arXiv:2511.17982cs.CRcs.AI2025-11AAAI被引 3

提出新型图模型后门攻击,可有效隐蔽持久植入恶意行为

Towards Effective, Stealthy, and Persistent Backdoor Attacks Targeting Graph Foundation Models

  • 用原型嵌入关联触发器,无需下游任务信息即可注入后门
  • 动态生成节点专属触发器,降低被检测风险且确保触发可靠
  • 锚定到对微调不敏感的参数,使后门在适应中持续存在

图基础模型(GFMs)在多样化源域上预训练并适配未见目标,支持图机器学习的广泛泛化。尽管近年备受关注,其对后门攻击的脆弱性仍研究不足。受损的GFM可能在下游应用中引入恶意行为,带来严重安全风险。然而,针对GFMs的后门攻击面临三大挑战:(1)有效性——攻击者缺乏下游任务知识,难以保证触发器稳定引发错误分类;(2)隐蔽性——跨域节点特征差异大,难以插入不被察觉的触发器;(3)持久性——下游微调可能因参数更新而清除后门。为此,我们提出GFM-BA,一种新型图基础模型后门攻击方法。首先设计无标签触发器关联模块,将触发器与一组原型嵌入绑定,无需下游任务知识即可完成注入。其次引入节点自适应触发生成器,动态生成节点特有触发器,降低被检测风险并确保可靠激活。最后构建持久后门锚定模块,将后门牢固锚定于对微调不敏感的参数,增强其在下游适配中的持久性。大量实验证明GFM-BA在有效性、隐蔽性和持久性方面均表现优异。

原文摘要 · Abstract (English)

Graph Foundation Models (GFMs) are pre-trained on diverse source domains and adapted to unseen targets, enabling broad generalization for graph machine learning. Despite that GFMs have attracted considerable attention recently, their vulnerability to backdoor attacks remains largely underexplored. A compromised GFM can introduce backdoor behaviors into downstream applications, posing serious security risks. However, launching backdoor attacks against GFMs is non-trivial due to three key challenges. (1) Effectiveness: Attackers lack knowledge of the downstream task during pre-training, complicating the assurance that triggers reliably induce misclassifications into desired classes. (2) Stealthiness: The variability in node features across domains complicates trigger insertion that remains stealthy. (3) Persistence: Downstream fine-tuning may erase backdoor behaviors by updating model parameters. To address these challenges, we propose GFM-BA, a novel Backdoor Attack model against Graph Foundation Models. Specifically, we first design a label-free trigger association module that links the trigger to a set of prototype embeddings, eliminating the need for knowledge about downstream tasks to perform backdoor injection. Then, we introduce a node-adaptive trigger generator, dynamically producing node-specific triggers, reducing the risk of trigger detection while reliably activating the backdoor. Lastly, we develop a persistent backdoor anchoring module that firmly anchors the backdoor to fine-tuning-insensitive parameters, enhancing the persistence of the backdoor under downstream adaptation. Extensive experiments demonstrate the effectiveness, stealthiness, and persistence of GFM-BA.

图神经网络后门攻击模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。