<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Exploiting Temporal Importance for Adversarial Attacks on Dynamic Graphs</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Brilian Surya Budi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Toshiyuki Amagasa</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>University of Tsukuba</institution>
          ,
          <addr-line>Tsukuba, Ibaraki</addr-line>
          ,
          <country country="JP">Japan</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2026</year>
      </pub-date>
      <abstract>
        <p>Graph neural networks (GNNs) have emerged as powerful tools for modeling dynamic graphs, yet their vulnerability to adversarial attacks remains underexplored. Existing attack methods on dynamic graphs lack explicit mechanisms to incorporate temporal importance into perturbation allocation. We propose TIDGA (Temporal Importance-aware Dynamic Graph Attack), a novel framework that incorporates temporal importance weighting to guide perturbation placement on discrete-time dynamic GNNs. TIDGA introduces two weighting mechanisms: (1) temporal position weight ( ), which prioritizes earlier snapshots based on the intuition that early perturbations have more time to propagate through subsequent snapshots, and (2) edge persistence factor ( ), which measures structural stability using Jaccard similarity. We evaluate TIDGA on three benchmark datasets, and the results demonstrate that TIDGA achieves statistically significant improvement over the comparative methods.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Adversarial attack</kwd>
        <kwd>discrete-time dynamic graph</kwd>
        <kwd>graph neural network (GNN)</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Graph-structured data has become ubiquitous across numerous domains, and Graph Neural Networks
(GNNs) have emerged as a powerful paradigm for learning from such data [
        <xref ref-type="bibr" rid="ref1 ref2 ref3">1, 2, 3</xref>
        ], with applications
spanning social network analysis [
        <xref ref-type="bibr" rid="ref4 ref5">4, 5</xref>
        ], recommendation systems [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], and fraud detection [
        <xref ref-type="bibr" rid="ref10 ref11 ref7 ref8 ref9">7, 8, 9, 10, 11</xref>
        ].
While these foundational architectures operate on static graphs, real-world networks are inherently
dynamic, with edges and nodes evolving over time [
        <xref ref-type="bibr" rid="ref12 ref13">12, 13</xref>
        ]. This has driven the formalization of
discretetime dynamic graphs, represented as ordered sequences of snapshots  = {1, 2, . . . ,  } [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], and
the development of architectures that combine graph convolution with recurrent mechanisms to capture
both structural and temporal patterns.
      </p>
      <p>
        Despite their efectiveness, GNNs are vulnerable to adversarial perturbations [
        <xref ref-type="bibr" rid="ref15 ref16">15, 16</xref>
        ]. While static
GNN vulnerability has been extensively studied through surrogate-model-guided perturbations [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ],
gradient-based methods [
        <xref ref-type="bibr" rid="ref18 ref19">18, 19</xref>
        ], meta-learning [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ], and continuous optimization [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ], the vulnerability
of discrete-time dynamic graph models remains comparatively underexplored. TGA [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ] proposed
greedy perturbation selection based on gradient magnitude across snapshots, and TD-PGD [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ] extended
projected gradient descent to the temporal setting. However, existing methods select edges based on
gradient magnitude alone, ignoring temporal factors such as snapshot position and edge persistence.
This work addresses this gap by incorporating temporal importance awareness into the perturbation
optimization process.
      </p>
      <p>Understanding this vulnerability is practically important: in safety-critical deployments such as fraud
detection and social network monitoring, adversaries may manipulate historical interaction patterns
to evade detection. Adversarial evaluation serves as a red-teaming tool for assessing model reliability
before deployment, and studying efective perturbation strategies reveals which temporal patterns
dynamic GNNs rely on, informing more robust architecture design.</p>
      <p>Adversarial perturbations on dynamic graphs can be viewed as a form of graph transformation, where
deliberate structural modifications to edge sets across temporal snapshots are designed to maximally
degrade model prediction performance. By studying how such transformations propagate through
sequential architectures, we gain insights into the sensitivity of dynamic GNNs to structural changes at
diferent temporal positions.</p>
      <p>We propose TIDGA (Temporal Importance-aware Dynamic Graph Attack), a framework that weights
perturbations based on their temporal significance. Our contributions are as follows:
• Temporal importance weighting mechanism that integrates two components: (1) temporal position
weight, which prioritizes perturbations at earlier snapshots where they propagate through more
subsequent computations, and (2) edge persistence factor, which considers edge stability across
snapshots.
• Empirical analysis across three datasets and two victim model architectures, identifying that
temporal weighting improves attack efectiveness on dense graphs with parameter-evolving
architectures.</p>
      <p>The rest of this paper is organized as follows. Section 2 introduces the preliminary definitions.
Section 3 surveys the related studies. Section 4 presents the proposed method. We evaluate the
performance in Section 5, followed by the results and discussions in Section 6. Section 7 concludes this
paper.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Preliminaries</title>
      <p>Definition 1 (Discrete-Time Dynamic Graph). A discrete-time dynamic graph is an ordered sequence
of graph snapshots  = {1, 2, . . . ,  }, where each snapshot  = (, ) consists of a node set
 and adjacency matrix .</p>
      <p>Let {′1, ′2, . . . , ′ } denote the perturbed snapshots.</p>
      <p>
        Definition 2 (Adversarial Attack on Dynamic Graphs). Let ℳ be a victim dynamic GNN and  its
embedding function that generates node embeddings of  given 1:−1 . Let  be the ground-truth
labels for a given task (for link prediction, these correspond to binary labels representing link existence
at timestep  ). The attacker aims to introduce structural perturbations  = ′ −   at each timestep
 &lt;  such that model inference at timestep  for the target edges  deteriorates. Following [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ], the
optimization problem is:
      </p>
      <p>max
′1,′2,...,′ −1
subject to
ℒ(^( (′1: −1 )), , )
∑︁ ‖′ −  ‖0 ≤ 

(1)
where ^ is the predicted labels, ℒ is a task-specific loss (binary cross-entropy for link prediction),
and  is the perturbation budget.</p>
    </sec>
    <sec id="sec-3">
      <title>3. Related Work</title>
      <p>
        Dynamic Graph Neural Networks. Several architectures combine graph convolution with temporal
modeling for discrete-time dynamic graphs. EvolveGCN [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ] employs recurrent units to evolve GCN
weight matrices across timesteps. GC-LSTM [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ] embeds graph convolution within LSTM gates, jointly
considering structural context in gating decisions. DySAT [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ] applies self-attention over both structural
neighborhoods and historical snapshots, while TGAT [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ] uses temporal encoding with attention
mechanisms for continuous-time graphs. These architectures difer in how temporal information propagates:
EvolveGCN through weight evolution, GC-LSTM through gated embeddings, and attention-based
methods through learned attention scores. Architectures that evolve model parameters across timesteps
create stronger temporal dependencies, a distinction with implications for adversarial vulnerability as
analyzed in Section 6.
      </p>
      <p>
        Adversarial Attacks on Graphs. For static GNNs, NETTACK [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] performs targeted attacks by
selecting perturbations guided by a linearized surrogate model. FGA [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ] uses first-order gradients of the
attack loss to rank candidate edges, while IG-JSMA [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ] applies integrated gradients for more accurate
attribution. Metattack [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ] treats global poisoning as a meta-learning problem, optimizing perturbations
through the model’s training procedure. RL-S2V [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ] formulates attack as a Markov decision process
solved via reinforcement learning. PGD topology attack [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ] relaxes the discrete perturbation matrix
to continuous space and applies projected gradient descent. For dynamic graphs, TGA [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ] extends
gradient-based selection by computing gradients across temporal snapshots for greedy edge selection,
and TD-PGD [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ] generalizes PGD topology attack to the temporal setting with constraints preserving
temporal dynamics. Neither method considers temporal position when weighting perturbations, leaving
potential improvement unexplored.
      </p>
      <p>
        Practical Attack Scenarios. Adversarial attacks on dynamic GNNs are practically relevant in
settings where adversaries can manipulate interactions over time. In fraud detection, adversaries may
alter transaction patterns across time periods to evade GNN-based detectors [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. In social networks,
malicious actors may create or remove connections to manipulate recommendation systems. While
white-box evaluation assumes strong attacker knowledge, such analysis establishes upper bounds on
vulnerability that inform defense design and deployment decisions [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
      </p>
    </sec>
    <sec id="sec-4">
      <title>4. Methodology</title>
      <sec id="sec-4-1">
        <title>4.1. Temporal Importance Weight</title>
        <p>In discrete-time dynamic graphs, GNN models process graph snapshots sequentially, updating node
representations at each timestep based on both current graph structure and previous hidden states. This
sequential processing creates an asymmetry: perturbations introduced at earlier snapshots influence
more subsequent computations than those at later snapshots. We design a weighting mechanism that
exploits this temporal asymmetry.</p>
        <p>Temporal Position Weight. We define () to prioritize perturbations at earlier snapshots:
() =
︂(  −  )︂

× exp(−)
(2)
where  is the sequence length and  controls the decay rate. The linear term ( − )/ captures
propagation opportunity: a perturbation at timestep  can influence ( − ) subsequent snapshots before
reaching the prediction target. The exponential term exp(−) models propagation attenuation: as
information flows through sequential layers, its influence diminishes due to normalization operations
and non-linear activations. Together, these terms estimate the efective impact of perturbations based
on their temporal position.</p>
        <p>We note that this prioritization is motivated by the sequential processing of recurrent architectures:
perturbations at earlier timesteps pass through more recurrent updates before reaching the prediction
target at  , creating greater opportunity for cumulative influence on learned representations.</p>
        <p>Edge Persistence Factor. Beyond temporal position, we consider structural stability. Edges that
persist across multiple snapshots are more deeply encoded in learned representations, as the model
repeatedly observes and reinforces these patterns. We quantify persistence using Jaccard similarity
between consecutive edge sets:
() =</p>
        <p>1 ∑︁  (, +),  (, ) = | ∩ |
 =1 | ∪ |
(3)
where  is the lookahead window. Higher () indicates that edges at snapshot  tend to persist,
suggesting perturbations at this snapshot target more stable, and thus more impactful, structural
patterns.</p>
        <p>Combined Weight. The temporal importance weight integrates both factors:
(4)
(5)</p>
        <p>Normalization. We apply  () as a learning rate multiplier during gradient-based perturbation
optimization. To preserve overall optimization dynamics, we normalize by the mean:
 () = () × ()
˜ () =
 ()
¯ ,

where ¯ = 1 ∑︁  ( )

=1
This ensures the average multiplier equals 1: snapshots with above-average importance receive amplified
updates (˜ () &gt; 1), while below-average snapshots receive dampened updates (˜ () &lt; 1). The total
learning capacity is preserved while redistributing emphasis toward temporally significant snapshots.</p>
      </sec>
      <sec id="sec-4-2">
        <title>4.2. TIDGA Attack Algorithm</title>
        <p>TIDGA optimizes the perturbation matrix  initialized to ones. At each iteration, gradients are
weighted by temporal importance:
 ←   +  ×
˜ () × ∇  ℒ
(6)
where  is the learning rate. The normalized weight ˜ () functions as a per-snapshot learning rate
multiplier, making the efective learning rate  × ˜ () for each snapshot. For earlier snapshots where
˜ () &gt; 1 , gradient updates are amplified, causing perturbation scores to increase more rapidly.</p>
        <p>
          After each update, the perturbation matrix is projected onto the feasible set. When ∑︀ [
          <xref ref-type="bibr" rid="ref1">0,1</xref>
          ]() &gt;
, a threshold  is found via bisection search such that ∑︀ [
          <xref ref-type="bibr" rid="ref1">0,1</xref>
          ]( − ) =  , where [
          <xref ref-type="bibr" rid="ref1">0,1</xref>
          ]() =
max(0, min(1, )). After optimization converges, randomized rounding with multiple samples converts
continuous values to discrete perturbations, selecting the sample maximizing attack loss.
Algorithm 1 TIDGA
Require: Input: Graph sequence , budget , learning rate  , Initial 0, iteration  , rounding iteration

Ensure: Output: Perturbed graph ′
1: ˜ ← TemporalImportanceWeight()
2: for  = 1 to  do
3: ′ ←  ⊕ 
4:  ←  +  × ˜ × ∇ ℒ(′, , )
5:  ← Π()
6: end for
7: return ′ =  ⊕ Discretization(, ,  )
        </p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Experimental Evaluation</title>
      <p>
        Datasets. We evaluate on three datasets with varying characteristics, following the preprocessing
protocol of Sharma et al. [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]. Table 1 summarizes the dataset statistics. (1) Radoslaw—a dense email
communication network from a manufacturing company with 167 nodes, 22K edges across 13 snapshots
(3-week split), exhibiting high edge density and strong temporal persistence; (2) UCI—a medium-scale
online message network with 1.9K nodes, 24K edges across 13 snapshots (2-week split) (3) Reddit—a
large sparse subreddit hyperlink network with 35K nodes, 715K edges across 20 snapshots (4-week
split). These datasets span diverse graph properties to comprehensively evaluate temporal weighting
efectiveness.
      </p>
      <p>
        Victim Models. Two discrete-time dynamic GNN architectures serve as targets: EvolveGCN-O [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ],
which uses an LSTM to evolve GCN weight matrices over time ( = LSTM(−1 )) independent of
node embeddings, and GC-LSTM [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ], which embeds graph convolution within LSTM gates to process
hidden and cell states, allowing graph structure to directly influence recurrent state updates.
      </p>
      <p>
        Training Protocol. Both victim models are trained on clean graph snapshots from timesteps 1 to
 − 1 for link prediction at timestep  , following the configuration of Sharma et al. [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]: embedding
dimension 32, Adam optimizer with learning rate 0.0001, and 500 training epochs with early stopping
patience of 10. The attack operates in a poisoning setting where perturbations are injected into training
snapshots before model training. For target edge selection, UCI and Radoslaw use all edges as attack
targets, while Reddit randomly samples 500 positive and 500 negative edges due to computational
constraints.
      </p>
      <p>Task and Evaluation Protocol. We target link prediction at the final timestep  , where the model
predicts edge existence based on learned node embeddings. Attack efectiveness is measured by relative
drop:</p>
      <p>Rel. Drop = AUCattacked − AUC clean × 100%</p>
      <p>AUCclean
(7)
where larger negative values indicate more efective attacks.</p>
      <p>
        Baselines. TIDGA is compared against four methods: (1) Random—uniform random perturbation
selection serving as lower bound; (2) Degree—targeting edges connected to high-degree nodes based
on structural importance heuristic; (3) TGA-Greedy [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ]—greedy selection by gradient magnitude
without temporal consideration; (4) TD-PGD [
        <xref ref-type="bibr" rid="ref23">23</xref>
        ]—projected gradient descent with temporal dynamics
constraints, without temporal importance consideration.
      </p>
      <p>
        Configuration. Attack budgets  ∈ {5, 10, 20, 50} are tested with 50 optimization iterations using
Adam optimizer [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ] with initial learning rate  = 10 , temporal decay  = 0.1 , and lookahead
window  = 3. Results are averaged over 4 random seeds with standard deviation reported. Statistical
significance is assessed with  = 0.05 using paired t-tests when normality assumptions hold, and
Wilcoxon signed-rank tests otherwise.
      </p>
      <p>Computational Overhead. TIDGA adds negligible per-iteration overhead compared to TD-PGD, as
temporal weighting involves only element-wise multiplication with precomputed weights; the one-time
preprocessing for Jaccard similarities is ( ×  × ||).</p>
    </sec>
    <sec id="sec-6">
      <title>6. Results and Discussion</title>
      <sec id="sec-6-1">
        <title>6.1. Main Results</title>
        <p>Radoslaw-EvolveGCN-O. TIDGA achieves the best performance among all attack methods, including
Random, Degree heuristic, TGA, and TD-PGD. PGD-based methods (TIDGA and TD-PGD)
substantially outperform other approaches—at budget=50, TIDGA achieves −60.10% relative drop compared
to TGA’s −19.29% and Random’s −9.62% . Among PGD-based methods, TIDGA outperforms
TDPGD with margins of 1.17% (budget=5) to 6.10% (budget=50), with statistical significance confirmed
(Wilcoxon signed-rank, -value = 3.05e-5). The improvement magnitude increases with budget size,
suggesting temporal weighting becomes more efective when more perturbations are available for
strategic allocation. This configuration combines favorable conditions: dense graph structure ensuring
substantial gradient flow, short sequence (13 snapshots) where gradient vanishing remains manageable,
and EvolveGCN-O’s parameter-evolving architecture.</p>
        <p>Radoslaw-GCLSTM. TIDGA’s efectiveness diminishes on GC-LSTM architecture. While PGD-based
methods still outperform other approaches (TIDGA: −15.79% vs TGA: −2.11% at budget=50), TIDGA
shows marginally lower efectiveness than TD-PGD with diferences of 0.34–1.38%. GC-LSTM integrates
graph convolution within LSTM gates operating on embeddings rather than evolving weights.
Consequently, perturbations at early snapshots do not accumulate influence through the same propagation
mechanism, reducing temporal weighting benefit.</p>
        <p>UCI Dataset. On EvolveGCN-O, TIDGA and TD-PGD achieve comparable performance, both
substantially outperforming other baselines (PGD-based: &gt; 60% drop vs TGA: &lt; 53%). Non-monotonic
behavior occurs at budget=20, where both methods underperform compared to adjacent budgets,
indicating convergence to local optima due to UCI’s intermediate density creating a complex loss
landscape. On GC-LSTM, TIDGA shows reduced efectiveness compared to TD-PGD, consistent with
the pattern observed on Radoslaw.</p>
        <p>Reddit Dataset. On EvolveGCN-O, TIDGA underperforms TD-PGD by 0.61–1.78%, a diference
confirmed as statistically significant (Wilcoxon signed-rank,  &lt; 0.001). On GC-LSTM, TIDGA shows
substantially reduced efectiveness across all budgets, with the gap widening at higher budgets ( −3.23%
vs −6.48% at budget=50). This represents the least favorable configuration for TIDGA.</p>
      </sec>
      <sec id="sec-6-2">
        <title>6.2. Analysis of Efectiveness Conditions</title>
        <p>boosting early timesteps where gradients indicate lower attack efectiveness. Since actual perturbation
placement is determined by gradient magnitudes after weighting, TIDGA’s intervention becomes
counterproductive when the optimization landscape favors late timesteps. On Radoslaw, gradients favor
early timesteps, so temporal weighting successfully reinforces this direction.</p>
        <p>Architectural Vulnerability Analysis. The consistent performance gap between EvolveGCN-O and
GC-LSTM reveals fundamental architectural diferences. EvolveGCN-O evolves weight matrices through
aLcScTuMmurelactuerirneflunecnec(eth(r)ou=ghLSthTeMw(eig−1ht ,evol(−1u)ti)o)n,ccrheaaitnin. gInaccoanstcraadstin,GgCefe-LctSTwMheorpeeeraartleys preecruturrrebnactieoonns
node embeddings (ℎ = LSTM(GCN(, ), ℎ−1 )) with fixed parameters across timesteps, limiting
temporal accumulation of perturbation efects and explaining why temporal weighting provides minimal
benefit regardless of dataset.</p>
      </sec>
      <sec id="sec-6-3">
        <title>6.3. Ablation Study</title>
        <p>We conduct ablation on Radoslaw with EvolveGCN-O, comparing TIDGA- (temporal position only)
and TIDGA- (edge persistence only). At budget=50, TIDGA- achieves −60.56% versus −54.45% for
TIDGA- , confirming that temporal position weight contributes more substantially. Figure 4 summarizes
the results.</p>
      </sec>
      <sec id="sec-6-4">
        <title>6.4. Summary of Findings</title>
        <p>TIDGA improves attack efectiveness when two conditions are satisfied: (1) the victim model employs
recurrent architecture that evolves model parameters across snapshots (EvolveGCN-O), and (2) gradient
magnitudes remain distributed across multiple snapshots rather than concentrated at specific timesteps.
When both conditions are met, TIDGA achieves statistically significant improvement over TD-PGD.
When either condition is violated, TD-PGD maintains equal or superior performance. Across all
configurations, both PGD-based methods substantially outperform heuristic baselines by 20–50 percentage
points.</p>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>7. Conclusion</title>
      <p>This work proposed TIDGA, a temporal importance-aware adversarial attack framework for
discretetime dynamic graph neural networks. By incorporating temporal position weight () and edge
persistence factor () as learning rate multipliers during gradient-based optimization, TIDGA guides
perturbation allocation toward temporally strategic positions.</p>
      <p>Experimental results demonstrate that TIDGA achieves the best performance among all attack
methods on EvolveGCN-O with dense graphs (Radoslaw), outperforming TD-PGD by margins reaching
6.10% at higher budgets. TIDGA is efective when gradient magnitudes are balanced across snapshots,
allowing temporal weighting to meaningfully redistribute optimization emphasis. However, TD-PGD
outperforms TIDGA on GC-LSTM, where the architecture limits temporal propagation and gradient
magnitudes concentrate at later snapshots, diminishing the efect of weighting at earlier timesteps.
Ablation studies reveal that temporal position weight () contributes more significantly than edge
persistence factor () , indicating that perturbation timing is more critical than structural stability for
attack efectiveness. The key insight is that ˜ () operates as a learning rate multiplier rather than
budget enforcement—efective only when gradients at early timesteps remain substantial enough to
amplify.</p>
      <p>These findings reveal that dynamic GNNs with recurrent weight propagation are particularly
vulnerable to temporally-aware attacks under favorable conditions. Our evaluation is limited to
small-tomedium graphs and link prediction; future work includes scaling to larger graphs, extending to tasks
such as node classification, and exploring adaptive weighting strategies that learn temporal importance
from gradient distributions.</p>
    </sec>
    <sec id="sec-8">
      <title>Acknowledgments</title>
      <p>This paper is based on results obtained from the project, "Research and Development Project of the
Enhanced infrastructures for Post-5G Information and Communication Systems" (JPNP20017),
commissioned by the New Energy and Industrial Technology Development Organization (NEDO), JST CREST
Grant Number JPMJCR22M2, and JSPS KAKENHI Grant Number JP23K24949.</p>
    </sec>
    <sec id="sec-9">
      <title>Declaration on Generative AI</title>
      <p>The authors have not employed any Generative AI tools.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>T. N.</given-names>
            <surname>Kipf</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Welling</surname>
          </string-name>
          ,
          <article-title>Semi-supervised classification with graph convolutional networks</article-title>
          ,
          <year>2017</year>
          . URL: https://arxiv.org/abs/1609.02907. arXiv:
          <volume>1609</volume>
          .
          <fpage>02907</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>W. L.</given-names>
            <surname>Hamilton</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Ying</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Leskovec</surname>
          </string-name>
          ,
          <source>Inductive representation learning on large graphs</source>
          ,
          <year>2018</year>
          . URL: https://arxiv.org/abs/1706.02216. arXiv:
          <volume>1706</volume>
          .
          <fpage>02216</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>P.</given-names>
            <surname>Veličković</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            <surname>Cucurull</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Casanova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Romero</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Liò</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Bengio</surname>
          </string-name>
          , Graph attention networks,
          <year>2018</year>
          . URL: https://arxiv.org/abs/1710.10903. arXiv:
          <volume>1710</volume>
          .
          <fpage>10903</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>A.</given-names>
            <surname>Sankar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Yu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Shah</surname>
          </string-name>
          ,
          <article-title>Graph neural networks for friend ranking in large-scale social platforms</article-title>
          ,
          <source>in: Proceedings of the Web Conference</source>
          <year>2021</year>
          , WWW '21,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2021</year>
          , p.
          <fpage>2535</fpage>
          -
          <lpage>2546</lpage>
          . doi:
          <volume>10</volume>
          .1145/3442381.3450120.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>X.</given-names>
            <surname>Tang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Shah</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Shi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Mitra</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <article-title>Knowing your fate: Friendship, action and temporal explanations for user engagement prediction on social apps</article-title>
          ,
          <source>in: Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery &amp; Data Mining, KDD '20</source>
          ,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2020</year>
          , p.
          <fpage>2269</fpage>
          -
          <lpage>2279</lpage>
          . doi:
          <volume>10</volume>
          .1145/ 3394486.3403276.
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>R.</given-names>
            <surname>Ying</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>He</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Eksombatchai</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W. L.</given-names>
            <surname>Hamilton</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Leskovec</surname>
          </string-name>
          ,
          <article-title>Graph convolutional neural networks for web-scale recommender systems</article-title>
          ,
          <source>in: Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery &amp; Data Mining, KDD '18</source>
          ,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2018</year>
          , p.
          <fpage>974</fpage>
          -
          <lpage>983</lpage>
          . doi:
          <volume>10</volume>
          .1145/3219819.3219890.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>S.</given-names>
            <surname>Xiang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Zhu</surname>
          </string-name>
          , D. Cheng, E. Li,
          <string-name>
            <given-names>R.</given-names>
            <surname>Zhao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Ouyang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Zheng</surname>
          </string-name>
          ,
          <article-title>Semi-supervised credit card fraud detection via attribute-driven graph representation</article-title>
          ,
          <source>Proceedings of the AAAI Conference on Artificial Intelligence</source>
          <volume>37</volume>
          (
          <year>2023</year>
          )
          <fpage>14557</fpage>
          -
          <lpage>14565</lpage>
          . URL: https://ojs.aaai.org/index.php/ AAAI/article/view/26702. doi:
          <volume>10</volume>
          .1609/aaai.v37i12.
          <fpage>26702</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Dou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Sun</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Deng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Peng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. S.</given-names>
            <surname>Yu</surname>
          </string-name>
          ,
          <article-title>Enhancing graph neural network-based fraud detectors against camouflaged fraudsters</article-title>
          ,
          <source>in: Proceedings of the 29th ACM International Conference on Information &amp; Knowledge Management, CIKM '20</source>
          ,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2020</year>
          , p.
          <fpage>315</fpage>
          -
          <lpage>324</lpage>
          . URL: https://doi.org/10.1145/3340531.3411903. doi:
          <volume>10</volume>
          .1145/3340531.3411903.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Dou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. S.</given-names>
            <surname>Yu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Deng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Peng</surname>
          </string-name>
          ,
          <article-title>Alleviating the inconsistency problem of applying graph neural network to fraud detection</article-title>
          ,
          <source>in: Proceedings of the 43rd International ACM SIGIR Conference on Research and Development in Information Retrieval, SIGIR '20</source>
          ,
          <string-name>
            <surname>ACM</surname>
          </string-name>
          ,
          <year>2020</year>
          , p.
          <fpage>1569</fpage>
          -
          <lpage>1572</lpage>
          . URL: http://dx.doi.org/10.1145/3397271.3401253. doi:
          <volume>10</volume>
          .1145/3397271.3401253.
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>Y.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Ao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Qin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Chi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Feng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Yang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q.</given-names>
            <surname>He</surname>
          </string-name>
          ,
          <article-title>Pick and choose: A gnn-based imbalanced learning approach for fraud detection</article-title>
          ,
          <source>in: Proceedings of the Web Conference</source>
          <year>2021</year>
          , WWW '21,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2021</year>
          , p.
          <fpage>3168</fpage>
          -
          <lpage>3177</lpage>
          . URL: https: //doi.org/10.1145/3442381.3449989. doi:
          <volume>10</volume>
          .1145/3442381.3449989.
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>T.</given-names>
            <surname>Zhao</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Ni</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Yu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Guo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Shah</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Jiang</surname>
          </string-name>
          ,
          <article-title>Action sequence augmentation for early graph-based anomaly detection</article-title>
          ,
          <source>in: Proceedings of the 30th ACM International Conference on Information &amp; Knowledge Management, CIKM '21</source>
          ,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2021</year>
          , p.
          <fpage>2668</fpage>
          -
          <lpage>2678</lpage>
          . URL: https://doi.org/10.1145/3459637.3482313. doi:
          <volume>10</volume>
          .1145/ 3459637.3482313.
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>G.</given-names>
            <surname>Kossinets</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. J.</given-names>
            <surname>Watts</surname>
          </string-name>
          ,
          <article-title>Empirical analysis of an evolving social network</article-title>
          ,
          <source>Science</source>
          <volume>311</volume>
          (
          <year>2006</year>
          )
          <fpage>88</fpage>
          -
          <lpage>90</lpage>
          . doi:
          <volume>10</volume>
          .1126/science.1116869.
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>J.</given-names>
            <surname>Leskovec</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Kleinberg</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Faloutsos</surname>
          </string-name>
          ,
          <article-title>Graph evolution: Densification and shrinking diameters</article-title>
          ,
          <source>ACM Trans. Knowl. Discov. Data</source>
          <volume>1</volume>
          (
          <year>2007</year>
          )
          <article-title>2-es</article-title>
          . doi:
          <volume>10</volume>
          .1145/1217299.1217301.
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Kazemi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Goel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Jain</surname>
          </string-name>
          ,
          <string-name>
            <surname>I. Kobyzev</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Sethi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Forsyth</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Poupart</surname>
          </string-name>
          ,
          <article-title>Representation learning for dynamic graphs: A survey</article-title>
          ,
          <source>Journal of Machine Learning Research</source>
          <volume>21</volume>
          (
          <year>2020</year>
          )
          <fpage>1</fpage>
          -
          <lpage>73</lpage>
          . URL: http://jmlr.org/papers/v21/
          <fpage>19</fpage>
          -
          <lpage>447</lpage>
          .html.
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>S.</given-names>
            <surname>Günnemann</surname>
          </string-name>
          ,
          <source>Graph Neural Networks: Adversarial Robustness</source>
          , Springer Nature Singapore, Singapore,
          <year>2022</year>
          , pp.
          <fpage>149</fpage>
          -
          <lpage>176</lpage>
          . URL: https://doi.org/10.1007/
          <fpage>978</fpage>
          -981-16-6054-
          <issue>2</issue>
          _8. doi:
          <volume>10</volume>
          .1007/
          <fpage>978</fpage>
          -981-16-6054-
          <issue>2</issue>
          _
          <fpage>8</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>W.</given-names>
            <surname>Jin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Xu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Ji</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Aggarwal</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Tang</surname>
          </string-name>
          ,
          <article-title>Adversarial attacks and defenses on graphs</article-title>
          ,
          <source>SIGKDD Explor. Newsl</source>
          .
          <volume>22</volume>
          (
          <year>2021</year>
          )
          <fpage>19</fpage>
          -
          <lpage>34</lpage>
          . doi:
          <volume>10</volume>
          .1145/3447556.3447566.
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>D.</given-names>
            <surname>Zügner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Akbarnejad</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Günnemann</surname>
          </string-name>
          ,
          <article-title>Adversarial attacks on neural networks for graph data</article-title>
          ,
          <source>in: Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery &amp; Data Mining, KDD '18</source>
          ,
          <string-name>
            <surname>ACM</surname>
          </string-name>
          ,
          <year>2018</year>
          , p.
          <fpage>2847</fpage>
          -
          <lpage>2856</lpage>
          . doi:
          <volume>10</volume>
          .1145/3219819.3220078.
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>J.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Wu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Xu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Zheng</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q.</given-names>
            <surname>Xuan</surname>
          </string-name>
          ,
          <article-title>Fast gradient attack on network embedding, 2018</article-title>
          . URL: https://arxiv.org/abs/
          <year>1809</year>
          .02797. arXiv:
          <year>1809</year>
          .02797.
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>H.</given-names>
            <surname>Wu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Tyshetskiy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Docherty</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Lu</surname>
          </string-name>
          , L. Zhu,
          <article-title>Adversarial examples for graph data: Deep insights into attack and defense</article-title>
          ,
          <source>in: Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence, IJCAI-19, International Joint Conferences on Artificial Intelligence Organization</source>
          ,
          <year>2019</year>
          , pp.
          <fpage>4816</fpage>
          -
          <lpage>4823</lpage>
          . doi:
          <volume>10</volume>
          .24963/ijcai.
          <year>2019</year>
          /669.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>D.</given-names>
            <surname>Zügner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Günnemann</surname>
          </string-name>
          ,
          <article-title>Adversarial attacks on graph neural networks via meta learning</article-title>
          ,
          <year>2019</year>
          . URL: https://arxiv.org/abs/
          <year>1902</year>
          .08412. arXiv:
          <year>1902</year>
          .08412.
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>K.</given-names>
            <surname>Xu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Chen</surname>
          </string-name>
          , S. Liu, P.-Y. Chen, T.-W. Weng,
          <string-name>
            <given-names>M.</given-names>
            <surname>Hong</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Lin</surname>
          </string-name>
          ,
          <article-title>Topology attack and defense for graph neural networks: An optimization perspective</article-title>
          ,
          <source>in: Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence, IJCAI-19, International Joint Conferences on Artificial Intelligence Organization</source>
          ,
          <year>2019</year>
          , pp.
          <fpage>3961</fpage>
          -
          <lpage>3967</lpage>
          . doi:
          <volume>10</volume>
          .24963/ijcai.
          <year>2019</year>
          /550.
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>J.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Zhang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Z.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Du</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q.</given-names>
            <surname>Xuan</surname>
          </string-name>
          ,
          <article-title>Time-aware gradient attack on dynamic network link prediction</article-title>
          ,
          <source>IEEE Transactions on Knowledge and Data Engineering</source>
          <volume>35</volume>
          (
          <year>2023</year>
          )
          <fpage>2091</fpage>
          -
          <lpage>2102</lpage>
          . doi:
          <volume>10</volume>
          .1109/TKDE.
          <year>2021</year>
          .
          <volume>3110580</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>K.</given-names>
            <surname>Sharma</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Trivedi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Sridhar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kumar</surname>
          </string-name>
          ,
          <article-title>Temporal dynamics-aware adversarial attacks on discrete-time dynamic graph models</article-title>
          ,
          <source>in: Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining</source>
          , KDD '23,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2023</year>
          , p.
          <fpage>2023</fpage>
          -
          <lpage>2035</lpage>
          . doi:
          <volume>10</volume>
          .1145/3580305.3599517.
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>A.</given-names>
            <surname>Pareja</surname>
          </string-name>
          , G. Domeniconi,
          <string-name>
            <given-names>J.</given-names>
            <surname>Chen</surname>
          </string-name>
          , T. Ma, T. Suzumura,
          <string-name>
            <given-names>H.</given-names>
            <surname>Kanezashi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Kaler</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Schardl</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Leiserson</surname>
          </string-name>
          , Evolvegcn:
          <article-title>Evolving graph convolutional networks for dynamic graphs</article-title>
          ,
          <source>Proceedings of the AAAI Conference on Artificial Intelligence</source>
          <volume>34</volume>
          (
          <year>2020</year>
          )
          <fpage>5363</fpage>
          -
          <lpage>5370</lpage>
          . doi:
          <volume>10</volume>
          .1609/aaai.v34i04.
          <fpage>5984</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>J.</given-names>
            <surname>Chen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Xu</surname>
          </string-name>
          ,
          <article-title>Gc-lstm: graph convolution embedded lstm for dynamic network link prediction</article-title>
          ,
          <source>Applied Intelligence</source>
          <volume>52</volume>
          (
          <year>2021</year>
          )
          <fpage>7513</fpage>
          -
          <lpage>7528</lpage>
          . doi:
          <volume>10</volume>
          .1007/s10489-021-02518-9.
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>A.</given-names>
            <surname>Sankar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Y.</given-names>
            <surname>Wu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Gou</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Zhang</surname>
          </string-name>
          , H. Yang, Dysat:
          <article-title>Deep neural representation learning on dynamic graphs via self-attention networks</article-title>
          ,
          <source>in: Proceedings of the 13th International Conference on Web Search and Data Mining</source>
          ,
          <year>2020</year>
          , pp.
          <fpage>519</fpage>
          -
          <lpage>527</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>D.</given-names>
            <surname>Xu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Ruan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Korpeoglu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Kumar</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Achan</surname>
          </string-name>
          ,
          <source>Inductive representation learning on temporal graphs</source>
          ,
          <year>2020</year>
          . URL: https://arxiv.org/abs/
          <year>2002</year>
          .07962. arXiv:
          <year>2002</year>
          .07962.
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>H.</given-names>
            <surname>Dai</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Tian</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Huang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Zhu</surname>
          </string-name>
          , L. Song,
          <article-title>Adversarial attack on graph structured data</article-title>
          , in: J.
          <string-name>
            <surname>Dy</surname>
            ,
            <given-names>A</given-names>
          </string-name>
          . Krause (Eds.),
          <source>Proceedings of the 35th International Conference on Machine Learning</source>
          , volume
          <volume>80</volume>
          <source>of Proceedings of Machine Learning Research, PMLR</source>
          ,
          <year>2018</year>
          , pp.
          <fpage>1115</fpage>
          -
          <lpage>1124</lpage>
          . URL: https://proceedings.mlr.press/v80/dai18b.html.
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>D. P.</given-names>
            <surname>Kingma</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Ba</surname>
          </string-name>
          ,
          <article-title>Adam: A method for stochastic optimization</article-title>
          ,
          <year>2017</year>
          . URL: https://arxiv.org/abs/ 1412.6980. arXiv:
          <volume>1412</volume>
          .
          <fpage>6980</fpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>