{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T16:07:32Z","timestamp":1780675652007,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","funder":[{"name":"the Zhejiang Provincial Natural Science Foundation","award":["LQN26F020049"],"award-info":[{"award-number":["LQN26F020049"]}]},{"name":"the Zhejiang Province Key R&D Program Project","award":["2025C01023"],"award-info":[{"award-number":["2025C01023"]}]},{"name":"the National Natural Science Foundation of China","award":["62372146"],"award-info":[{"award-number":["62372146"]}]},{"name":"the National Natural Science Foundation of China","award":["62322203"],"award-info":[{"award-number":["62322203"]}]},{"name":"the National Natural Science Foundation of China","award":["62172052"],"award-info":[{"award-number":["62172052"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,13]]},"DOI":"10.1145\/3774904.3792502","type":"proceedings-article","created":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T21:54:39Z","timestamp":1775771679000},"page":"1217-1228","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Can LLMs Fool Graph Learning? Exploring Universal Adversarial Attacks on Text-Attributed Graphs"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-0881-3441","authenticated-orcid":false,"given":"Zihui","family":"Chen","sequence":"first","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5804-9742","authenticated-orcid":false,"given":"Yuling","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1049-1002","authenticated-orcid":false,"given":"Pengfei","family":"Jiao","sequence":"additional","affiliation":[{"name":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7974-4638","authenticated-orcid":false,"given":"Kai","family":"Wu","sequence":"additional","affiliation":[{"name":"Hangzhou Dianzi University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4444-7811","authenticated-orcid":false,"given":"Xiao","family":"Wang","sequence":"additional","affiliation":[{"name":"Beihang University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9633-8361","authenticated-orcid":false,"given":"Xiang","family":"Ao","sequence":"additional","affiliation":[{"name":"Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5869-6544","authenticated-orcid":false,"given":"Dalin","family":"Zhang","sequence":"additional","affiliation":[{"name":"Hangzhou Dianzi University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,12]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"The Thirteenth International Conference on Learning Representations.","author":"Alom Zulfikar","year":"2025","unstructured":"Zulfikar Alom, Tran Gia Bao Ngo, Murat Kantarcioglu, and Cuneyt Gurcan Akcora. 2025. GOttack: Universal Adversarial Attacks on Graph Neural Networks via Graph Orbits Learning. In The Thirteenth International Conference on Learning Representations."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i22.34510"},{"key":"e_1_3_2_1_3_1","volume-title":"International conference on machine learning. PMLR, 695-704","author":"Bojchevski Aleksandar","year":"2019","unstructured":"Aleksandar Bojchevski and Stephan G\u00fcnnemann. 2019. Adversarial attacks on node embeddings via graph poisoning. In International conference on machine learning. PMLR, 695-704."},{"key":"e_1_3_2_1_4_1","volume-title":"Jailbreaking black box large language models in twenty queries. arXiv preprint arXiv:2310.08419","author":"Chao Patrick","year":"2023","unstructured":"Patrick Chao, Alexander Robey, Edgar Dobriban, Hamed Hassani, George J Pappas, and Eric Wong. 2023. Jailbreaking black box large language models in twenty queries. arXiv preprint arXiv:2310.08419 (2023)."},{"key":"e_1_3_2_1_5_1","volume-title":"Llaga: Large language and graph assistant. arXiv preprint arXiv:2402.08170","author":"Chen Runjin","year":"2024","unstructured":"Runjin Chen, Tong Zhao, Ajay Jaiswal, Neil Shah, and Zhangyang Wang. 2024b. Llaga: Large language and graph assistant. arXiv preprint arXiv:2402.08170 (2024)."},{"key":"e_1_3_2_1_6_1","unstructured":"Yongqiang Chen Han Yang Yonggang Zhang Kaili Ma Tongliang Liu Bo Han and James Cheng. 2022. Understanding and Improving Graph Injection Attack by Promoting Unnoticeability. arXiv:2202.08057 [cs.LG] https:\/\/arxiv.org\/abs\/2202.08057"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3655103.3655110"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2024.128133"},{"key":"e_1_3_2_1_9_1","volume-title":"Jos\u00e9 MF Moura, and Soummya Kar","author":"Du Jian","year":"2017","unstructured":"Jian Du, Shanghang Zhang, Guanhang Wu, Jos\u00e9 MF Moura, and Soummya Kar. 2017. Topology adaptive graph convolutional networks. arXiv preprint arXiv:1710.10370 (2017)."},{"key":"e_1_3_2_1_10_1","volume-title":"Learning on Graphs with Large Language Models (LLMs): A Deep Dive into Model Robustness. arXiv preprint arXiv:2407.12068","author":"Guo Kai","year":"2024","unstructured":"Kai Guo, Zewen Liu, Zhikai Chen, Hongzhi Wen, Wei Jin, Jiliang Tang, and Yi Chang. 2024. Learning on Graphs with Large Language Models (LLMs): A Deep Dive into Model Robustness. arXiv preprint arXiv:2407.12068 (2024)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Zirui Guo Lianghao Xia Yanhua Yu Tu Ao and Chao Huang. 2025. LightRAG: Simple and Fast Retrieval-Augmented Generation. arXiv:2410.05779 [cs.IR] https:\/\/arxiv.org\/abs\/2410.05779","DOI":"10.18653\/v1\/2025.findings-emnlp.568"},{"key":"e_1_3_2_1_12_1","volume-title":"Inductive representation learning on large graphs. Advances in neural information processing systems","author":"Hamilton Will","year":"2017","unstructured":"Will Hamilton, Zhitao Ying, and Jure Leskovec. 2017. Inductive representation learning on large graphs. Advances in neural information processing systems, Vol. 30 (2017)."},{"key":"e_1_3_2_1_13_1","volume-title":"Harnessing Explanations: LLM-to-LM Interpreter for Enhanced Text-Attributed Graph Representation Learning. In ICLR.","author":"He Xiaoxin","year":"2024","unstructured":"Xiaoxin He, Xavier Bresson, Thomas Laurent, Adam Perold, Yann LeCun, and Bryan Hooi. 2024. Harnessing Explanations: LLM-to-LM Interpreter for Enhanced Text-Attributed Graph Representation Learning. In ICLR."},{"key":"e_1_3_2_1_14_1","first-page":"110097","article-title":"Robust graph neural networks via unbiased aggregation","volume":"37","author":"Hou Zhichao","year":"2024","unstructured":"Zhichao Hou, Ruiqi Feng, Tyler Derr, and Xiaorui Liu. 2024. Robust graph neural networks via unbiased aggregation. Advances in Neural Information Processing Systems, Vol. 37 (2024), 110097-110130.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_15_1","volume-title":"Open graph benchmark: Datasets for machine learning on graphs. Advances in neural information processing systems","author":"Hu Weihua","year":"2020","unstructured":"Weihua Hu, Matthias Fey, Marinka Zitnik, Yuxiao Dong, Hongyu Ren, Bowen Liu, Michele Catasta, and Jure Leskovec. 2020. Open graph benchmark: Datasets for machine learning on graphs. Advances in neural information processing systems, Vol. 33 (2020), 22118-22133."},{"key":"e_1_3_2_1_16_1","volume-title":"Diego de las Casas, Emma Bou Hanna, Florian Bressand, et al.","author":"Jiang Albert Q","year":"2024","unstructured":"Albert Q Jiang, Alexandre Sablayrolles, Antoine Roux, Arthur Mensch, Blanche Savary, Chris Bamford, Devendra Singh Chaplot, Diego de las Casas, Emma Bou Hanna, Florian Bressand, et al., 2024. Mixtral of experts. arXiv preprint arXiv:2401.04088 (2024)."},{"key":"e_1_3_2_1_17_1","volume-title":"Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907","author":"Kipf Thomas N","year":"2016","unstructured":"Thomas N Kipf and Max Welling. 2016. Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907 (2016)."},{"key":"e_1_3_2_1_18_1","volume-title":"Intruding with Words: Towards Understanding Graph Injection Attacks at the Text Level. arXiv preprint arXiv:2405.16405","author":"Lei Runlin","year":"2024","unstructured":"Runlin Lei, Yuwei Hu, Yuchen Ren, and Zhewei Wei. 2024. Intruding with Words: Towards Understanding Graph Injection Attacks at the Text Level. arXiv preprint arXiv:2405.16405 (2024)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.5555\/3692070.3693216"},{"key":"e_1_3_2_1_20_1","first-page":"82","article-title":"Adversarial Attack on Large Scale Graph","volume":"35","author":"Li Jintang","year":"2023","unstructured":"Jintang Li, Tao Xie, Liang Chen, Fenfang Xie, Xiangnan He, and Zibin Zheng. 2023. Adversarial Attack on Large Scale Graph. IEEE Transactions on Knowledge & Data Engineering, Vol. 35, 01 (2023), 82-95.","journal-title":"IEEE Transactions on Knowledge & Data Engineering"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3696410.3714727"},{"key":"e_1_3_2_1_22_1","volume-title":"One for all: Towards training one graph model for all classification tasks. arXiv preprint arXiv:2310.00149","author":"Liu Hao","year":"2023","unstructured":"Hao Liu, Jiarui Feng, Lecheng Kong, Ningyue Liang, Dacheng Tao, Yixin Chen, and Muhan Zhang. 2023. One for all: Towards training one graph model for all classification tasks. arXiv preprint arXiv:2310.00149 (2023)."},{"key":"e_1_3_2_1_23_1","unstructured":"Jiawei Liu Cheng Yang Zhiyuan Lu Junze Chen Yibo Li Mengmei Zhang Ting Bai Yuan Fang Lichao Sun Philip S Yu et al. 2025a. Graph Foundation Models: Concepts Opportunities and Challenges. IEEE Transactions on Pattern Analysis and Machine Intelligence (2025)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2025.3565306"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i12.33332"},{"key":"e_1_3_2_1_26_1","unstructured":"Haoyu Lu Wen Liu Bo Zhang Bingxuan Wang Kai Dong Bo Liu Jingxiang Sun Tongzheng Ren Zhuoshu Li Hao Yang et al. 2024. Deepseek-vl: towards real-world vision-language understanding. arXiv preprint arXiv:2403.05525 (2024)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-023-36559-0"},{"key":"e_1_3_2_1_28_1","volume-title":"Towards more practical adversarial attacks on graph neural networks. Advances in neural information processing systems","author":"Ma Jiaqi","year":"2020","unstructured":"Jiaqi Ma, Shuangrui Ding, and Qiaozhu Mei. 2020. Towards more practical adversarial attacks on graph neural networks. Advances in neural information processing systems, Vol. 33 (2020), 4756-4766."},{"key":"e_1_3_2_1_29_1","volume-title":"International Conference on Learning Representations.","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1009953814988"},{"key":"e_1_3_2_1_31_1","volume-title":"Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. 2284-2295","author":"Wang Shijie","year":"2024","unstructured":"Liang-bo Ning, Shijie Wang, Wenqi Fan, Qing Li, Xin Xu, Hao Chen, and Feiran Huang. 2024. Cheatagent: Attacking llm-empowered recommender systems via llm agent. In Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. 2284-2295."},{"key":"e_1_3_2_1_32_1","volume-title":"The Thirteenth International Conference on Learning Representations.","author":"Qi Xiangyu","unstructured":"Xiangyu Qi, Ashwinee Panda, Kaifeng Lyu, Xiao Ma, Subhrajit Roy, Ahmad Beirami, Prateek Mittal, and Peter Henderson. [n.d.]. Safety Alignment Should be Made More Than Just a Few Tokens Deep. In The Thirteenth International Conference on Learning Representations."},{"key":"e_1_3_2_1_33_1","volume-title":"KG-RAG: Bridging the Gap Between Knowledge and Creativity. arXiv preprint arXiv:2405.12035","author":"Sanmartin Diego","year":"2024","unstructured":"Diego Sanmartin. 2024. KG-RAG: Bridging the Gap Between Knowledge and Creativity. arXiv preprint arXiv:2405.12035 (2024)."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3583780.3615095"},{"key":"e_1_3_2_1_35_1","volume-title":"Exploring the deceptive power of llm-generated fake news: A study of real-world detection challenges. arXiv preprint arXiv:2403.18249","author":"Sun Yanshen","year":"2024","unstructured":"Yanshen Sun, Jianfeng He, Limeng Cui, Shuo Lei, and Chang-Tien Lu. 2024. Exploring the deceptive power of llm-generated fake news: A study of real-world detection challenges. arXiv preprint arXiv:2403.18249 (2024)."},{"key":"e_1_3_2_1_36_1","volume-title":"Llama: Open and efficient foundation language models. arXiv preprint arXiv:2302.13971","author":"Touvron Hugo","year":"2023","unstructured":"Hugo Touvron, Thibaut Lavril, Gautier Izacard, Xavier Martinet, Marie-Anne Lachaux, Timoth\u00e9e Lacroix, Baptiste Rozi\u00e8re, Naman Goyal, Eric Hambro, Faisal Azhar, et al., 2023. Llama: Open and efficient foundation language models. arXiv preprint arXiv:2302.13971 (2023)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354206"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01302"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3616855.3635826"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01573"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671716"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645671"},{"key":"e_1_3_2_1_43_1","volume-title":"International conference on machine learning. Pmlr, 6861-6871","author":"Wu Felix","year":"2019","unstructured":"Felix Wu, Amauri Souza, Tianyi Zhang, Christopher Fifty, Tao Yu, and Kilian Weinberger. 2019. Simplifying graph convolutional networks. In International conference on machine learning. Pmlr, 6861-6871."},{"key":"e_1_3_2_1_44_1","volume-title":"Query-free black-box adversarial attacks on graphs. arXiv preprint arXiv","author":"Xu Jiarong","year":"2012","unstructured":"Jiarong Xu, Yizhou Sun, Xin Jiang, Yanhao Wang, Yang Yang, Chunping Wang, and Jiangang Lu. 2012. Query-free black-box adversarial attacks on graphs. arXiv preprint arXiv (2012)."},{"key":"e_1_3_2_1_45_1","volume-title":"How powerful are graph neural networks? arXiv preprint arXiv:1810.00826","author":"Xu Keyulu","year":"2018","unstructured":"Keyulu Xu, Weihua Hu, Jure Leskovec, and Stefanie Jegelka. 2018. How powerful are graph neural networks? arXiv preprint arXiv:1810.00826 (2018)."},{"key":"e_1_3_2_1_46_1","volume-title":"An llm can fool itself: A prompt-based adversarial attack. arXiv preprint arXiv:2310.13345","author":"Xu Xilie","year":"2023","unstructured":"Xilie Xu, Keyi Kong, Ning Liu, Lizhen Cui, Di Wang, Jingfeng Zhang, and Mohan Kankanhalli. 2023. An llm can fool itself: A prompt-based adversarial attack. arXiv preprint arXiv:2310.13345 (2023)."},{"key":"e_1_3_2_1_47_1","first-page":"17238","article-title":"A comprehensive study on text-attributed graphs: Benchmarking and rethinking","volume":"36","author":"Yan Hao","year":"2023","unstructured":"Hao Yan, Chaozhuo Li, Ruosong Long, Chao Yan, Jianan Zhao, Wenwen Zhuang, Jun Yin, Peiyan Zhang, Weihao Han, Hao Sun, et al., 2023. A comprehensive study on text-attributed graphs: Benchmarking and rethinking. Advances in Neural Information Processing Systems, Vol. 36 (2023), 17238-17264.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_48_1","volume-title":"Trustworthy Graph Neural Networks: Aspects, Methods and Trends. (May","author":"Zhang He","year":"2022","unstructured":"He Zhang, Bang Wu, Xingliang Yuan, Shirui Pan, Hanghang Tong, and Jian Pei. 2022. Trustworthy Graph Neural Networks: Aspects, Methods and Trends. (May 2022)."},{"key":"e_1_3_2_1_49_1","first-page":"377","article-title":"Eatn: An efficient adaptive transfer network for aspect-level sentiment analysis","volume":"35","author":"Zhang Kai","year":"2021","unstructured":"Kai Zhang, Qi Liu, Hao Qian, Biao Xiang, Qing Cui, Jun Zhou, and Enhong Chen. 2021b. Eatn: An efficient adaptive transfer network for aspect-level sentiment analysis. IEEE Transactions on Knowledge and Data Engineering, Vol. 35, 1 (2021), 377-389.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3437963.3441761"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3450569.3463560"},{"key":"e_1_3_2_1_52_1","volume-title":"Can Large Language Models Improve the Adversarial Robustness of Graph Neural Networks? arXiv preprint arXiv:2408.08685","author":"Zhang Zhongjian","year":"2024","unstructured":"Zhongjian Zhang, Xiao Wang, Huichi Zhou, Yue Yu, Mengmei Zhang, Cheng Yang, and Chuan Shi. 2024. Can Large Language Models Improve the Adversarial Robustness of Graph Neural Networks? arXiv preprint arXiv:2408.08685 (2024)."},{"key":"e_1_3_2_1_53_1","volume-title":"Graph robustness benchmark: Benchmarking the adversarial robustness of graph machine learning. arXiv preprint arXiv:2111.04314","author":"Zheng Qinkai","year":"2021","unstructured":"Qinkai Zheng, Xu Zou, Yuxiao Dong, Yukuo Cen, Da Yin, Jiarong Xu, Yang Yang, and Jie Tang. 2021. Graph robustness benchmark: Benchmarking the adversarial robustness of graph machine learning. arXiv preprint arXiv:2111.04314 (2021)."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330851"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"crossref","unstructured":"Yun Zhu Haizhou Shi Xiaotang Wang Yongchao Liu Yaoke Wang Boci Peng Chuntao Hong and Siliang Tang. 2025. GraphCLIP: Enhancing Transferability in Graph Foundation Models for Text-Attributed Graphs. arXiv:2410.10329 [cs.LG] https:\/\/arxiv.org\/abs\/2410.10329","DOI":"10.1145\/3696410.3714801"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467314"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220078"}],"event":{"name":"WWW '26: The ACM Web Conference 2026","location":"Dubai United Arab Emirates","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Proceedings of the ACM Web Conference 2026"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3774904.3792502","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T15:53:35Z","timestamp":1780674815000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3774904.3792502"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,12]]},"references-count":57,"alternative-id":["10.1145\/3774904.3792502","10.1145\/3774904"],"URL":"https:\/\/doi.org\/10.1145\/3774904.3792502","relation":{},"subject":[],"published":{"date-parts":[[2026,4,12]]},"assertion":[{"value":"2026-04-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}