{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T14:45:27Z","timestamp":1773153927466,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":74,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,5,13]],"date-time":"2024-05-13T00:00:00Z","timestamp":1715558400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100006374","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202402,61906161"],"award-info":[{"award-number":["62202402,61906161"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Startup Grant (Tier 1) for New Academics of Hong Kong Baptist University under Grant AY2020\/21"},{"name":"Guangdong Basic and Applied Basic Research Foundation","award":["2022A1515011583,2023A1515011562"],"award-info":[{"award-number":["2022A1515011583,2023A1515011562"]}]},{"name":"Hong Kong Research Grants Council Early Career Scheme","award":["22202423"],"award-info":[{"award-number":["22202423"]}]},{"name":"Germany\/Hong Kong Joint Research Scheme sponsored by the Research Grants Council of Hong Kong and the German Academic Exchange Service of Germany","award":["G-HKBU203\/22"],"award-info":[{"award-number":["G-HKBU203\/22"]}]},{"name":"One-Off Tier 2 Start-Up Grant (2020\/2021) of Hong Kong Baptist University","award":["RC-OFSGT2\/20-21\/COMM\/002"],"award-info":[{"award-number":["RC-OFSGT2\/20-21\/COMM\/002"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,5,13]]},"DOI":"10.1145\/3589334.3648139","type":"proceedings-article","created":{"date-parts":[[2024,5,8]],"date-time":"2024-05-08T07:08:13Z","timestamp":1715152093000},"page":"4512-4522","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Message Injection Attack on Rumor Detection under the Black-Box Evasion Setting Using Large Language Model"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3635-8154","authenticated-orcid":false,"given":"Yifeng","family":"Luo","sequence":"first","affiliation":[{"name":"Department of Interactive Media, Hong Kong Baptist University, Hong Kong, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9652-3321","authenticated-orcid":false,"given":"Yupeng","family":"Li","sequence":"additional","affiliation":[{"name":"Department of Interactive Media, Hong Kong Baptist University, Hong Kong, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8198-6227","authenticated-orcid":false,"given":"Dacheng","family":"Wen","sequence":"additional","affiliation":[{"name":"Department of Computer Science, The University of Hong Kong, Hong Kong, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0427-977X","authenticated-orcid":false,"given":"Liang","family":"Lan","sequence":"additional","affiliation":[{"name":"Department of Interactive Media, Hong Kong Baptist University, Hong Kong, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,5,13]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.3390\/fi12050087"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2187836.2187907"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5393"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3264418"},{"key":"e_1_3_2_1_5_1","volume-title":"Proc. ICML.","author":"Bojchevski Aleksandar","year":"2019","unstructured":"Aleksandar Bojchevski and Stephan G\u00fcnnemann. 2019. Adversarial attacks on node embeddings via graph poisoning. In Proc. ICML."},{"key":"e_1_3_2_1_6_1","volume-title":"Proc. ICLR.","author":"Chen Canyu","year":"2024","unstructured":"Canyu Chen and Kai Shu. 2024. Can LLM-generated misinformation be detected?. In Proc. ICLR."},{"key":"e_1_3_2_1_7_1","volume-title":"Proc. ICLR.","author":"Chen Yongqiang","year":"2022","unstructured":"Yongqiang Chen, Han Yang, Yonggang Zhang, Kaili Ma, Tongliang Liu, Bo Han, and James Cheng. 2022. Understanding and improving graph injection attack by promoting unnoticeability. In Proc. ICLR."},{"key":"e_1_3_2_1_8_1","volume-title":"Understanding convolutions on graphs. Distill","author":"Daigavane Ameya","year":"2021","unstructured":"Ameya Daigavane, Balaraman Ravindran, and Gaurav Aggarwal. 2021. Understanding convolutions on graphs. Distill (2021)."},{"key":"e_1_3_2_1_9_1","volume-title":"Proc. NAACL-HLT.","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018. BERT: Pre-training of deep bidirectional transformers for language understanding. In Proc. NAACL-HLT."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3404835.3462990"},{"key":"e_1_3_2_1_11_1","volume-title":"Proc. ICLR.","author":"Goodfellow Ian J","year":"2015","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In Proc. ICLR."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1093\/isq\/sqx015"},{"key":"e_1_3_2_1_13_1","volume-title":"Proc. NeurIPS.","author":"Hamilton Will","year":"2017","unstructured":"Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. In Proc. NeurIPS."},{"key":"e_1_3_2_1_14_1","volume-title":"Proc. ICLR Workshops LLD.","author":"Han Sooji","year":"2019","unstructured":"Sooji Han, Jie Gao, and Fabio Ciravegna. 2019. Data augmentation for rumor detection using context-sensitive neural language model with large-scale credibility corpus. In Proc. ICLR Workshops LLD."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.socnet.2010.11.003"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.4269\/ajtmh.20-0812"},{"key":"e_1_3_2_1_17_1","volume-title":"Disinformation detection: An evolving challenge in the age of LLMs. arXiv","author":"Jiang Bohan","year":"2023","unstructured":"Bohan Jiang, Zhen Tan, Ayushi Nirmal, and Huan Liu. 2023. Disinformation detection: An evolving challenge in the age of LLMs. arXiv (2023)."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2014.2339799"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-75762-5_33"},{"key":"e_1_3_2_1_20_1","volume-title":"Proc. ICLR.","author":"Kingma Diederik P","year":"2015","unstructured":"Diederik P Kingma and Jimmy Ba. 2015. ADAM: A method for stochastic optimization. In Proc. ICLR."},{"key":"e_1_3_2_1_21_1","volume-title":"Proc. ICLR.","author":"Kurakin Alexey","year":"2017","unstructured":"Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2017. Adversarial machine learning at scale. In Proc. ICLR."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3450016"},{"key":"e_1_3_2_1_23_1","volume-title":"Nature","volume":"521","author":"LeCun Yann","year":"2015","unstructured":"Yann LeCun, Yoshua Bengio, and Geoffrey Hinton. 2015. Deep learning. Nature, Vol. 521, 7553 (2015), 436--444."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.coling-main.473"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.786"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i4.25651"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11268"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/TASLP.2022.3140474"},{"key":"e_1_3_2_1_29_1","volume-title":"GCAN: Graph-aware co-attention networks for explainable fake news detection on social media. arXiv","author":"Lu Yi-Ju","year":"2020","unstructured":"Yi-Ju Lu and Cheng-Te Li. 2020. GCAN: Graph-aware co-attention networks for explainable fake news detection on social media. arXiv (2020)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN54540.2023.10191290"},{"key":"e_1_3_2_1_31_1","volume-title":"Proc. AAAI.","author":"Ma Jing","year":"2016","unstructured":"Jing Ma, Wei Gao, Prasenjit Mitra, Sejeong Kwon, Bernard J Jansen, Kam-Fai Wong, and Meeyoung Cha. 2016. Detecting rumors from microblogs with recurrent neural networks. In Proc. AAAI."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-1184"},{"key":"e_1_3_2_1_33_1","volume-title":"Proc. ICLR.","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks. In Proc. ICLR."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/BigMM50055.2020.00034"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1146\/annurev.soc.27.1.415"},{"key":"e_1_3_2_1_36_1","first-page":"1735","article-title":"Long short-term memory","volume":"9","author":"Short-Term Memory Long","year":"2010","unstructured":"Long Short-Term Memory. 2010. Long short-term memory. Neural Computation, Vol. 9, 8 (2010), 1735--1780.","journal-title":"Neural Computation"},{"key":"e_1_3_2_1_37_1","volume-title":"Adversarial learning in statistical classification: A comprehensive review of defenses against attacks. arXiv","author":"Miller David J","year":"2019","unstructured":"David J Miller, Zhen Xiang, and George Kesidis. 2019. Adversarial learning in statistical classification: A comprehensive review of defenses against attacks. arXiv (2019)."},{"key":"e_1_3_2_1_38_1","volume-title":"Proc. NeurIPS.","author":"Ouyang Long","year":"2022","unstructured":"Long Ouyang, Jeffrey Wu, Xu Jiang, Diogo Almeida, Carroll Wainwright, Pamela Mishkin, Chong Zhang, Sandhini Agarwal, Katarina Slama, Alex Ray, et al. 2022. Training language models to follow instructions with human feedback. In Proc. NeurIPS."},{"key":"e_1_3_2_1_39_1","volume-title":"Proc. ICLR.","author":"Pei Hongbin","year":"2020","unstructured":"Hongbin Pei, Bingzhe Wei, Kevin Chen-Chuan Chang, Yu Lei, and Bo Yang. 2020. GEOM-GCN: Geometric graph convolutional networks. In Proc. ICLR."},{"key":"e_1_3_2_1_40_1","volume-title":"Manning","author":"Pennington Jeffrey","year":"2014","unstructured":"Jeffrey Pennington, Richard Socher, and Christopher D. Manning. 2014. GloVe: Global Vectors for Word Representation. In Proc. EMNLP. 1532--1543."},{"key":"e_1_3_2_1_41_1","volume-title":"The truly deep graph convolutional networks for node classification. arXiv","author":"Rong Yu","year":"2019","unstructured":"Yu Rong, Wenbing Huang, Tingyang Xu, and Junzhou Huang. 2019. The truly deep graph convolutional networks for node classification. arXiv (2019)."},{"key":"e_1_3_2_1_42_1","volume-title":"Wiltschko","author":"Sanchez-Lengeling Benjamin","year":"2021","unstructured":"Benjamin Sanchez-Lengeling, Emily Reif, Adam Pearce, and Alexander B. Wiltschko. 2021. A gentle introduction to graph neural networks. Distill (2021)."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2019.2961675"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.findings-acl.118"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1108\/eb026526"},{"key":"e_1_3_2_1_46_1","volume-title":"Adapting fake news detection to the era of large language models. arXiv","author":"Su Jinyan","year":"2023","unstructured":"Jinyan Su, Claire Cardie, and Preslav Nakov. 2023. Adapting fake news detection to the era of large language models. arXiv (2023)."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2022.3201243"},{"key":"e_1_3_2_1_48_1","volume-title":"Answering ambiguous questions via iterative prompting. arXiv","author":"Sun Weiwei","year":"2023","unstructured":"Weiwei Sun, Hengyi Cai, Hongshen Chen, Pengjie Ren, Zhumin Chen, Maarten de Rijke, and Zhaochun Ren. 2023. Answering ambiguous questions via iterative prompting. arXiv (2023)."},{"key":"e_1_3_2_1_49_1","volume-title":"Node injection attacks on graphs via reinforcement learning. arXiv","author":"Sun Yiwei","year":"2019","unstructured":"Yiwei Sun, Suhang Wang, Xianfeng Tang, Tsung-Yu Hsieh, and Vasant Honavar. 2019. Node injection attacks on graphs via reinforcement learning. arXiv (2019)."},{"key":"e_1_3_2_1_50_1","volume-title":"Proc. NeurIPS.","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N Gomez, \u0141ukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need. In Proc. NeurIPS."},{"key":"e_1_3_2_1_51_1","volume-title":"Proc. ICLR.","author":"Petar Velivc","year":"2018","unstructured":"Petar Velivc kovi\u0107 , Guillem Cucurull, Arantxa Casanova, Adriana Romero, Pietro Lio, and Yoshua Bengio. 2018. Graph attention networks. In Proc. ICLR."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P17-2102"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354206"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583868"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10618-020-00696-7"},{"key":"e_1_3_2_1_56_1","volume-title":"Proc. ICLR.","author":"Welling Max","year":"2017","unstructured":"Max Welling and Thomas N Kipf. 2017. Semi-supervised classification with graph convolutional networks. In Proc. ICLR."},{"key":"e_1_3_2_1_57_1","unstructured":"Bingzhe Wu Jintang Li Junchi Yu Yatao Bian Hengtong Zhang CHaochao Chen Chengbin Hou Guoji Fu Liang Chen Tingyang Xu et al. 2022. A survey of trustworthy graph learning: Reliability explainability and privacy protection. arXiv preprint arXiv:2205.10014 (2022)."},{"key":"e_1_3_2_1_58_1","volume-title":"Fake news in sheep's clothing: robust fake news detection against LLM-empowered style attacks. arXiv","author":"Wu Jiaying","year":"2023","unstructured":"Jiaying Wu and Bryan Hooi. 2023. Fake news in sheep's clothing: robust fake news detection against LLM-empowered style attacks. arXiv (2023)."},{"key":"e_1_3_2_1_59_1","volume-title":"Topology attack and defense for graph neural networks: An optimization perspective. arXiv","author":"Xu Kaidi","year":"2019","unstructured":"Kaidi Xu, Hongge Chen, Sijia Liu, Pin-Yu Chen, Tsui-Wei Weng, Mingyi Hong, and Xue Lin. 2019. Topology attack and defense for graph neural networks: An optimization perspective. arXiv (2019)."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN52387.2021.9533748"},{"key":"e_1_3_2_1_61_1","volume-title":"Proc. IJCAI.","author":"Yang Xiaoyu","year":"2021","unstructured":"Xiaoyu Yang, Yuefei Lyu, Tian Tian, Yifei Liu, Yudong Liu, and Xi Zhang. 2021a. Rumor detection on social media with graph structured adversarial learning. In Proc. IJCAI."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2017\/545"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2019.00090"},{"key":"e_1_3_2_1_64_1","first-page":"2578","article-title":"Adversarial examples: Opportunities and challenges","volume":"31","author":"Zhang Jiliang","year":"2019","unstructured":"Jiliang Zhang and Chen Li. 2019. Adversarial examples: Opportunities and challenges. IEEE Transactions on neural networks and learning systems, Vol. 31, 7 (2019), 2578--2593.","journal-title":"IEEE Transactions on neural networks and learning systems"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3374217","article-title":"Adversarial attacks on deep-learning models in natural language processing: A survey","volume":"11","author":"Zhang Wei Emma","year":"2020","unstructured":"Wei Emma Zhang, Quan Z Sheng, Ahoud Alhazmi, and Chenliang Li. 2020. Adversarial attacks on deep-learning models in natural language processing: A survey. ACM Transactions on Intelligent Systems and Technology, Vol. 11, 3 (2020), 1--41.","journal-title":"ACM Transactions on Intelligent Systems and Technology"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3450004"},{"key":"e_1_3_2_1_67_1","volume-title":"Proc. NeurIPS Datasets and Benchmarks Track.","author":"Zheng Qinkai","year":"2022","unstructured":"Qinkai Zheng, Xu Zou, Yuxiao Dong, Yukuo Cen, Da Yin, Jiarong Xu, Yang Yang, and Jie Tang. 2022. Graph robustness benchmark: Benchmarking the adversarial robustness of graph machine learning. In Proc. NeurIPS Datasets and Benchmarks Track."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N19-1163"},{"key":"e_1_3_2_1_69_1","volume-title":"Proc. NeurIPS.","author":"Zhu Jiong","year":"2020","unstructured":"Jiong Zhu, Yujun Yan, Lingxiao Zhao, Mark Heimann, Leman Akoglu, and Danai Koutra. 2020. Beyond homophily in graph neural networks: Current limitations and effective designs. In Proc. NeurIPS."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467314"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3161603"},{"key":"e_1_3_2_1_72_1","volume-title":"Learning reporting dynamics during breaking news for rumour detection in social media. arXiv","author":"Zubiaga Arkaitz","year":"2016","unstructured":"Arkaitz Zubiaga, Maria Liakata, and Rob Procter. 2016. Learning reporting dynamics during breaking news for rumour detection in social media. arXiv (2016)."},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"},{"key":"e_1_3_2_1_74_1","volume-title":"Proc. ICLR. io","author":"Z\u00fcgner Daniel","year":"2019","unstructured":"Daniel Z\u00fcgner and Stephan G\u00fcnnemann. 2019. Adversarial attacks on graph neural networks via meta learning. In Proc. ICLR. io"}],"event":{"name":"WWW '24: The ACM Web Conference 2024","location":"Singapore Singapore","acronym":"WWW '24","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2024"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3589334.3648139","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3589334.3648139","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T00:27:10Z","timestamp":1755822430000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3589334.3648139"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,13]]},"references-count":74,"alternative-id":["10.1145\/3589334.3648139","10.1145\/3589334"],"URL":"https:\/\/doi.org\/10.1145\/3589334.3648139","relation":{},"subject":[],"published":{"date-parts":[[2024,5,13]]},"assertion":[{"value":"2024-05-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}