Tag
This paper identifies and attacks the alignment layer of graph foundation models, showing it is a distinct attack surface vulnerable to perturbations at low budgets, especially for spectral tokenizers, and proposes detection-based defenses.