Optimal Transport-Guided Adversarial Attacks on Graph Neural Network-Based Bot Detection
Researchers have introduced BOCLOAK, a novel framework designed to evaluate the robustness of Graph Neural Networks (GNNs) used in social media bot detection. Addressing the limitations of existing attack methods that often ignore real-world constraints, BOCLOAK utilizes optimal transport geometry to construct probability measures over spatio-temporal neighbor features. This approach allows for the generation of sparse, plausible edge edits and node injections that effectively evade detection while adhering to domain-specific and temporal constraints. Extensive evaluations across three social bot datasets, five state-of-the-art detectors, and three adversarial defenses demonstrate BOCLOAK's superiority. The framework achieves up to an 80.13% higher attack success rate compared to leading baselines while consuming 99.80% less GPU memory. These findings highlight the critical vulnerability of current GNN-based security systems and establish optimal transport as a lightweight, principled method for bridging the gap between theoretical adversarial attacks and practical, constraint-aware bot detection scenarios.
Wire timeline
Optimal Transport-Guided Adversarial Attacks on Graph Neural Network-Based Bot Detection
Researchers have introduced BOCLOAK, a novel framework designed to evaluate the robustness of Graph Neural Networks (GNNs) used in social media bot detection. Addressing the limitations of existing attack methods that often ignore real-world constraints, BOCLOAK utilizes optimal transport geometry to construct probability measures over spatio-temporal neighbor features. This approach allows for the generation of sparse, plausible edge edits and node injections that effectively evade detection while adhering to domain-specific and temporal constraints. Extensive evaluations across three social bot datasets, five state-of-the-art detectors, and three adversarial defenses demonstrate BOCLOAK's superiority. The framework achieves up to an 80.13% higher attack success rate compared to leading baselines while consuming 99.80% less GPU memory. These findings highlight the critical vulnerability of current GNN-based security systems and establish optimal transport as a lightweight, principled method for bridging the gap between theoretical adversarial attacks and practical, constraint-aware bot detection scenarios.
cs.AI updates on arXiv.org