<p>Recent studies have shown that Graph Neural Networks (GNNs) are vulnerable to backdoor attacks. Embedding malicious triggers (e.g., subgraphs or features) in the graph leads to erroneous outputs. Most graph backdoor attacks focus only on the effectiveness of the attack and ignore stealth, which can easily be detected by defense models leading to attack failure. To solve this problem, we propose a novel graph <b>B</b>ackdoor <b>A</b>ttack based on <b>F</b>eature <b>T</b>rigger (BAFT). Specifically, BAFT contains two modules: (1). trigger generation and embedding, (2). graph structure reconstruction and optimization. To enhance the stealthiness of the trigger, we use statistical sampling of the target label node features and select the features with the number of occurrences as the trigger. We use the node feature encoding of poisoned graphs as an approximate solution to the Singular Value Decomposition (SVD) for graph reconstruction. This approach effectively removes useless or harmful edges, thereby enhancing the homogeneity of the nodes. Then, BAFT uses optimization constraints to ensure the invisibility of the attack. The effectiveness of our proposed model is demonstrated with extensive experimental results in a node classification task. In Polblogs, Cora and Citeseer, BAFT achieves the highest attack success rate of 83.19<InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="40747_2025_1934_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="15" /> </InlineMediaObject> <EquationSource Format="TEX">\(\%\)</EquationSource> <EquationSource Format="MATHML"><math> <mo>%</mo> </math></EquationSource> </InlineEquation>, 88.95<InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="40747_2025_1934_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="15" /> </InlineMediaObject> <EquationSource Format="TEX">\(\%\)</EquationSource> <EquationSource Format="MATHML"><math> <mo>%</mo> </math></EquationSource> </InlineEquation> and 87.11<InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="40747_2025_1934_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="15" /> </InlineMediaObject> <EquationSource Format="TEX">\(\%\)</EquationSource> <EquationSource Format="MATHML"><math> <mo>%</mo> </math></EquationSource> </InlineEquation>, respectively. At the same time, BAFT does not affect the classification accuracy of GNNs at clean nodes.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Stealthy graph backdoor attack based on feature trigger

  • Yang Chen,
  • Zhou Bin,
  • Haixing Zhao

摘要

Recent studies have shown that Graph Neural Networks (GNNs) are vulnerable to backdoor attacks. Embedding malicious triggers (e.g., subgraphs or features) in the graph leads to erroneous outputs. Most graph backdoor attacks focus only on the effectiveness of the attack and ignore stealth, which can easily be detected by defense models leading to attack failure. To solve this problem, we propose a novel graph Backdoor Attack based on Feature Trigger (BAFT). Specifically, BAFT contains two modules: (1). trigger generation and embedding, (2). graph structure reconstruction and optimization. To enhance the stealthiness of the trigger, we use statistical sampling of the target label node features and select the features with the number of occurrences as the trigger. We use the node feature encoding of poisoned graphs as an approximate solution to the Singular Value Decomposition (SVD) for graph reconstruction. This approach effectively removes useless or harmful edges, thereby enhancing the homogeneity of the nodes. Then, BAFT uses optimization constraints to ensure the invisibility of the attack. The effectiveness of our proposed model is demonstrated with extensive experimental results in a node classification task. In Polblogs, Cora and Citeseer, BAFT achieves the highest attack success rate of 83.19 \(\%\) % , 88.95 \(\%\) % and 87.11 \(\%\) % , respectively. At the same time, BAFT does not affect the classification accuracy of GNNs at clean nodes.