{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T18:46:14Z","timestamp":1773081974728,"version":"3.50.1"},"reference-count":44,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T00:00:00Z","timestamp":1773014400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Project of the Natural Science Foundation of Shandong Province","award":["ZR2024MF057"],"award-info":[{"award-number":["ZR2024MF057"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Hypergraph Neural Networks (HGNNs) have become an important tool for processing complex structured data due to their ability to model higher-order associative relationships. However, the inherent adversarial vulnerabilities of HGNNs may raise serious security risks. The associated risks are far more pronounced in strong target attacks, which are highly targeted and demand the accurate misclassification of source-class nodes into predefined target classes. Current research on attacks against HGNNs mostly focuses on untargeted attacks or common target attacks, and lacks attacks that precisely control the attack class. Therefore, the research related to strong target attacks is still in an undeveloped state. To fill this research gap, this paper proposes a Strong Target Attack framework for HGNNs based on Label poisoning and Structure modification (STALS). The framework first uses feature similarity and hypergraph structure adaptability to select the optimal target class. Subsequently, the nodes are label-poisoned under the label change budget constraint. A gradient-guided greedy hyperedge reconstruction strategy is used to optimize the association relationship between poisoned nodes and hyperedges within the structure modification budget, maximize the propagation efficiency of mislabeled information, and achieve stable directed misclassification from source class nodes to target classes. We conducted extensive experiments on four mainstream datasets, and the experimental results show that STALS achieves excellent attack performance and significantly outperforms existing baseline methods in terms of success classification rate.<\/jats:p>","DOI":"10.3390\/e28030308","type":"journal-article","created":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T11:06:52Z","timestamp":1773054412000},"page":"308","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Strong Target Attack on Hypergraph Neural Networks via Label Poisoning and Structure Modification"],"prefix":"10.3390","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-1714-589X","authenticated-orcid":false,"given":"Jie","family":"Huang","sequence":"first","affiliation":[{"name":"College of Technology and Data, Yantai Nanshan University, Yantai 265713, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiaoyan","family":"Sun","sequence":"additional","affiliation":[{"name":"College of Intelligent Science and Engineering, Yantai Nanshan University, Yantai 265713, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Na","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Technology and Data, Yantai Nanshan University, Yantai 265713, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Meizhu","family":"Zheng","sequence":"additional","affiliation":[{"name":"College of Technology and Data, Yantai Nanshan University, Yantai 265713, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,3,9]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"2216","DOI":"10.1007\/s10618-023-00952-6","article-title":"Datasets, tasks, and training methods for large-scale hypergraph learning","volume":"37","author":"Kim","year":"2023","journal-title":"Data Min. Knowl. Discov."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"858","DOI":"10.1007\/s10489-025-06754-1","article-title":"Multi-modal parameter-efficient fine-tuning via graph neural network","volume":"55","author":"Cheng","year":"2025","journal-title":"Appl. Intell."},{"key":"ref_3","first-page":"17","article-title":"Learning Hypergraphs Tensor Representations From Data via t-HGSP","volume":"10","author":"Taipe","year":"2024","journal-title":"IEEE Trans. Signal Inf. Process. Over Netw."},{"key":"ref_4","first-page":"5504405","article-title":"EHGNN: Enhanced Hypergraph Neural Network for Hyperspectral Image Classification","volume":"21","author":"Wang","year":"2024","journal-title":"IEEE Geosci. Remote Sens. Lett."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"110292","DOI":"10.1016\/j.patcog.2024.110292","article-title":"Hypergraph modeling and hypergraph multi-view attention neural network for link prediction","volume":"149","author":"Chai","year":"2024","journal-title":"Pattern Recognit."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"114897","DOI":"10.1016\/j.knosys.2025.114897","article-title":"Structural complementary hypergraph defense framework against adversarial attacks","volume":"332","author":"Su","year":"2025","journal-title":"Knowl.-Based Syst."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"110474","DOI":"10.1016\/j.ress.2024.110474","article-title":"Robustness study of hybrid hypergraphs","volume":"252","author":"Zhang","year":"2024","journal-title":"Reliab. Eng. Syst. Saf."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"115518","DOI":"10.1016\/j.chaos.2024.115518","article-title":"Robustness of hypergraph under attack with limited information based on percolation theory","volume":"188","author":"Duan","year":"2024","journal-title":"Chaos Solitons Fractals"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"128746","DOI":"10.1016\/j.neucom.2024.128746","article-title":"H3NI: Non-target-specific node injection attacks on hypergraph neural networks via genetic algorithm","volume":"613","author":"Shi","year":"2025","journal-title":"Neurocomputing"},{"key":"ref_10","unstructured":"Hu, C., Yu, R., Zeng, B., Zhan, Y., Fu, Y., Zhang, Q., Liu, R., and Shi, H. (2023). HyperAttack: Multi-Gradient-Guided White-box Adversarial Structure Attack of Hypergraph Neural Networks. arXiv."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"30222","DOI":"10.1038\/s41598-024-79824-y","article-title":"DGHSA: Derivative graph-based hypergraph structure attack","volume":"14","author":"Chen","year":"2024","journal-title":"Sci. Rep."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"129835","DOI":"10.1016\/j.neucom.2025.129835","article-title":"Momentum gradient-based untargeted poisoning attack on hypergraph neural networks","volume":"634","author":"Chen","year":"2025","journal-title":"Neurocomputing"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"130769","DOI":"10.1016\/j.eswa.2025.130769","article-title":"FMGHA: Future momentum gradient-based attack on hypergraph neural networks","volume":"304","author":"Zhou","year":"2026","journal-title":"Expert Syst. Appl."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Zhang, M., Hu, L., Shi, C., and Wang, X. (2020, January 17\u201320). Adversarial Label-Flipping Attack and Defense for Graph Neural Networks. Proceedings of the 2020 IEEE International Conference on Data Mining (ICDM), Sorrento, Italy.","DOI":"10.1109\/ICDM50108.2020.00088"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"2098","DOI":"10.1109\/TNSE.2023.3243058","article-title":"RAHG: A Role-Aware Hypergraph Neural Network for Node Classification in Graphs","volume":"10","author":"Li","year":"2023","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"106929","DOI":"10.1016\/j.neunet.2024.106929","article-title":"I2HGNN: Iterative Interpretable HyperGraph Neural Network for semi-supervised classification","volume":"183","author":"Zhang","year":"2025","journal-title":"Neural Netw."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"107637","DOI":"10.1016\/j.patcog.2020.107637","article-title":"Hypergraph convolution and hypergraph attention","volume":"110","author":"Bai","year":"2021","journal-title":"Pattern Recognit."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"4515","DOI":"10.1109\/TKDE.2024.3380643","article-title":"CHGNN: A Semi-Supervised Contrastive Hypergraph Learning Network","volume":"36","author":"Song","year":"2024","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"1365","DOI":"10.1109\/TBDATA.2023.3278988","article-title":"A Multi-Modal Hypergraph Neural Network via Parametric Filtering and Feature Sampling","volume":"9","author":"Liu","year":"2023","journal-title":"IEEE Trans. Big Data"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"184","DOI":"10.1145\/3663670","article-title":"FastHGNN: A New Sampling Technique for Learning with Hypergraph Neural Networks","volume":"18","author":"Lu","year":"2024","journal-title":"ACM Trans. Knowl. Discov. Data"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"1081","DOI":"10.1109\/TCSS.2020.3004059","article-title":"Link Prediction Adversarial Attack Via Iterative Gradient Attack","volume":"7","author":"Chen","year":"2020","journal-title":"IEEE Trans. Comput. Soc. Syst."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"112686","DOI":"10.1016\/j.patcog.2025.112686","article-title":"ALDA: Enhancing the transferability of adversarial attacks with attention-guided look-ahead and data augmentation","volume":"172","author":"Guo","year":"2026","journal-title":"Pattern Recognit."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"108262","DOI":"10.1016\/j.neunet.2025.108262","article-title":"AdaptiveWordBug: Generating adversarial texts with an adaptive scoring strategy against deep learning classifiers","volume":"195","author":"Zhang","year":"2026","journal-title":"Neural Netw."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"108237","DOI":"10.1016\/j.cnsns.2024.108237","article-title":"Cascading failures on interdependent hypergraph","volume":"138","author":"Qian","year":"2024","journal-title":"Commun. Nonlinear Sci. Numer. Simul."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"2760","DOI":"10.1109\/TNSE.2025.3620668","article-title":"High-Order Knowledge Based Network Controllability Robustness Prediction: A Hypergraph Neural Network Approach","volume":"13","author":"Mo","year":"2026","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"ref_26","unstructured":"Goodfellow, I., Shlens, J., and Szegedy, C. (2014). Explaining and Harnessing Adversarial Examples. arXiv."},{"key":"ref_27","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (May, January 30). Towards Deep Learning Models Resistant to Adversarial Attacks. Proceedings of the 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada. Conference Track Proceedings."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"113786","DOI":"10.1016\/j.asoc.2025.113786","article-title":"Improving adversarial transferability with Neighborhood Gradient Information","volume":"184","author":"Guo","year":"2025","journal-title":"Appl. Soft Comput."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"122888","DOI":"10.1016\/j.ins.2025.122888","article-title":"TextJosher: A transfer-based black-box attack method Against text classifiers","volume":"731","author":"Wang","year":"2026","journal-title":"Inf. Sci."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"108338","DOI":"10.1016\/j.neunet.2025.108338","article-title":"GuidedDE: Targeted black-box adversarial attacks via confidence-guided mutation on automatic speech recognition systems","volume":"196","author":"Li","year":"2026","journal-title":"Neural Netw."},{"key":"ref_31","first-page":"1","article-title":"A Novel Unsupervised Structural Attack and Defense for Graph Classification","volume":"86","author":"Wang","year":"2026","journal-title":"CMC-Comput. Mater. Contin."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"119877","DOI":"10.1016\/j.ins.2023.119877","article-title":"Two-level adversarial attacks for graph neural networks","volume":"654","author":"Song","year":"2024","journal-title":"Inf. Sci."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"577","DOI":"10.1109\/TNSE.2021.3127557","article-title":"GraphAttacker: A General Multi-Task Graph Attack Framework","volume":"9","author":"Chen","year":"2022","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"3218","DOI":"10.1109\/TCSS.2023.3344642","article-title":"Detecting Targets of Graph Adversarial Attacks With Edge and Feature Perturbations","volume":"11","author":"Lee","year":"2024","journal-title":"IEEE Trans. Comput. Soc. Syst."},{"key":"ref_35","unstructured":"Z\u00fcgner, D., and G\u00fcnnemann, S. (2019, January 6\u20139). Adversarial Attacks on Graph Neural Networks via Meta Learning. Proceedings of the 7th International Conference on Learning Representations, ICLR 2019, New Orleans, LA, USA."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Z\u00fcgner, D., Akbarnejad, A., and G\u00fcnnemann, S. (2018, January 19\u201323). Adversarial attacks on neural networks for graph data. Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, London, UK.","DOI":"10.1145\/3219819.3220078"},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1007\/s40747-025-02129-8","article-title":"GraphZOOM: Subgraph black-box attack against inductive graph neural networks","volume":"12","author":"Tang","year":"2025","journal-title":"Complex Intell. Syst."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"1586","DOI":"10.1109\/TBDATA.2023.3296936","article-title":"A Black-Box Adversarial Attack Method via Nesterov Accelerated Gradient and Rewiring Towards Attacking Graph Neural Networks","volume":"9","author":"Zhao","year":"2023","journal-title":"IEEE Trans. Big Data"},{"key":"ref_39","first-page":"3814","article-title":"Information Entropy-Driven Black-box Transferable Adversarial Attack Method for Graph Neural Networks","volume":"47","author":"Wu","year":"2025","journal-title":"J. Electron. Inf. Technol."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1023\/A:1009953814988","article-title":"Automating the construction of internet portals with machine learning","volume":"3","author":"McCallum","year":"2000","journal-title":"Inf. Retr."},{"key":"ref_41","unstructured":"Bojchevski, A., and G\u00fcnnemann, S. (2017). Deep gaussian embedding of graphs: Unsupervised inductive learning via ranking. arXiv."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Giles, C.L., Bollacker, K.D., and Lawrence, S. (1998, January 23\u201326). CiteSeer: An automatic citation indexing system. Proceedings of the Third ACM Conference on Digital Libraries, Pittsburgh, PA, USA.","DOI":"10.1145\/276675.276685"},{"key":"ref_43","first-page":"93","article-title":"Collective Classification in Network Data","volume":"29","author":"Sen","year":"2008","journal-title":"AI Mag."},{"key":"ref_44","first-page":"2548","article-title":"Hypergraph Learning: Methods and Practices","volume":"44","author":"Gao","year":"2022","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/28\/3\/308\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T11:07:23Z","timestamp":1773054443000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/28\/3\/308"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,9]]},"references-count":44,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2026,3]]}},"alternative-id":["e28030308"],"URL":"https:\/\/doi.org\/10.3390\/e28030308","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,9]]}}}