Opportunities

  • Two ways of perturbations: changing node features, or changing the graph structure
  • Possibility to misguide the prediction of another instance by attacker’s own actions.

Challenges (and Questions to be answered)

  • How to handle discrete node features?
  • How to define “unnoticeable perturbations” for a graph?