cs.LGSep 27, 2026

ZeroGAR: Benchmarking the Adversarial Robustness of Zero-Shot Graph Models

Authors: Zhongjian Zhang, Xiao Wang, Busheng Zhang, Bo Yan, Xingtong Yu, Yue Gao, Jia Li, Chuan Shi

Organizations: Beijing University of Posts and Telecommunications · Beihang University · Tsinghua University · The Chinese University of Hong Kong · The Hong Kong University of Science and Technology (Guangzhou)

Abstract

Zero-shot graph models (ZGMs), which learn transferable knowledge from source graphs and directly apply to unseen target graphs without any adaptation, have achieved promising performance and attracted considerable attention. Despite their proliferation, existing ZGMs are predominantly evaluated on clean graphs, while existing graph robustness benchmarks mainly focus on supervised settings, leaving a fundamental question largely unexplored: How robust are ZGMs when their unseen target graphs are exposed to adversarial manipulation? In this paper, we answer this question by proposing ZeroGAR, the first systematic benchmark for evaluating the adversarial robustness of ZGMs. ZeroGAR evaluates 13 representative ZGMs from 3 different paradigms on 8 graph datasets across 4 domains, covering both in-domain and cross-domain transfer under structural, textual, and node injection attacks with multiple perturbation budgets. It further investigates whether existing graph defenses remain effective in the zero-shot setting. Extensive experiments reveal that strong clean zero-shot performance does not guarantee adversarial robustness, with three key findings: (1) Vulnerability patterns are related to model prediction mechanisms: GNN-based methods are particularly vulnerable to structural and node injection attacks, whereas LLM-based methods are more vulnerable to textual attacks; (2) Stronger LLM backbones introduce a structure-text robustness trade-off; (3) Existing graph defense methods do not consistently improve zero-shot robustness and may compromise clean performance. We hope that ZeroGAR will facilitate rapid, equitable evaluation and inspire further innovative research in ZGM security.

Figures & tables

Explore similar work

CardsList
  1. Adversarial Graph Neural Network Benchmarks: Towards Practical and Fair Evaluation

    May 7, 2026Tran Gia Bao Ngo, Zulfikar Alom, Federico Errica +2Graph Neural NetworksGraph Representations

  2. On the Safety of Graph Representation Learning

    May 7, 2026Xiaoguang Guo, Zehong Wang, Ziming Li +5Graph Representation LearningGraph Neural Networks

  3. COPYCOP: Ownership Verification for Graph Neural Networks

    May 6, 2026Rahul Nandakumar, Deepayan ChakrabartiGraph Neural NetworksWatermarking