwei Liu, Yingtong Dou, Philip S Yu, Yutong Deng, and Hao Peng. 2020. Alleviating the inconsistency problem of applying graph neural network to fraud detection. In Proceedings of the 43rd international ACM SIGIR conference on research and development in information retrieval. 1569--1572.
Yao Ma, Suhang Wang, Tyler Derr, Lingfei Wu, and Jiliang Tang. 2021. Graph Adversarial Attack via Rewiring. In Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining (Virtual Event, Singapore) (KDD '21). Association for Computing Machinery, New York, NY, USA, 1161--1169.
Qiheng Mao, Zemin Liu, Chenghao Liu, and Jianling Sun. 2023. HINormer: Representation Learning On Heterogeneous Information Networks with Graph Transformer. In Proceedings of the ACM Web Conference 2023, WWW 2023, Austin, TX, USA, 30 April 2023 - 4 May 2023. ACM, 599--610. 3543507.3583493
Chanyoung Park, Donghyun Kim, Jiawei Han, and Hwanjo Yu. 2020. Unsupervised Attributed Multiplex Network Embedding. Proceedings of the AAAI Conference on Artificial Intelligence 34, 04, 5371--5378. aaai.v34i04.5985
Jiajie Peng, Yuxian Wang, Jiaojiao Guan, Jingyi Li, Ruijiang Han, Jianye Hao, Zhongyu Wei, and Xuequn Shang. 2021. An end-to-end heterogeneous graph representation learning-based framework for drug--target interaction prediction. Briefings in bioinformatics 22, 5 (2021).
Yiyue Qian, Yiming Zhang, Yanfang Ye, Chuxu Zhang, et al. 2021. Distilling meta knowledge on heterogeneous graph for illicit drug trafficker detection on social media. Advances in Neural Information Processing Systems 34 (2021), 26911--26923.
Yuxiang Ren, Bo Liu, Chao Huang, Peng Dai, Liefeng Bo, and Jiawei Zhang. 2019. Heterogeneous deep graph infomax. arXiv preprint arXiv:1911.08538 (2019).
Michael Sejr Schlichtkrull, Thomas N. Kipf, Peter Bloem, Rianne van den Berg, Ivan Titov, and Max Welling. 2018. Modeling Relational Data with Graph Convolutional Networks. In The Semantic Web - 15th International Conference, ESWC 2018, Heraklion, Crete, Greece, June 3--7, 2018, Proceedings (Lecture Notes in Computer Science, Vol. 10843). Springer, 593--607. 93417--4_38
Yu Shang, Yudong Zhang, Jiansheng Chen, Depeng Jin, and Yong Li. 2023. Transferable Structure-based Adversarial Attack of Heterogeneous Graph Neural Network. In Proceedings of the 32nd ACM International Conference on Information and Knowledge Management. 2188--2197.
Gen Shi, Yifan Zhu, Jian K. Liu, and Xuesong Li. 2023. HeGCL: Advance Self-Supervised Learning in Heterogeneous Graph-Level Representation. IEEE Transactions on Neural Networks and Learning Systems (2023), 1--12. https: //
Lichao Sun, Yingtong Dou, Carl Yang, Kai Zhang, JiWang, S Yu Philip, Lifang He, and Bo Li. 2022. Adversarial attack and defense on graph data: A survey. IEEE Transactions on Knowledge and Data Engineering (2022).
Shuchang Tao, Qi Cao, Huawei Shen, Junjie Huang, Yunfan Wu, and Xueqi Cheng. 2021. Single Node Injection Attack against Graph Neural Networks. In CIKM '21: The 30th ACM International Conference on Information and Knowledge Management, Virtual Event, Queensland, Australia, November 1 - 5, 2021. ACM, 1794--1803.
Yijun Tian, Kaiwen Dong, Chunhui Zhang, Chuxu Zhang, and Nitesh V Chawla. 2023. Heterogeneous graph masked autoencoders. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 37. 9997--10005.
Li Wang, Peipei Li, Kai Xiong, Jiashu Zhao, and Rui Lin. 2021. Modeling heterogeneous graph network on fraud detection: a community-based framework with attention mechanism. In Proceedings of the 30th ACM international conference on information & knowledge management. 1959--1968.
Xiao Wang, Houye Ji, Chuan Shi, Bai Wang, Yanfang Ye, Peng Cui, and Philip S. Yu. 2019. Heterogeneous Graph Attention Network. In The World Wide Web Conference, WWW 2019, San Francisco, CA, USA, May 13--17, 2019. ACM, 2022-- 2032.
Xiao Wang, Nian Liu, Hui Han, and Chuan Shi. 2021. Self-Supervised Heterogeneous Graph Neural Network with Co-Contrastive Learning. In Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining (Virtual Event, Singapore) (KDD '21). Association for Computing Machinery, New York, NY, USA, 1726--1736.
ZehongWang, Qi Li, Donghua Yu, Xiaolong Han, Xiao-Zhi Gao, and Shigen Shen. 2023. Heterogeneous graph contrastive multi-view learning. In Proceedings of the 2023 SIAM International Conference on Data Mining (SDM). SIAM, 136--144.
Kaidi Xu, Hongge Chen, Sijia Liu, Pin-Yu Chen, Tsui-Wei Weng, Mingyi Hong, and Xue Lin. 2019. Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective. In Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence, IJCAI 2019, Macao, China, August 10--16, 2019. 3961--3967.
Surong Yan, HaosenWang, Yixiao Li, ChunqiWu, Long Han, Chenglong Shi, and Ruilin Guo. 2023. Metapath-guided dual semantic-aware filtering for HIN-based recommendation. The Journal of Supercomputing (2023), 1--31.
Surong Yan, HaosenWang, Yixiao Li, Yuan Zheng, and Long Han. 2021. Attention aware metapath-based network embedding for HIN based recommendation. Expert Systems with Applications 174 (2021), 114601.
Xiaocheng Yang, Mingyu Yan, Shirui Pan, Xiaochun Ye, and Dongrui Fan. 2023. Simple and Efficient Heterogeneous Graph Neural Network. In Thirty-Seventh AAAI Conference on Artificial Intelligence, AAAI 2023, Thirty-Fifth Conference on Innovative Applications of Artificial Intelligence, IAAI 2023, Thirteenth Symposium on Educational Advances in Artificial Intelligence, EAAI 2023, Washington, DC, USA, February 7--14, 2023. AAAI Press, 10816--10824. AAAI.V37I9.26283
Yuning You, Tianlong Chen, Yongduo Sui, Ting Chen, Zhangyang Wang, and Yang Shen. 2020. Graph Contrastive Learning with Augmentations. In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, December 6--12, 2020, virtual. 3fe230348e9a12c13120749e3f9fa4cd-Abstract.html
Jianxiang Yu and Xiang Li. 2023. Heterogeneous Graph Contrastive Learning with Meta-path Contexts and Weighted Negative Samples. In Proceedings of the 2023 SIAM International Conference on Data Mining (SDM). SIAM, 37--45.
Xiangchi Yuan, Chunhui Zhang, Yijun Tian, Yanfang Ye, and Chuxu Zhang. 2023. Mitigating Severe Robustness Degradation on Graphs. In The Twelfth International Conference on Learning Representations.
Haoxi Zhan and Xiaobing Pei. 2021. Black-box Gradient Attack on Graph Neural Networks: Deeper Insights in Graph-based Attack and Defense. abs/2104.15061 (2021).
Chuxu Zhang, Dongjin Song, Chao Huang, Ananthram Swami, and Nitesh V. Chawla. 2019. Heterogeneous Graph Neural Network. In Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (Anchorage, AK, USA) (KDD '19). Association for Computing Machinery, New York, NY, USA, 793--803.
Chunhui Zhang, Yijun Tian, Mingxuan Ju, Zheyuan Liu, Yanfang Ye, Nitesh V. Chawla, and Chuxu Zhang. 2023. Chasing All-Round Graph Representation Robustness: Model, Training, and Optimization. In The Eleventh International Conference on Learning Representations, ICLR 2023, Kigali, Rwanda, May 1--5, 2023.
Mengmei Zhang, Xiao Wang, Meiqi Zhu, Chuan Shi, Zhiqiang Zhang, and Jun Zhou. 2022. Robust heterogeneous graph neural networks against adversarial attacks. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 36. 4363--4370.
Sixiao Zhang, Hongxu Chen, Xiangguo Sun, Yicong Li, and Guandong Xu. 2022. Unsupervised graph poisoning attack via contrastive loss back-propagation. In Proceedings of the ACM Web Conference 2022. 1322--1330.
Jianan Zhao, Xiao Wang, Chuan Shi, Zekuan Liu, and Yanfang Ye. 2020. Network schema preserving heterogeneous information network embedding. In International joint conference on artificial intelligence (IJCAI).
Kai Zhao, Qiyu Kang, Yang Song, Rui She, Sijie Wang, and Wee Peng Tay. 2023. Adversarial Robustness in Graph Neural Networks: A Hamiltonian Approach. In Advances in Neural Information Processing Systems 36: Annual Conference on Neural Information Processing Systems 2023, NeurIPS 2023, New Orleans, LA, USA, December 10 - 16, 2023.
Qinkai Zheng, Xu Zou, Yuxiao Dong, Yukuo Cen, Da Yin, Jiarong Xu, Yang Yang, and Jie Tang. 2021. Graph Robustness Benchmark: Benchmarking the Adversarial Robustness of Graph Machine Learning. In Proceedings of the Neural Information Processing Systems Track on Datasets and Benchmarks 1, NeurIPS Datasets and Benchmarks 2021, December 2021, virtual.
Guanghui Zhu, Mengyu Chen, Chunfeng Yuan, and Yihua Huang. [n. d.]. Simple and Efficient Partial Graph Adversarial Attack: A New Perspective. IEEE Transactions on Knowledge and Data Engineering ([n. d.]).
Yanqiao Zhu, Yichen Xu, Hejie Cui, Carl Yang, Qiang Liu, and Shu Wu. 2021. Structure-aware hard negative mining for heterogeneous graph contrastive learning. arXiv preprint arXiv:2108.13886 (2021).
Yanqiao Zhu, Yichen Xu, Feng Yu, Qiang Liu, Shu Wu, and Liang Wang. 2021. Graph Contrastive Learning with Adaptive Augmentation. In WWW '21: The Web Conference 2021, Virtual Event / Ljubljana, Slovenia, April 19--23, 2021. ACM / IW3C2, 2069--2080.
Daniel Zügner, Amir Akbarnejad, and Stephan Günnemann. 2018. Adversarial attacks on neural networks for graph data. In Proceedings of the 24th ACM SIGKDD international conference on knowledge discovery & data mining. 2847--2856.
Daniel Zügner and Stephan Günnemann. 2019. Adversarial Attacks on Graph Neural Networks via Meta Learning. In 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA, May 6--9, 2019.



Information & Contributors


Published In

cover image ACM Conferences
KDD '24: Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining
August 2024
6901 pages
Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected].



Association for Computing Machinery

New York, NY, United States

Publication History

Published: 24 August 2024


Request permissions for this article.

Check for updates

Author Tags

  1. adversarial attack
  2. graph contrastive learning
  3. heterogeneous graph neural network


  • Research-article

Funding Sources


KDD '24

Acceptance Rates

Overall Acceptance Rate 1,133 of 8,635 submissions, 13%

Upcoming Conference

KDD '25


Other Metrics

Bibliometrics & Citations


Article Metrics

  • 0
    Total Citations
  • 315
    Total Downloads
  • Downloads (Last 12 months)315
  • Downloads (Last 6 weeks)26
Reflects downloads up to 27 Feb 2025

Other Metrics


View Options

Login options

View options


View or Download as a PDF file.



View online with eReader.







Share this Publication link

Share on social media