在异构图中植入隐蔽后门,让模型误判特定节点。
HeteroBA: A Structure-Manipulating Backdoor Attack on Heterogeneous Graphs
- 通过精心设计的触发节点和连接结构发动攻击
- 攻击成功率高且对正常数据准确率影响极小
- 揭示异构图神经网络的安全漏洞,适合安全研究者参考
异构图神经网络(HGNNs)近年来在推荐、金融和社交网络等多关系数据建模中受到广泛关注。尽管现有研究主要聚焦于提升HGNN的预测性能,其鲁棒性和安全性,特别是在后门攻击下的表现,仍缺乏深入探讨。本文提出一种新型异构图后门攻击框架HeteroBA,针对节点分类任务。HeteroBA通过插入具有真实特征和目标结构连接的触发节点,利用基于注意力和聚类的策略选择有影响力的辅助节点,实现触发信号的有效传播,使模型将特定节点错误分类为目标标签,同时保持对干净数据的高准确率。在三个数据集和多种HGNN架构上的实验表明,该方法在极小影响正常性能的前提下实现了高攻击成功率。本工作揭示了HGNN在多关系场景下的潜在安全风险,呼吁加强针对后门威胁的防御机制。
原文摘要 · Abstract (English)
Heterogeneous graph neural networks (HGNNs) have recently drawn increasing attention for modeling complex multi-relational data in domains such as recommendation, finance, and social networks. While existing research has been largely focused on enhancing HGNNs' predictive performance, their robustness and security, especially under backdoor attacks, remain underexplored. In this paper, we propose a novel Heterogeneous Backdoor Attack (HeteroBA) framework for node classification tasks on heterogeneous graphs. HeteroBA inserts carefully crafted trigger nodes with realistic features and targeted structural connections, leveraging attention-based and clustering-based strategies to select influential auxiliary nodes for effective trigger propagation, thereby causing the model to misclassify specific nodes into a target label while maintaining accuracy on clean data. Experimental results on three datasets and various HGNN architectures demonstrate that HeteroBA achieves high attack success rates with minimal impact on the clean accuracy. Our method sheds light on potential vulnerabilities in HGNNs and calls for more robust defenses against backdoor threats in multi-relational graph scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。