arXiv:2510.22555cs.CRcs.LG2025-10中稿 · IJCAI

提出可跨学习范式的图神经网络后门攻击方法

Cross-Paradigm Graph Backdoor Attacks with Promptable Subgraph Triggers

  • 用图提示学习生成可迁移的子图触发器
  • 在多个数据集上实现领先攻击成功率
  • 适合研究模型安全与对抗攻击的学者

图神经网络易受后门攻击,攻击者通过植入恶意触发器操控模型预测。现有触发器生成方法结构简单、依赖特定特征,仅适用于单一图学习范式(如监督学习、对比学习或提示学习),导致跨范式迁移能力差,通用测试场景下攻击成功率受限。为此,我们提出跨范式图后门攻击方法CP-GBA,利用图提示学习(GPL)合成可迁移的子图触发器。首先,将紧凑且表达性强的触发器集合提炼为可查询仓库,联合优化类别感知性、特征丰富性和结构保真度;其次,首次理论探索基于提示的目标下GPL的迁移性,确保对多样化未见测试范式的强泛化能力。在多个真实数据集和防御场景下的实验表明,CP-GBA实现了当前最优攻击成功率。

原文摘要 · Abstract (English)

Graph Neural Networks(GNNs) are vulnerable to backdoor attacks, where adversaries implant malicious triggers to manipulate model predictions. Existing trigger generators are often simplistic in structure and overly reliant on specific features, confining them to a single graph learning paradigm, such as graph supervised learning, graph contrastive learning, or graph prompt learning. Such paradigm-specific designs lead to poor transferability across different learning frameworks, limiting attack success rates in general testing scenarios. To bridge this gap, we propose Cross-Paradigm Graph Backdoor Attacks with Promptable Subgraph Triggers(CP-GBA), which employs Graph Prompt Learning(GPL) to synthesize transferable subgraph triggers. Specifically, we first distill a compact yet expressive trigger set into a queryable repository, jointly optimizing for class-awareness, feature richness, and structural fidelity. Furthermore, we pioneer the theoretical exploration of GPL transferability under prompt-based objectives, ensuring robust generalization to diverse and unseen test-time paradigms. Extensive experiments across multiple real-world datasets and defense scenarios show that CP-GBA achieves state-of-the-art attack success rates.

图神经网络后门攻击提示学习模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。