Related Experiment Video
Updated: Aug 20, 2026

Evidence-based Knowledge Synthesis and Hypothesis Validation: Navigating Biomedical Knowledge Bases via Explainable AI and Agentic Systems
Published on: June 13, 2025
TGPA: Transferable graph prompt attack with hierarchical subgraph augmentation
Ju Jia1, Haonan Wang1, Tian Wu2
1School of Cyber Science and Engineering, Southeast University, Nanjing, 210096, China.
None:
Graph prompt learning effectively mitigates the challenges associated with complex tuning processes, which can address the inherent inconsistency between downstream tasks and pre-training objectives. As graph prompts play a pivotal role in the inference of graph pre-trained models, the malicious attacks on graph prompts can substantially compromise the predictive accuracy of model. Unfortunately, existing graph adversarial attacks largely rely on single-scale topological perturbations, which overlook the multi-granular structural dependencies that graph prompts use to transfer knowledge. Consequently, they fail to maintain transferability across different downstream tasks. To alleviate this issue, we propose a novel transferable graph prompt attack, called TGPA, which shifts the attack paradigm by introducing a hierarchical structural decoupling mechanism. Specifically, the hierarchical subgraph information extraction is first employed to obtain the global information and local information. Subsequently, the corresponding node selection based on local and global knowledge is utilized to identify the target nodes. Finally, the perturbations between features and structures are applied to generate malicious samples through the selection of target nodes, which can be utilized to mislead the graph prompt learning. Large-scale experiments across multiple popular graph datasets demonstrate that TGPA successfully reduces the performance of pre-trained graph models with graph prompts by up to 28.9%, while guaranteeing robustness, stealthiness, and transferability.