NeurIPS 2020

Towards More Practical Adversarial Attacks on Graph Neural Networks

Meta Review

The paper proposes a restricted black-box attach for GNN, which is claimed to be more applicable in real world scenarios. After extensive discussion and having read the reviews and the rebuttal it is clear that the novelty of the approach is acknowledged across the board. This leaves the main weakness of the work in the experimental validation. Although a fair comparison with other approaches is hard to make due to the more challenging setting of this work, an in depth analysis of the method and the various settings would have been desirable. Some of the choices seem not very realistic as well, i.e. assuming to be able to perturb 1% of the nodes.