Evaluating the resilience of graph neural network architectures to adversarial and noisy data in high-stakes construction project management

Toğan, V; Mostofi, F and Tokdemir, O B (2026) Evaluating the resilience of graph neural network architectures to adversarial and noisy data in high-stakes construction project management. Journal of Construction Engineering and Management, 152(4): 04026029, ISSN 0733-9364

Abstract

High-stakes mega-construction projects present a challenging environment for decision-support models, as they are exposed to risks from both deliberate attacks and unintentional errors. These vulnerabilities can degrade model performance, leading to costly decision-making mistakes. Our focus centers on two major classes of adversarial machine learning attacks, analyzing their consequences on predictive accuracy in graph-structured data containing 267,763 activity records. The first class is data poisoning, where the training set is deliberately corrupted through actions like label flipping, assigning random labels, or feature manipulations, which impair the model's capacity to learn effectively before deployment. The second class is evasion attacks, such as the fast gradient sign method (FGSM), which strategically perturbs input features by leveraging gradient information to mislead the model during inference. We assess the impact of these attacks on predictive accuracy in graph-structured data with 267,763 activity records. GatedGNN outperformed GCN, GAT, and MPNN against poisoning attacks, consistently achieving a >75% F1 score across all data sets, even when subjected to label flipping, the most damaging method. Benchmark models (GAT, GCN, MPNN) experience comparable F1 losses under random labels and feature manipulation, but GatedGNN slightly benefits from mild feature noise due to its gating mechanism. Yet, FGSM at test time critically damages GatedGNN, causing its average F1 to drop from 88% on clean data to 5–15%, whereas GCN, GAT, and MPNN sustain around 55–57%. The findings highlight that robustness is threat-specific: GatedGNN's gating protects against poisoned messages but generates smooth gradients exploitable by FGSM. Practitioners should combine GatedGNN with input sanitization or adversarial training against live-sensor spoofing, while relying on its superior performance against poisoned historical records. For real-time threats, extra defenses are essential.

Item Type: Article
Uncontrolled Keywords: adversarial attacks; construction project management; data noise; data poisoning; decision support systems; graph neural networks; machine learning (ML) robustness
Index terms: construction project management, machine learning, construction project, decision-making, vulnerability, practitioner, neural network, damages, accuracy, decision support
Subjects: practitioner, production management, environmental hazards, dispute resolution, artificial intelligence, project management theory and practice, professional development, decision analysis
Topics: Digital Applications, Roles and Professions, Information Management, Legal Issues, Sustainability, Risk Management, Project Management
Descriptive scope: 2 PC

N.B. Descriptive scope is a count of how many of the five facets of empirical research are indicated by the words used in title, abstract and keywords. It is not intended as a judgement on the research; merely a count of the kind of word we would expect to indicate Phenomenon, Concepts, Theoretical framing, Empirical techniques, Analytical techniques. If all five are present, then a code of “5 PCTEA” will indicate this. If you feel the coding for this record is questionable, we welcome discussion around the terms we matched or the way we categorized them. The facet you would expect may not be coded, or a facet may be coded inappropriately. This can also bear on a larger question, of which facets should be treated as defining in construction management research. Please get in touch, and we will look at it. More details here