ZeroGAR: Benchmarking the Adversarial Robustness of Zero-Shot Graph Models

📅 2026-09-27
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the absence of adversarial robustness evaluation for zero-shot graph models on unseen graphs by establishing the first systematic benchmark. Methodologically, it encompasses three attack paradigms—structural, textual, and node injection—to comprehensively assess the vulnerabilities of GNN- and LLM-based baselines and their correlation with underlying prediction mechanisms. The findings reveal that strong clean performance does not guarantee adversarial robustness, and that existing defense strategies fail to effectively enhance security in zero-shot scenarios, often degrading accuracy. By bridging this critical gap in security assessment, this work provides essential foundations for developing reliable zero-shot graph models.
📝 Abstract
Zero-shot graph models (ZGMs), which learn transferable knowledge from source graphs and directly apply to unseen target graphs without any adaptation, have achieved promising performance and attracted considerable attention. Despite their proliferation, existing ZGMs are predominantly evaluated on clean graphs, while existing graph robustness benchmarks mainly focus on supervised settings, leaving a fundamental question largely unexplored: How robust are ZGMs when their unseen target graphs are exposed to adversarial manipulation? In this paper, we answer this question by proposing ZeroGAR, the first systematic benchmark for evaluating the adversarial robustness of ZGMs. ZeroGAR evaluates 13 representative ZGMs from 3 different paradigms on 8 graph datasets across 4 domains, covering both in-domain and cross-domain transfer under structural, textual, and node injection attacks with multiple perturbation budgets. It further investigates whether existing graph defenses remain effective in the zero-shot setting. Extensive experiments reveal that strong clean zero-shot performance does not guarantee adversarial robustness, with three key findings: (1) Vulnerability patterns are related to model prediction mechanisms: GNN-based methods are particularly vulnerable to structural and node injection attacks, whereas LLM-based methods are more vulnerable to textual attacks; (2) Stronger LLM backbones introduce a structure-text robustness trade-off; (3) Existing graph defense methods do not consistently improve zero-shot robustness and may compromise clean performance. We hope that ZeroGAR will facilitate rapid, equitable evaluation and inspire further innovative research in ZGM security.
Problem

Research questions and friction points this paper is trying to address.

Zero-shot graph models
Adversarial robustness
Benchmark
Graph neural networks
Innovation

Methods, ideas, or system contributions that make the work stand out.

Zero-shot Graph Models
Adversarial Robustness
Benchmark
Graph Neural Networks
Large Language Models
🔎 Similar Papers
No similar papers found.