Stealthy Yet Effective: In-Distribution Node Injection Attacks for Hyperedge Prediction
Abstract
Deep hypergraph models are widely adopted in real-world decision-making systems due to their powerful higher-order modeling capabilities for complex data, making their security and robustness increasingly critical. Recent studies have revealed adversarial vulnerabilities in deep hypergraph models on node-level tasks that predict individual node properties. However, their robustness in hyperedge prediction, a fundamental task for inferring missing or future group-level interactions among multiple entities, remains largely unexplored. To fill this gap, we systematically analyze mainstream injection-based attacks and identify two key challenges in applying them to hyperedge prediction: (1) Perturbation attenuation: we theoretically demonstrate that group-level aggregation in edge prediction weakens the adversarial influence of injected nodes, limiting attack effectiveness. (2) Distributional deviation: empirical results reveal pronounced shifts in membership- and hyperedge-level statistical distributions after injection, compromising attack stealthiness. To tackle these challenges, we propose DPHIA, the first effective and unnoticeable node injection attack tailored for hyperedge prediction. DPHIA employs an adaptive ranking-based objective to perturb the decision boundary between positive and negative hyperedges, thereby misleading the predictor. A dual-level adversarial regularizer constrains distributional shifts in higher-order relations through membership- and hyperedge-level adversarial training, improving attack stealthiness. Extensive experiments on five real-world datasets demonstrate that DPHIA achieves a superior trade-off between attack effectiveness and detectability compared with state-of-the-art baselines. Our code is available at https://anonymous.4open.science/r/DPHIA-063D.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.