T-STAG: Training-Free Adversarial Defense for Temporal Graph Networks via Latent-Driven Surprise
Atharv Gupta ⋅ Jaikaran Singh ⋅ Akshat Jindal ⋅ Tanvi Sharma
Abstract
Continuous-Time Dynamic Graphs (CTDGs) naturally represent structurally and temporally evolving systems in high-stakes applications such as fraud detection, content moderation, and social networks. Temporal Graph Networks (TGNs) trained on such interaction data achieve strong performance on tasks like link prediction and node classification. Yet recent works show that they are vulnerable to adversarial perturbations of the training data that can quietly manipulate what the model learns. Adversarial attacks on CTDGs have received growing attention; however, defenses tailored to this temporal setting remain underexplored. We propose **T-STAG** (**T**emporal **S**urprise-scored **T**raining-free **A**dversarial defense on **G**raphs, a training-free, model-agnostic method for defending against adversarial attacks on CTDGs. T-STAG summarizes each node's recent history with a latent state that jumps at events and decays exponentially between them. We observe that adversarially injected edges are structurally surprising with respect to a node's own history. Accordingly, we assign a surprise score to each edge and filter out the highest-surprise edges in a single unsupervised pass, before the victim model is trained. We evaluate T-STAG on Wikipedia, UCI, and MOOC under two attack regimes: pure edge injection and a two-stage delete-then-inject attack. T-STAG is the strongest defense on Wikipedia against the two-stage attack at every severity, beating undefended by up to 11\% and SVD by up to 32\% while running $17.8\times$ faster than SVD; on UCI no method reliably beats undefended, and on MOOC, defenses track undefended closely under the two-stage attack but trailing under injection alone. We provide thorough analysis of our method and identify weaknesses specific to other defenses.
Chat is not available.
Successful Page Load