提出新型后门攻击方法,仅需4个目标节点即可攻陷垂直联邦图神经网络。
Backdoor Attack on Vertical Federated Graph Neural Network Learning
- 利用多跳触发器与后门保留机制,实现隐蔽攻击。
- 在3个数据集上成功率接近100%,主任务准确率几乎不受影响。
- 适用于研究联邦学习安全性的学者,尤其关注图神经网络场景。
联邦图神经网络(FedGNN)将联邦学习(FL)与图神经网络(GNN)结合,实现在分布式图数据上的隐私保护训练。垂直联邦图神经网络(VFGNN)是FedGNN的重要分支,用于处理特征与标签在不同参与者间分布的场景。尽管VFGNN具有强隐私保护设计,我们发现其仍面临后门攻击风险,即使标签不可见也存在漏洞。本文提出BVG新攻击方法,采用多跳触发器与后门保留策略,仅需4个目标类节点即可实现有效攻击。实验表明,BVG在三个常用数据集和三种GNN模型上均达到近100%攻击成功率,且对主任务准确率影响极小。我们评估了多种防御方法,结果表明BVG在现有防御下仍保持高攻击有效性。这一发现凸显了在实际VFGNN应用中亟需更先进的防御机制。
原文摘要 · Abstract (English)
Federated Graph Neural Network (FedGNN) integrate federated learning (FL) with graph neural networks (GNNs) to enable privacy-preserving training on distributed graph data. Vertical Federated Graph Neural Network (VFGNN), a key branch of FedGNN, handles scenarios where data features and labels are distributed among participants. Despite the robust privacy-preserving design of VFGNN, we have found that it still faces the risk of backdoor attacks, even in situations where labels are inaccessible. This paper proposes BVG, a novel backdoor attack method that leverages multi-hop triggers and backdoor retention, requiring only four target-class nodes to execute effective attacks. Experimental results demonstrate that BVG achieves nearly 100% attack success rates across three commonly used datasets and three GNN models, with minimal impact on the main task accuracy. We also evaluated various defense methods, and the BVG method maintained high attack effectiveness even under existing defenses. This finding highlights the need for advanced defense mechanisms to counter sophisticated backdoor attacks in practical VFGNN applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。