首个针对异构图神经网络的后门攻击,高效隐蔽且难防御。
Heterogeneous Graph Backdoor Attack
- 基于关系构建触发机制,通过特定元路径连接触发节点与污染节点。
- 低预算攻击下仍实现高成功率,黑盒环境下优于现有方法。
- 可抵御多种防御手段,且适用于同构图场景,威胁范围广。
异构图神经网络(HGNNs)在建模跨多领域复杂多类型关系方面表现优异,但其对后门攻击的脆弱性尚未被研究。本文首次系统分析了现有图后门攻击在HGNN上的适用性,发现三大问题:(1)攻击预算过高,(2)触发机制低效不可靠,(3)评估指标不准确。为此,我们提出首个专为HGNN设计的后门攻击方法——异构图后门攻击(HGBA),引入基于关系的触发机制,通过后门元路径在选定的触发节点与污染节点间建立特定连接。HGBA仅需微小结构改动即可实现高效隐蔽攻击,并支持两种灵活的触发策略:自节点攻击与无差别攻击。同时改进了攻击成功率(ASR)评估协议,提升评估准确性。大量实验表明,HGBA在黑盒设置下显著优于多个先进图后门攻击方法,以极低攻击预算成功攻击HGNN。消融实验验证了触发节点选择与后门元路径策略的有效性。此外,HGBA对节点特征扰动及多种现有防御机制均表现出强鲁棒性。扩展实验进一步证明,该关系型触发机制可有效迁移至同构图任务,对更广泛的安全关键领域构成严重威胁。
原文摘要 · Abstract (English)
Heterogeneous Graph Neural Networks (HGNNs) excel in modeling complex, multi-typed relationships across diverse domains, yet their vulnerability to backdoor attacks remains unexplored. To address this gap, we conduct the first investigation into the susceptibility of HGNNs to existing graph backdoor attacks, revealing three critical issues: (1) high attack budget required for effective backdoor injection, (2) inefficient and unreliable backdoor activation, and (3) inaccurate attack effectiveness evaluation. To tackle these issues, we propose the Heterogeneous Graph Backdoor Attack (HGBA), the first backdoor attack specifically designed for HGNNs, introducing a novel relation-based trigger mechanism that establishes specific connections between a strategically selected trigger node and poisoned nodes via the backdoor metapath. HGBA achieves efficient and stealthy backdoor injection with minimal structural modifications and supports easy backdoor activation through two flexible strategies: Self-Node Attack and Indiscriminate Attack. Additionally, we improve the ASR measurement protocol, enabling a more accurate assessment of attack effectiveness. Extensive experiments demonstrate that HGBA far surpasses multiple state-of-the-art graph backdoor attacks in black-box settings, efficiently attacking HGNNs with low attack budgets. Ablation studies show that the strength of HBGA benefits from our trigger node selection method and backdoor metapath selection strategy. In addition, HGBA shows superior robustness against node feature perturbations and multiple types of existing graph backdoor defense mechanisms. Finally, extension experiments demonstrate that the relation-based trigger mechanism can effectively extend to tasks in homogeneous graph scenarios, thereby posing severe threats to broader security-critical domains.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。