Adversarial Attacks and Robust Training for Hypergraph Neural Networks

Naheed Anjum Arafat, Debabrota Basu, Yulia Gel, Danda B. Rawat
Proceedings of the 43rd International Conference on Machine Learning, PMLR 306:3276-3305, 2026.

Abstract

Recent studies show that Hypergraph Neural Networks (HGNNs) are vulnerable to adversarial attacks, while adversarial learning in the context of hypergraphs remains substantially under-investigated. In particular, all existing attacks on HGNNs are white-box and customized for either structural or feature perturbation. But in reality, the attacker might not have access to the target model parameters. Motivated by this knowledge gap, we propose a generic meta-objective-based learning framework, MeLA, that leverages the hypergraph Laplacian to conduct gray-box, structural, and feature perturbations under explicit perturbation budgets. In contrast to the attack literature, there is no adversarial training mechanism for HGNNs to defend against such attacks. Hence, we propose a novel adversarial training mechanism for HGNNs to obtain a robust classifier. We further prove the convergence of our robust training. Extensive experiments across various HGNN models and datasets show that (a) our proposed attack is effective in poisoning and evasion settings, and (b) our adversarial training enhances defense against adversarial attacks.

Cite this Paper


BibTeX
@InProceedings{pmlr-v306-arafat26a, title = {Adversarial Attacks and Robust Training for Hypergraph Neural Networks}, author = {Arafat, Naheed Anjum and Basu, Debabrota and Gel, Yulia and Rawat, Danda B.}, booktitle = {Proceedings of the 43rd International Conference on Machine Learning}, pages = {3276--3305}, year = {2026}, editor = {Zhang, Tong and Dudik, Miroslav and Jaggi, Martin and Agarwal, Alekh and Li, Sharon and Schuurmans, Dale and Zhu, Jerry and Berkenkamp, Felix and Dong, Hanze and Bietti, Alberto}, volume = {306}, series = {Proceedings of Machine Learning Research}, month = {06--11 Jul}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v306/main/assets/arafat26a/arafat26a.pdf}, url = {https://proceedings.mlr.press/v306/arafat26a.html}, abstract = {Recent studies show that Hypergraph Neural Networks (HGNNs) are vulnerable to adversarial attacks, while adversarial learning in the context of hypergraphs remains substantially under-investigated. In particular, all existing attacks on HGNNs are white-box and customized for either structural or feature perturbation. But in reality, the attacker might not have access to the target model parameters. Motivated by this knowledge gap, we propose a generic meta-objective-based learning framework, MeLA, that leverages the hypergraph Laplacian to conduct gray-box, structural, and feature perturbations under explicit perturbation budgets. In contrast to the attack literature, there is no adversarial training mechanism for HGNNs to defend against such attacks. Hence, we propose a novel adversarial training mechanism for HGNNs to obtain a robust classifier. We further prove the convergence of our robust training. Extensive experiments across various HGNN models and datasets show that (a) our proposed attack is effective in poisoning and evasion settings, and (b) our adversarial training enhances defense against adversarial attacks.} }
Endnote
%0 Conference Paper %T Adversarial Attacks and Robust Training for Hypergraph Neural Networks %A Naheed Anjum Arafat %A Debabrota Basu %A Yulia Gel %A Danda B. Rawat %B Proceedings of the 43rd International Conference on Machine Learning %C Proceedings of Machine Learning Research %D 2026 %E Tong Zhang %E Miroslav Dudik %E Martin Jaggi %E Alekh Agarwal %E Sharon Li %E Dale Schuurmans %E Jerry Zhu %E Felix Berkenkamp %E Hanze Dong %E Alberto Bietti %F pmlr-v306-arafat26a %I PMLR %P 3276--3305 %U https://proceedings.mlr.press/v306/arafat26a.html %V 306 %X Recent studies show that Hypergraph Neural Networks (HGNNs) are vulnerable to adversarial attacks, while adversarial learning in the context of hypergraphs remains substantially under-investigated. In particular, all existing attacks on HGNNs are white-box and customized for either structural or feature perturbation. But in reality, the attacker might not have access to the target model parameters. Motivated by this knowledge gap, we propose a generic meta-objective-based learning framework, MeLA, that leverages the hypergraph Laplacian to conduct gray-box, structural, and feature perturbations under explicit perturbation budgets. In contrast to the attack literature, there is no adversarial training mechanism for HGNNs to defend against such attacks. Hence, we propose a novel adversarial training mechanism for HGNNs to obtain a robust classifier. We further prove the convergence of our robust training. Extensive experiments across various HGNN models and datasets show that (a) our proposed attack is effective in poisoning and evasion settings, and (b) our adversarial training enhances defense against adversarial attacks.
APA
Arafat, N.A., Basu, D., Gel, Y. & Rawat, D.B.. (2026). Adversarial Attacks and Robust Training for Hypergraph Neural Networks. Proceedings of the 43rd International Conference on Machine Learning, in Proceedings of Machine Learning Research 306:3276-3305 Available from https://proceedings.mlr.press/v306/arafat26a.html.

Related Material