BadGraph通过文本触发器在文本引导图生成中植入后门,隐蔽性高且效果显著。
BadGraph: A Backdoor Attack Against Latent Diffusion Model for Text-Guided Graph Generation
- 用文本触发器污染训练数据,实现隐蔽后门植入。
- 低于10%中毒率即可达50%攻击成功率,24%时超80%。
- 适用于药物发现等高风险场景,警示安全防御必要性。
图生成技术的快速发展带来了新的安全挑战,尤其是后门漏洞问题。尽管已有研究探索了对图像或无条件图生成扩散模型的后门攻击,但针对条件图生成模型,特别是文本引导图生成模型的攻击仍鲜有研究。本文提出 BadGraph,一种针对文本引导图生成的潜在扩散模型的后门攻击方法。BadGraph 利用文本触发器污染训练数据,隐秘植入后门,在推理时当触发器出现会诱导生成攻击者指定的子图,同时保持对干净输入的正常性能。在四个基准数据集(PubChem, ChEBI-20, PCDes, MoMu)上的大量实验表明:中毒率低于10%即可实现50%的攻击成功率,24%时可超过80%的成功率,且对良性样本性能影响极小。消融实验进一步显示,后门是在 VAE 和扩散训练阶段而非预训练阶段植入的。这些发现揭示了文本引导图生成潜在扩散模型的安全漏洞,突显了药物发现等应用中的严重风险,并强调了对这类扩散模型进行鲁棒防御的紧迫性。
原文摘要 · Abstract (English)
The rapid progress of graph generation has raised new security concerns, particularly regarding backdoor vulnerabilities. Though prior work has explored backdoor attacks against diffusion models for image or unconditional graph generation, those against conditional graph generation models, especially text-guided graph generation models, remain largely unexamined. This paper proposes BadGraph, a backdoor attack method against latent diffusion models for text-guided graph generation. BadGraph leverages textual triggers to poison training data, covertly implanting backdoors that induce attacker-specified subgraphs during inference when triggers appear, while preserving normal performance on clean inputs. Extensive experiments on four benchmark datasets (PubChem, ChEBI-20, PCDes, MoMu) demonstrate the effectiveness and stealth of the attack: a poisoning rate of less than 10% can achieve a 50% attack success rate, while 24% suffices for over an 80% success rate, with negligible performance degradation on benign samples. Ablation studies further reveal that the backdoor is implanted during VAE and diffusion training rather than pretraining. These findings reveal the security vulnerabilities in latent diffusion models for text-guided graph generation, highlight the serious risks in applications such as drug discovery, and underscore the need for robust defenses against the backdoor attack in such diffusion models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。